Humanize Health

HIPAAUS Health Data Privacy

HIPAA is the US federal framework for protecting identifiable health information. Its Privacy Rule governs use and disclosure, its Security Rule mandates administrative, physical and technical safeguards for electronic records, and its Breach Notification Rule sets disclosure obligations. It binds covered entities — providers, health plans and clearinghouses — and the business associates handling data on their behalf.

Full title
Health Insurance Portability and Accountability Act of 1996
Issued by
US Congress; enforced by HHS Office for Civil Rights
Applies
United States — covered entities and their business associates

What it covers

In practice

The most consequential thing to establish early is whether HIPAA applies to you at all. A great many digital health products are neither covered entities nor business associates. A direct-to-consumer wellness app with no provider relationship typically falls outside HIPAA entirely and lands instead under FTC authority and the Health Breach Notification Rule, which has been enforced actively in recent years. Claiming to be “HIPAA compliant” when you are out of scope is both meaningless and a misrepresentation risk.

Where you are a business associate, the obligations arrive through the BAA. The Security Rule’s distinction between required and addressable specifications is widely misread: addressable does not mean optional, it means implement it or document why an equivalent alternative is reasonable.

Where teams get it wrong

“HIPAA compliant” as a product claim

There is no certification and no certifying body. What exists is a defensible risk analysis, implemented safeguards, and executed business associate agreements.

Reading “addressable” as “optional”

It requires either implementation or a documented, reasoned alternative. Silence is a finding.

Assuming HIPAA covers what GDPR covers

Different scope, different triggers, different rights. A product serving both markets needs both analyses, not the stricter one applied twice.

Common questions

Does HIPAA apply to our app?

Only if you are a covered entity or a business associate acting for one. Many digital health products are neither — a direct-to-consumer wellness app with no provider relationship typically falls outside HIPAA entirely and lands under FTC authority and the Health Breach Notification Rule instead, which has been actively enforced in recent years.

Can we get HIPAA certified?

No. There is no certification and no certifying body, so any vendor badge claiming otherwise is marketing. What exists is a documented risk analysis, implemented administrative, physical and technical safeguards, and executed business associate agreements. Claiming compliance while out of scope is a misrepresentation risk in itself.

What does “addressable” mean in the Security Rule?

Not optional. An addressable specification must either be implemented, or you must document why it is not reasonable and appropriate and what equivalent alternative you put in place instead. Silently skipping one is a finding; the flexibility is in the method, not in whether you address it.

Working out how HIPAA applies to what you are building is usually the first conversation.

Get in touch →