/ Guide / Healthcare

HIPAA compliant IT services are defined by what gets signed and what gets recorded.

HIPAA compliant is a claim every IT provider makes and no IT provider can make on your behalf. Compliance belongs to the covered entity. What a provider can do is sign a business associate agreement, operate to a written standard and produce the records an audit asks for.

This page lists what to require, and states what Surya signs, what it operates and what stays with your organization.

Check Fit

/ What to require

Five things to ask for before the word compliant means anything.

  • A signed business associate agreement before any work near protected health information.
  • A written device and configuration standard applied at every location, not per technician.
  • Serial-level custody records for every device that moves.
  • Certified media sanitization to NIST 800-88, with a certificate per device.
  • An independent audit of the provider's own controls: a SOC 2 Type II report.

/ What Surya signs

The agreement and the attestations.

  • A business associate agreement is available.
  • HIPAA-aligned handling at every site in scope.
  • SOC 2 Type II audited. Report available on request under NDA.
  • Certified data erasure to NIST 800-88, with a certificate filed against the serial number.
  • Serial-level chain of custody.

HIPAA compliance remains an organizational responsibility. Surya provides scoped technology controls, operational practices and evidence that support your program.

/ What Surya operates

Controls as operating practice.

  • Configuration baseline. Supported device configurations and the agreed security baseline are applied when a module enters service, not after the fact.
  • Identity and access. Identity, sign-in and secure access are operated to the standard in the tenant the customer owns. Access to Surya facilities is controlled and logged.
  • Endpoint protection and updates. Endpoint protection and update handling for supported devices are operated within the standard.
  • Support records. Requests, troubleshooting and changes inside the supported environment produce an operational record available for review.
  • Device custody. Devices in Surya's custody are tracked by serial number, and every handoff, return and swap is documented.
  • Media sanitization. Drives are erased to NIST 800-88 where erasure applies, with a certificate per device, before approved disposition.
  • Vendor responsibilities. A business associate agreement is available. Clinical application and equipment vendors retain their own responsibilities.
  • Incident escalation. Issues needing a vendor, a physical action or your approval follow an agreed escalation path with named owners.

No patient data enters the device flow. Surya captures configuration, not records. Surya covers the technology that supports the clinical device: the workstation, printer, network connection and supported computing layer. The clinical device itself remains under the authority of the healthcare organization and its medical-equipment vendor unless separately qualified and contracted. We work up to the port, not past it.

/ What stays with you

Your program, your decisions.

  • The risk analysis, policies and workforce training.
  • Clinical application vendors and their own agreements.
  • Access decisions and data authority.
  • Medical equipment vendors and the clinical device itself.

Check Fit.

Tell us how many locations hold devices near protected health information and what your last audit asked for.

Check Fit