Understand the three rules
HIPAA governs how protected health information (PHI) is handled in the United States. If you are a health-tech company, you are most often a business associate — a vendor handling PHI on behalf of a covered entity — which means HIPAA applies to you directly. It is organised into three rules.
- Privacy Rule: governs the use and disclosure of PHI, and individuals' rights over their health information.
- Security Rule: sets requirements for protecting electronic PHI (ePHI) through administrative, physical and technical safeguards.
- Breach Notification Rule: requires notification of breaches of unsecured PHI within defined timeframes.
The Security Rule safeguards
The Security Rule is where most technical work sits. It is organised into three safeguard categories, each with required and addressable specifications.
| Safeguard | Examples |
|---|---|
| Administrative | Risk analysis, workforce training, access management, contingency planning |
| Physical | Facility access controls, workstation and device security, media disposal |
| Technical | Access controls, audit logging, encryption, integrity and transmission security |
The risk analysis is the anchor
The Security Rule requires an accurate, thorough risk analysis of the risks to ePHI, and a plan to manage them. This is not a one-off document; it is expected to be maintained. Enforcement actions frequently cite a missing or inadequate risk analysis as the root failure, so treat it as the anchor of your programme.
Scope PHI
Where ePHI lives
Risk analysis
Threats to ePHI
Safeguards
Admin/physical/tech
BAAs
Down the chain
Evidence
Maintain & prove
Business Associate Agreements
A Business Associate Agreement (BAA) is the contract that flows HIPAA obligations down the chain. You need a BAA with the covered entities you serve, and with any of your own subcontractors that touch PHI. No BAA, no lawful sharing of PHI. HIPAA also overlaps heavily with ISO 27001 and SOC 2, so most of the security work — and its evidence — is reusable.
Common pitfalls to avoid
- Skipping or under-scoping the risk analysis — the single most-cited enforcement failure.
- Missing BAAs with subcontractors that handle PHI on your behalf.
- Treating addressable specifications as optional rather than documenting your reasoning.