Skip to main content
NOVACompliance

Frameworks

Planned

HIPAA

United States requirements for safeguarding protected health information held by covered entities and business associates.

Overview

HIPAA establishes obligations for covered entities and their business associates regarding the confidentiality, integrity and availability of protected health information.

The Security Rule sets administrative, physical and technical safeguards; the Privacy Rule governs use and disclosure; the Breach Notification Rule sets reporting obligations.

Support in NOVA is planned and is not operational today. This page describes intent, not current capability.

Who this is for

  • Covered entities handling protected health information
  • Business associates processing health data on behalf of others
  • Health technology vendors entering the United States market

Governance areas

Administrative safeguards

Risk analysis, workforce training, sanction policy and contingency planning.

Physical safeguards

Facility access, workstation use and device and media controls.

Technical safeguards

Access control, audit controls, integrity and transmission security.

Privacy obligations

Permitted uses and disclosures, and individual rights over health information.

Breach notification

Assessment, documentation and notification obligations after an incident.

How NOVA supports this framework

  • Planned: safeguard mapping onto existing controls
  • Planned: business associate relationship records
  • Planned: breach assessment workflow support

Controls and evidence focus

  • Planned. No HIPAA-specific assessment or reporting exists in NOVA today.

Cross-framework reuse

Planned reuse of access control, audit and incident evidence already held for SOC 2 and ISO/IEC 27001

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Pricing

Plans that cover HIPAA

Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.

Launch

AUD $99 /month

A first certification or attestation programme run properly from the start.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Compare plans

Growth

Most chosen

AUD $249 /month

Multiple frameworks on one shared control set, with reuse across requirements.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Compare plans

Professional

AUD $499 /month

Assurance-grade operation with external review workflows included.

  • Everything in Growth
  • Auditor Portal with scoped engagement access
  • Trust Centre publication
  • Asset register and classification
Compare plans

Enterprise

On request

Quoted per organisation against scope, users and assurance requirements.

  • Everything in Business
  • Scope defined per organisation
  • Commercial terms agreed with Eredox
  • Structured onboarding programme
Compare plans

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

Getting started

How to start with HIPAA

Four steps from an empty workspace to a reviewable readiness position.

  1. Step 1

    Activate the framework

    Create the workspace and activate HIPAA so its requirements load into your control set.

  2. Step 2

    Assign control ownership

    Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.

  3. Step 3

    Map and validate evidence

    Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.

  4. Step 4

    Review readiness

    Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Talk to us

Ask about HIPAA

Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Forms are not connected yet. Please email compliance@eredox.com.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.