Skip to content

HIPAA

The US healthcare privacy law. No official certification, and liability that travels by contract.

What HIPAA is

HIPAA is a US federal law governing the protection of identifiable health information. It is structured as a set of rules, and the three that matter in practice are the Privacy Rule, on use and disclosure of information, the Security Rule, on safeguards for electronic protected health information, and the Breach Notification Rule.

It is enforced by the Office for Civil Rights at the Department of Health and Human Services.

Who HIPAA applies to

Two figures:

  • Covered entities: healthcare providers, health plans and healthcare clearinghouses
  • Business associates: anyone processing health information on behalf of a covered entity, software vendors included

If you sell software to a US healthcare provider and you touch patient information, you are a business associate and HIPAA reaches you by contract, through a Business Associate Agreement.

For a European healthtech company, that contract is the usual route by which HIPAA enters the picture.

What HIPAA requires

The Security Rule, safeguards in three blocks: administrative, physical and technical. It covers risk analysis, access management, audit controls, integrity and transmission security.

The Privacy Rule, limits on the use and disclosure of protected health information, and patient rights over their data.

The Breach Notification Rule, an obligation to notify breaches to those affected, to the authority and, depending on scale, to the media.

Business Associate Agreements, mandatory contracts that pass obligations along the chain.

How HIPAA is demonstrated

There is no official certification. The US authority certifies and accredits nobody, and any HIPAA compliance seal comes from a private third party with no official standing.

What gets demonstrated is documentation: risk analysis, policies, implemented safeguards, training, and the agreements with business associates.

Frequently asked questions

Is there a HIPAA certification?

No. The US authority does not certify HIPAA compliance. The seals sold in the market come from private third parties and attest nothing to the regulator.

Does HIPAA apply to me if my company is in Europe?

It can apply by contract. If you process health information on behalf of a US covered entity, the Business Associate Agreement passes obligations to you regardless of where you are.

HIPAA · Zerod