Get started
ComplianceLive · in the productRegister

HIPAAGuard

US privacy operations: the risk analysis, BAAs, the breach clock and workforce training.

Offered in: United States only.
Get HIPAAGuardOpen the appAvailable nowHow pricing works →

What it is

HIPAA as running registers rather than a binder. The security risk analysis is kept here: each risk by administrative, physical or technical safeguard, with its likelihood, impact, owner and due date, closed only as mitigated (what was done) or accepted (why the practice lives with it), and the date of the last full analysis with a flag when a year has passed. So is the business associate register: every vendor that handles PHI, what it handles, when its BAA was signed and is reviewed or ends — a vendor with no signed BAA shows as a gap — and how the agreement ended. The breach clocks are IncidentIQ’s: a US practice’s data breach opens the notice to the people affected and the report to HHS, each on a 60-day default with its source named. Access requests run in the Security Centre on HIPAA’s 30 days with one 30-day extension. Workforce training is read from the TrainingMatrix course the practice names as its HIPAA training, against every active member of staff.

Who uses it
Built for: Every specialty
Reads
Incident breach notices, access requests, training records
Writes
The risk analysis, business associate agreements
Never
It does not certify compliance — it keeps the evidence and shows the gaps; the attestation stays with the practice’s privacy and security officers.
Access
Only people whose role includes it — the clinic owner decides who
Your data
Full PHI. Hosted in Boston, United States. On uninstall: Every record stays; only the workflow leaves.

How it works

  1. The clocksBreach notices from IncidentIQ (people affected and HHS, 60 days by default) and access requests from the Security Centre (30 days, one extension), soonest first.
  2. Business associatesAdd each vendor that handles PHI and record its signed BAA; a vendor with none shows as a gap, and ending an agreement says what happened to the PHI.
  3. Risk analysis and trainingRecord risks by safeguard, close them as mitigated or accepted with a note, and name the TrainingMatrix course that is your HIPAA training to see who has not done it.

Rules it keeps

What it does not do, by design. A listing with only benefits is an advertisement.

It does not certify compliance — it keeps the evidence and shows the gaps; the attestation stays with the practice’s privacy and security officers.
The 60-day defaults are to be confirmed against the current rule.

AI in HIPAAGuard

AskQuestions about what is on screen — “What needs attention in HIPAAGuard today?” — answered with the records it read.
DraftSummaries and notes for the team, marked as drafts until a person signs.
Every answer shows its sources. Nothing AI writes is saved until a person accepts it.

See it on screen

Live product
01HIPAA — Keep the HIPAA risk analysis, BAAs, breach clocks and training in one placeCaptured from the running demo clinic
HIPAAGuard — HIPAA — Keep the HIPAA risk analysis, BAAs, breach clocks and training in one place
1 of 1

Connected to

Read out of the code, not the brochure: each app below is here because one service queries the other’s tables. Install either side and the hand-over is already wired.

See the whole clinic →

Questions clinics ask

What does HIPAAGuard do?
US privacy operations: the risk analysis, BAAs, the breach clock and workforce training. HIPAA as running registers rather than a binder. The security risk analysis is kept here: each risk by administrative, physical or technical safeguard, with its likelihood, impact, owner and due date, closed only as mitigated (what was done) or accepted (why the practice lives with it), and the date of the last full analysis with a flag when a year has passed. So is the business associate register: every vendor that handles PHI, what it handles, when its BAA was signed and is reviewed or ends — a vendor with no signed BAA shows as a gap — and how the agreement ended. The breach clocks are IncidentIQ’s: a US practice’s data breach opens the notice to the people affected and the report to HHS, each on a 60-day default with its source named. Access requests run in the Security Centre on HIPAA’s 30 days with one 30-day extension. Workforce training is read from the TrainingMatrix course the practice names as its HIPAA training, against every active member of staff.
What data does HIPAAGuard read and write?
HIPAAGuard reads incident breach notices, access requests, training records and writes the risk analysis, business associate agreements. Its data class is Full PHI. Every app works on the same patient record — nothing is copied into a silo.
What does HIPAAGuard deliberately not do?
It does not certify compliance — it keeps the evidence and shows the gaps; the attestation stays with the practice’s privacy and security officers. The 60-day defaults are to be confirmed against the current rule.
What happens to our data if we uninstall HIPAAGuard?
Every record stays; only the workflow leaves.
Is HIPAAGuard available today?
Yes — HIPAAGuard is live in clinics today. Set up your practice on MedAppz and install it from your dashboard.
Where is HIPAAGuard offered?
HIPAAGuard is offered in United States only: it is built on that market's own systems and rules.

Want to see HIPAAGuard running on your own patients?

Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.

More in Compliance

All 154 →