Help center
Shieldra Help Center
Answers to the questions healthcare teams ask most — getting set up, how compliance scoring works, what HIPAA actually requires, how scanning and evidence collection work, and how your data is handled.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Most small practices reach baseline compliance in 2–4 weeks, depending on what documentation already exists.
- One person can serve as both Privacy Officer and Security Officer — common in small practices, and permitted under 45 CFR §164.530(a)(1) and §164.308(a)(2).
- Compliance scores are weighted by severity across 73 HIPAA requirements, not a flat percentage.
- Integrations are optional: the platform works fully with manually uploaded evidence.
- Data is stored in the United States and encrypted at rest with AES-256; AI features are bring-your-own-key and your data is never used to train models.
Getting started
What to do first
After signing up, the onboarding wizard covers naming your organization, designating your HIPAA Privacy and Security Officers, inviting team members, and connecting a first integration. The recommended order after that is: complete the dashboard onboarding checklist, designate officers, upload or connect existing policies, run a first compliance scan, then review findings and start remediation.
Roles and access
Team members are invited from Settings → Team Members → Invite, and each gets a role: Owner (full access), Admin (manage settings and users), Compliance Officer (manage compliance workflows), or Viewer (read-only). No technical expertise is required — the platform uses plain-language explanations and guided workflows, and an IT team can connect technical integrations for deeper automation if you have one.
How compliance scoring works
Your score is earned weight divided by total catalog weight, times 100. Each of the 73 HIPAA requirements is weighted by severity — Critical counts 3×, High 2×, Medium 1×, and Low 0.5× — and a requirement earns its full weight once validated evidence is attached.
That weighting is deliberate: a flat percentage would let a practice look compliant while missing the controls that actually carry enforcement risk. It also means the fastest way to move the score is to close Critical gaps first, which is the same order OCR would look at them.
Scanning and evidence
- Seven scanner types: Policy, Technical, Access Control, Encryption, Network Security, Training Compliance, and Continuous Monitoring
- A quick scan analyzes a single document or policy — useful before publishing a new one
- A full scan runs all seven scanners across documents, integrations, and configurations
- Evidence uploads accept documents, screenshots, or any file, each linked to specific HIPAA requirements
- Integrations such as AWS, Azure, and Okta can collect technical evidence automatically, but are optional
- The audit trail logs logins, uploads, policy changes, status updates, integration events, scan results, and administrative actions — retained for six years as HIPAA requires
Frequently asked questions
How long does it take to get HIPAA compliant with Shieldra?
Most small healthcare practices achieve baseline compliance within 2–4 weeks. The timeline depends on your starting point — if you already have some policies in place it can be faster. The compliance roadmap breaks the work into prioritized stages.
Can the same person be both Privacy Officer and Security Officer?
Yes. HIPAA requires a designated Privacy Officer under 45 CFR §164.530(a)(1) and a Security Officer under §164.308(a)(2), but the same individual can serve in both roles. This is common in small practices.
What counts as Protected Health Information (PHI)?
Any individually identifiable health information held or transmitted by a covered entity — patient names, dates of birth, Social Security numbers, medical record numbers, diagnoses, treatment information, billing records, and any combination of data that could identify a patient.
How often do I need to do a risk assessment?
HIPAA requires periodic risk assessments without specifying an exact frequency. Industry best practice is annually, plus whenever there is a significant change — new systems, staff changes, security incidents, or new business relationships.
What HIPAA training do my employees need?
Every workforce member who handles PHI must be trained on what PHI is and how to protect it, your privacy and security policies, how to report incidents, and the consequences of violations. Training is required at hiring and periodically thereafter, and records must be documented.
Do I need a BAA with every vendor?
You need one with any vendor that creates, receives, maintains, or transmits PHI on your behalf — EHR providers, cloud hosting, billing companies, IT support, shredding companies, and email providers used for PHI.
What is the difference between Required and Addressable safeguards?
Required safeguards must be implemented with no exceptions. Addressable safeguards require you to assess whether the safeguard is reasonable and appropriate for your organization — if it is, you must implement it; if not, you must document why and what you did instead.
What happens if I am not 100% compliant?
OCR evaluates whether you made good-faith efforts to comply. A documented risk assessment, an active remediation plan, and evidence of ongoing improvement demonstrate good faith, which is why continuous documentation matters more than a perfect score at any single moment.
Can I use Shieldra without any integrations?
Yes. Integrations automate evidence collection but are not required. You can manually upload evidence, run document-based scans, manage your compliance program, and prepare for audits entirely within the platform.
Where is my data stored?
All data is stored in the United States on infrastructure provided by Railway for application hosting and Neon for managed PostgreSQL, both US-based providers. Data is encrypted at rest using AES-256.
How does Shieldra handle AI and my data?
Shieldra is bring-your-own-key for AI. You supply your own provider API key in Settings, and prompts flow directly between your tenant and that provider. Prompt content is not logged or retained beyond ephemeral processing, and your data is never used to train AI models.
How do I report a security vulnerability?
Email security@shieldra.ai with the details. We respond within 24 hours and ask that you not publicly disclose the vulnerability until it has been addressed. We acknowledge researchers who report responsibly.