TAC and HIPAA
How TAC maps to HIPAA Technical Safeguards for protecting electronic Protected Health Information.
Note: This guide describes how TAC’s technical capabilities align to HIPAA Technical Safeguard requirements under 45 CFR Part 164. HIPAA compliance requires a complete programme including administrative and physical safeguards. PortSys recommends working with qualified healthcare compliance advisors.
45 CFR § 164.312
TAC directly addresses all four Technical Safeguard standards.
Unique Advantages
Three capabilities that make TAC especially effective in healthcare environments.
Legacy EHR Security
Most healthcare organisations rely on legacy EHR systems that cannot support SAML, OIDC, or FIDO2. TAC injects MFA, device posture, and continuous validation via reverse proxy — without changing the application or its code.
Single-Tenant Isolation
Every TAC deployment is a dedicated, isolated Secure Virtual Appliance. Patient data from your organisation never co-mingles with another healthcare organisation’s environment.
Continuous Validation
Unlike point-in-time authentication, TAC evaluates device posture on every request. A clinician’s device that falls out of compliance mid-session loses access immediately — protecting ePHI at all times.
Questions About HIPAA Compliance?
Our team includes healthcare compliance specialists who can walk through your specific environment and ePHI system inventory.