HIPAA Compliance definition
HIPAA compliance is the practice of meeting the requirements of the US Health Insurance Portability and Accountability Act of 1996 and its rules for protecting health information. It applies to covered entities, such as healthcare providers, health plans and clearinghouses, and to their business associates, requiring safeguards for protected health information, limits on its use and breach notification.
Who must comply with HIPAA?
HIPAA applies to covered entities: health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard transactions electronically, such as billing insurers. It also applies to business associates, meaning vendors that create, receive, maintain or transmit protected health information on a covered entity's behalf, such as cloud hosts, billing companies and software developers. Business associates must sign a business associate agreement (BAA) and are directly liable for certain requirements. Subcontractors of business associates are covered too.
Scope is narrower than many assume. A consumer fitness or wellness app that is not offered on behalf of a covered entity is often outside HIPAA, though other laws, such as the FTC Health Breach Notification Rule or state privacy laws, may still apply. HIPAA is a US law and does not cover patients in other countries, which have their own regulations. Getting scope right early avoids both under- and over-engineering.
The main HIPAA rules
HIPAA's requirements are set out in several rules issued and enforced by the US Department of Health and Human Services, mainly through its Office for Civil Rights. Software teams most often work with the Security Rule, which applies to electronic protected health information, but the Privacy and Breach Notification Rules shape product features too. State laws can add further requirements.
- Privacy Rule: limits uses and disclosures of PHI and gives patients rights to access their records.
- Security Rule: administrative, physical and technical safeguards for electronic PHI.
- Breach Notification Rule: notifying individuals, HHS and sometimes media after breaches of unsecured PHI.
- Enforcement Rule: investigations and civil money penalties.
What counts as protected health information?
Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. It includes diagnoses, test results, treatment records and billing information when linked to identifiers such as names, addresses, dates, phone numbers, email addresses, medical record numbers or device identifiers. Properly de-identified data, using either the Safe Harbor method of removing specified identifiers or an expert determination, is not PHI. Minimum necessary use is another core principle: share only what each task requires.
HIPAA for software and cloud teams
There is no official government HIPAA certification for software; compliance is demonstrated through risk analysis, implemented safeguards and documentation. Technical safeguards include unique user IDs, access controls, audit logging, automatic logoff, integrity controls and transmission security. Encryption is an addressable specification, but encrypting PHI at rest and in transit is standard practice and can affect breach notification obligations. Use only cloud services covered by your provider's BAA, such as eligible AWS, Azure or Google Cloud services.
Nexzem builds telemedicine and healthcare software with these safeguards and signs BAAs where it acts as a business associate. This page is general information, not legal advice; consult a qualified healthcare compliance lawyer about your obligations. Covered entities should review vendors' safeguards before sharing any PHI.