Skip to main content
Help Compliance & Audit
Compliance & Audit

HIPAA evidence and Business Associate Agreements

1 min read·1 views·100% found this helpful

If you handle protected health information, G8KEPR gives you two things: evidence reports mapped to the HIPAA Security Rule, and a Business Associate Agreement for the parts G8KEPR is responsible for.

HIPAA evidence reports

G8KEPR produces live evidence reports that map your configuration and activity to HIPAA Security Rule safeguards — access controls, audit controls, integrity, and transmission security. Because the reports are generated from your live audit log and control status, they reflect the current state of your environment rather than a point-in-time snapshot.

Business Associate Agreements

A signed BAA is available on Enterprise. It covers G8KEPR's responsibilities as a business associate when the platform processes PHI on your behalf.

A BAA and evidence tooling support your HIPAA program — they don't replace it. You remain responsible for your own risk analysis, workforce training, and the safeguards on systems outside G8KEPR. Treat these reports as inputs to your compliance work, not a certification.

Keeping PHI in your control

For the strictest requirements, run G8KEPR in your own VPC, on-prem, or air-gapped (Enterprise), so PHI never leaves your infrastructure. See Deploy G8KEPR in your VPC.

Was this helpful?Still stuck? Submit a request →

Related articles