Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant safeguards
Current HIPAA Security Rule (45 CFR Part 164, Subpart C) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 13 IAM-relevant safeguards
This maps against the CURRENT HIPAA Security Rule (45 CFR Part 164, Subpart C) — the version OCR enforces today. A major overhaul was proposed in an NPRM (6 January 2025) that would make 'addressable' specifications mandatory and explicitly require MFA, encryption and more. As of mid-2026 it remains PROPOSED, not final — OCR's spring-2026 target passed and the timeline is uncertain. Revisit this mapping if a final rule issues.
The IAM-relevant safeguards — the Technical Safeguards for access control, authentication and audit (164.312) and the Administrative Safeguards for workforce access and activity review (164.308). This is NOT a full Security Rule mapping: risk analysis, physical, contingency, encryption and organizational requirements are out of scope. (R) = required, (A) = addressable under the current rule.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
HIPAA has no certification — it is a regulation enforced by HHS OCR, and compliance also requires a documented risk analysis (164.308(a)(1)(ii)(A)), the deficiency OCR cites most often. SimpliKeys can help meet specific safeguards when appropriately configured, but no tool makes an organisation 'HIPAA compliant.' Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Allow access to ePHI only to authorized persons and software.
What SimpliKeys does
Is the access-control system: authenticates every request and enforces access to ePHI systems by policy.
Customer responsibility & notes
Customer places SimpliKeys in the access path for all systems holding ePHI, including legacy.
Assign a unique name or number to identify and track each user.
What SimpliKeys does
Issues a unique identifier to every identity and tracks its activity.
Customer responsibility & notes
Customer ensures shared/generic accounts are eliminated or vaulted for individual accountability.
Provide a way to obtain ePHI during an emergency.
What SimpliKeys does
Provides break-glass / emergency privileged access, vaulted and recorded.
Customer responsibility & notes
SimpliKeys provides the break-glass access mechanism; the documented emergency procedure (who may invoke it, when, and sign-off) is the customer's, and access to the ePHI data itself may depend on the application.
End an electronic session after a predetermined period of inactivity.
What SimpliKeys does
Ends the sessions it manages automatically after a configurable idle period.
Customer responsibility & notes
Customer sets the inactivity timeout for ePHI sessions; application/OS-level logoff is a separate control.
Record and examine activity in systems that contain or use ePHI.
What SimpliKeys does
Records identity and access activity on the systems it fronts — sessions with recording and playback, plus device, location and keystroke detail — and forwards it to SIEM.
Customer responsibility & notes
Customer confirms audit records cover all ePHI systems and contain the detail it needs.
Verify that a person or entity seeking access is who they claim to be.
What SimpliKeys does
Authenticates every person and entity with strong authentication from a configurable spectrum of factors, including phishing-resistant FIDO2/passkeys.
Customer responsibility & notes
Customer selects the factors. The proposed 2025 update would make MFA explicit and mandatory — SimpliKeys already supports it today.
Regularly review records of system activity (audit logs, access reports, incident tracking).
What SimpliKeys does
Analyzes identity/access records with behavioural analytics and surfaces unusual activity in real time.
Customer responsibility & notes
SimpliKeys performs the automated analysis; the formal review cadence and responsibilities remain the customer's.
Authorize and/or supervise workforce members who work with ePHI.
What SimpliKeys does
Authorizes workforce access by policy and supervises it through session monitoring and recording.
Customer responsibility & notes
SimpliKeys authorizes and monitors access to ePHI; broader managerial supervision of the workforce is organisational.
Terminate access to ePHI when a workforce member leaves or no longer needs it.
What SimpliKeys does
Revokes access on termination or role change, driven by joiner/mover/leaver events from connected HR systems.
Customer responsibility & notes
Customer connects the HR source so revocation propagates promptly across all connected ePHI systems.
Grant access to ePHI through a defined authorization mechanism.
What SimpliKeys does
Grants access to ePHI through request and approval workflows tied to role.
Customer responsibility & notes
Customer defines approvers and the authorization workflow.
Establish, document, review and modify a user's access rights.
What SimpliKeys does
Establishes, modifies and reviews access rights, and runs periodic access-review campaigns.
Customer responsibility & notes
Customer schedules the reviews; SimpliKeys modifies access on role change and recertifies.
Monitor log-in attempts and report discrepancies.
What SimpliKeys does
Monitors log-in attempts, logs failed attempts, and flags anomalies through behavioural analytics.
Customer responsibility & notes
Customer confirms failed-login alerting is enabled on ePHI systems.
Create, change and safeguard passwords.
What SimpliKeys does
Creates, rotates and safeguards credentials in a vault, with passwordless options available.
Customer responsibility & notes
Customer sets the password creation/rotation/storage controls to its policy.
Mapping is against the current HIPAA Security Rule (45 CFR Part 164, Subpart C) as in effect in mid-2026, reviewed safeguard-by-safeguard with SimpliKeys. The proposed 2025 NPRM, if finalized, would make addressable specs mandatory and add explicit MFA/encryption/testing requirements — revisit then. Regulatory text is paraphrased; exact text is public-domain at ecfr.gov. 'Supports' = capability provided when appropriately configured; the customer configures and operates its deployment and maintains the required risk analysis. HIPAA has no certification.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo