Healthcare
Patient data protected. Compliance demonstrated.
Healthcare providers, health plans, health technology companies, and anyone who handles protected health information faces one of the most demanding compliance environments in any industry. HIPAA is the legal floor — but modern healthcare organizations need a full compliance stack. Johanson Group can help you demonstrate it.
Market leaders choose Johanson Group:
























Experienced Practitioners
Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.
Platform Experts
Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.
Integrated Audits
Your CSM and audit project lead guide the engagement from kickoff to final report — one seamless experience.
Expert Network
Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.
Our services
Built for the data healthcare organizations are trusted with.
Every framework below is placed in the category that reflects what drives it — what enterprise health systems and health plans screen for, and what applies as your patient populations and markets expand.
HIPAA Assessments
The Health Insurance Portability and Accountability Act governs PHI for covered entities and business associates. All three rules — Privacy, Security, and Breach Notification — are required with no exceptions.
- Privacy Rule: governs PHI use and disclosure, minimum necessary standard, patient rights
- Security Rule: administrative, physical, and technical safeguards for all ePHI
- Breach Notification: 60-day notification to individuals, HHS reporting requirements.
SOC 2 Type II
Enterprise health systems, health plans, and hospital networks require SOC 2 Type II from technology vendors alongside HIPAA attestation. Security, Availability, Confidentiality, and Privacy Trust Services Criteria all apply to healthcare data handling.
- Required alongside HIPAA attestation for enterprise healthcare vendor approval
- Privacy TSC specifically covers healthcare patient data protection
- Availability criteria address clinical system uptime and continuity requirements
- Significant control overlap with HIPAA Security Rule — pursue concurrently
GDPR Assessments
Healthcare organizations treating EU patients are subject to GDPR — which classifies health data as Special Category data requiring enhanced protections. GDPR and HIPAA have overlapping but distinct requirements that must be satisfied independently.
- Health data is Special Category — explicit consent or legal exception required
- Data subject rights: access, rectification, erasure, portability for EU patients
- DPIAs required for high-risk health data processing activities
- Both HIPAA and GDPR apply simultaneously for organizations with EU patients
NIST 800-53/800-171
Healthcare organizations participating in federal programs — Medicare, Medicaid, VA, DoD healthcare — or holding federal contracts may face NIST framework requirements.
- NIST 800-53 required for federal agency systems and FedRAMP-authorized cloud
- NIST 800-171 if CUI is handled under federal healthcare contracts
- HIPAA Security Rule maps closely to NIST 800-53 moderate baseline
- FedRAMP required for cloud services sold to federal health agencies such as VA
ISO 27001
Large health systems, international healthcare organizations, and health technology companies serving global markets increasingly require ISO 27001.
- Required by many international and large enterprise health systems
- Covers organizational ISMS beyond HIPAA's specific ePHI focus
- Maps well to HIPAA Security Rule — significant control overlap
- 3-year certification with annual surveillance audits
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
Frequently asked questions
Your answer not here? Feel free to contact us for more information.
Yes — if your software accesses, stores, or transmits protected health information on behalf of a healthcare client, you are a Business Associate under HIPAA and directly liable for compliance. The HITECH Act extended direct HIPAA liability to business associates in 2013. SaaS platforms, EHR vendors, telehealth services, cloud storage providers, and health analytics tools are all common business associates. You need a signed BAA with every healthcare client and must comply with the HIPAA Security Rule in full.
A BAA is a legally required contract between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on the covered entity's behalf. The BAA must specify permitted uses and disclosures of PHI, require Security Rule safeguards, mandate breach notification within 60 days, and require the same obligations to flow to subcontractors. Operating without a signed BAA is one of the most commonly cited HIPAA violations and a frequent focus of OCR enforcement.
HIPAA is US-specific and covers PHI in the context of healthcare treatment, payment, and operations. GDPR applies to EU residents' health data regardless of geography and treats it as Special Category data requiring enhanced protection. If you treat EU patients, both apply simultaneously — and you need to satisfy each framework's distinct legal basis requirements, patient rights obligations, and breach notification timelines independently. Both have overlapping but not identical breach notification requirements.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.



.png)
.jpg)
.avif)

