“HIPAA compliant” as a product claim
There is no certification and no certifying body. What exists is a defensible risk analysis, implemented safeguards, and executed business associate agreements.
HIPAA is the US federal framework for protecting identifiable health information. Its Privacy Rule governs use and disclosure, its Security Rule mandates administrative, physical and technical safeguards for electronic records, and its Breach Notification Rule sets disclosure obligations. It binds covered entities — providers, health plans and clearinghouses — and the business associates handling data on their behalf.
The most consequential thing to establish early is whether HIPAA applies to you at all. A great many digital health products are neither covered entities nor business associates. A direct-to-consumer wellness app with no provider relationship typically falls outside HIPAA entirely and lands instead under FTC authority and the Health Breach Notification Rule, which has been enforced actively in recent years. Claiming to be “HIPAA compliant” when you are out of scope is both meaningless and a misrepresentation risk.
Where you are a business associate, the obligations arrive through the BAA. The Security Rule’s distinction between required and addressable specifications is widely misread: addressable does not mean optional, it means implement it or document why an equivalent alternative is reasonable.
There is no certification and no certifying body. What exists is a defensible risk analysis, implemented safeguards, and executed business associate agreements.
It requires either implementation or a documented, reasoned alternative. Silence is a finding.
Different scope, different triggers, different rights. A product serving both markets needs both analyses, not the stricter one applied twice.
Only if you are a covered entity or a business associate acting for one. Many digital health products are neither — a direct-to-consumer wellness app with no provider relationship typically falls outside HIPAA entirely and lands under FTC authority and the Health Breach Notification Rule instead, which has been actively enforced in recent years.
No. There is no certification and no certifying body, so any vendor badge claiming otherwise is marketing. What exists is a documented risk analysis, implemented administrative, physical and technical safeguards, and executed business associate agreements. Claiming compliance while out of scope is a misrepresentation risk in itself.
Not optional. An addressable specification must either be implemented, or you must document why it is not reasonable and appropriate and what equivalent alternative you put in place instead. Silently skipping one is a finding; the flexibility is in the method, not in whether you address it.
Working out how HIPAA applies to what you are building is usually the first conversation.
Get in touch →