Skip to content

What is HIPAA Compliance?

Cybersecurity & Compliance, explained by the engineers who build it. Definition, how it works, use cases and common questions.

HIPAA Compliance definition

HIPAA compliance is the practice of meeting the requirements of the US Health Insurance Portability and Accountability Act of 1996 and its rules for protecting health information. It applies to covered entities, such as healthcare providers, health plans and clearinghouses, and to their business associates, requiring safeguards for protected health information, limits on its use and breach notification.

Who must comply with HIPAA?

HIPAA applies to covered entities: health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard transactions electronically, such as billing insurers. It also applies to business associates, meaning vendors that create, receive, maintain or transmit protected health information on a covered entity's behalf, such as cloud hosts, billing companies and software developers. Business associates must sign a business associate agreement (BAA) and are directly liable for certain requirements. Subcontractors of business associates are covered too.

Scope is narrower than many assume. A consumer fitness or wellness app that is not offered on behalf of a covered entity is often outside HIPAA, though other laws, such as the FTC Health Breach Notification Rule or state privacy laws, may still apply. HIPAA is a US law and does not cover patients in other countries, which have their own regulations. Getting scope right early avoids both under- and over-engineering.

The main HIPAA rules

HIPAA's requirements are set out in several rules issued and enforced by the US Department of Health and Human Services, mainly through its Office for Civil Rights. Software teams most often work with the Security Rule, which applies to electronic protected health information, but the Privacy and Breach Notification Rules shape product features too. State laws can add further requirements.

  • Privacy Rule: limits uses and disclosures of PHI and gives patients rights to access their records.
  • Security Rule: administrative, physical and technical safeguards for electronic PHI.
  • Breach Notification Rule: notifying individuals, HHS and sometimes media after breaches of unsecured PHI.
  • Enforcement Rule: investigations and civil money penalties.

What counts as protected health information?

Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. It includes diagnoses, test results, treatment records and billing information when linked to identifiers such as names, addresses, dates, phone numbers, email addresses, medical record numbers or device identifiers. Properly de-identified data, using either the Safe Harbor method of removing specified identifiers or an expert determination, is not PHI. Minimum necessary use is another core principle: share only what each task requires.

HIPAA for software and cloud teams

There is no official government HIPAA certification for software; compliance is demonstrated through risk analysis, implemented safeguards and documentation. Technical safeguards include unique user IDs, access controls, audit logging, automatic logoff, integrity controls and transmission security. Encryption is an addressable specification, but encrypting PHI at rest and in transit is standard practice and can affect breach notification obligations. Use only cloud services covered by your provider's BAA, such as eligible AWS, Azure or Google Cloud services.

Nexzem builds telemedicine and healthcare software with these safeguards and signs BAAs where it acts as a business associate. This page is general information, not legal advice; consult a qualified healthcare compliance lawyer about your obligations. Covered entities should review vendors' safeguards before sharing any PHI.

HIPAA Compliance: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Is there an official HIPAA certification?

No. The US Department of Health and Human Services does not certify software, vendors or organizations as HIPAA compliant. Third-party assessments and attestations exist, and they can help demonstrate due diligence, but compliance rests on implementing the required safeguards, conducting risk analyses, maintaining documentation and signing business associate agreements where needed.

Does HIPAA apply to health apps?

It depends on who offers the app and how. An app provided by or on behalf of a covered entity, such as a hospital's patient portal, handles PHI under HIPAA. A consumer app that people download independently to track health data is often not covered by HIPAA, though FTC rules and state laws may apply.

What is a business associate agreement?

A business associate agreement is a contract required by HIPAA between a covered entity and a vendor that handles PHI on its behalf. It defines permitted uses of PHI, requires appropriate safeguards, sets breach reporting duties and requires subcontractors to accept the same restrictions. Major cloud providers offer BAAs for eligible services.

Keep exploring the cybersecurity & compliance glossary

Need HIPAA Compliance in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.