Compliance

HIPAA Compliance Checklist for Health-Tech Companies

If your product touches protected health information, HIPAA applies. Here's a practical checklist of the safeguards and agreements you need.

The Pelta Team8 min readUpdated Part of HIPAA

HIPAA governs how protected health information (PHI) is handled in the United States. If you are a health-tech company, you are most often a business associate — a vendor handling PHI on behalf of a covered entity — which means HIPAA applies to you directly. This checklist covers what you need in place.

This is a general guide, not legal advice. Confirm your status and obligations under HIPAA with qualified counsel.

Understand the three rules

  • Privacy Rule: governs the use and disclosure of PHI, and individuals' rights over their health information.
  • Security Rule: sets requirements for protecting electronic PHI (ePHI) through administrative, physical and technical safeguards.
  • Breach Notification Rule: requires notification of breaches of unsecured PHI within defined timeframes.

The Security Rule safeguards

The Security Rule is where most technical work sits. It is organised into three safeguard categories, each with required and addressable specifications.

HIPAA Security Rule safeguards
SafeguardExamples
AdministrativeRisk analysis, workforce training, access management, contingency planning
PhysicalFacility access controls, workstation and device security, media disposal
TechnicalAccess controls, audit logging, encryption, integrity and transmission security

Business Associate Agreements

A Business Associate Agreement (BAA) is the contract that flows HIPAA obligations down the chain. You need a BAA in place with covered entities you serve, and with any of your own subcontractors that touch PHI. No BAA, no lawful sharing of PHI.

Run a risk analysis — it's the anchor

The Security Rule requires an accurate, thorough risk analysis of the risks to ePHI, and a plan to manage them. This is not a one-off document; it is expected to be maintained. Enforcement actions frequently cite a missing or inadequate risk analysis as the root failure, so treat it as the anchor of your programme rather than a formality.

Evidence it continuously

As with every framework here, meeting the safeguards is only half the job — you have to demonstrate them, and demonstrate that your business associates do too. Mapping HIPAA safeguards to linked evidence, and tracking the risk of the vendors that touch PHI, is what makes HIPAA sustainable. HIPAA also overlaps heavily with ISO 27001 and SOC 2, so most of the security work is reusable.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

SOC 2

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding HIPAA

~55% carried over
Carried over from SOC 2 New work for your team

Auto-completed from your existing program

Access controlAudit loggingEncryptionRisk analysisContingency planningVendor oversight

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

Frequently asked questions

Who must comply with HIPAA?+

Covered entities (such as healthcare providers, health plans and clearinghouses) and their business associates — vendors that handle protected health information on their behalf. Health-tech companies are usually business associates.

What are the HIPAA Security Rule safeguards?+

Three categories: administrative (risk analysis, training, access management), physical (facility and device controls) and technical (access controls, audit logging, encryption). Each has required and addressable specifications.

What is a Business Associate Agreement?+

A BAA is the contract that passes HIPAA obligations to a vendor handling PHI. You need one with the covered entities you serve and with any subcontractors that touch PHI on your behalf.

Is a HIPAA risk analysis mandatory?+

Yes. The Security Rule requires an accurate and thorough risk analysis of risks to electronic PHI, maintained over time. A missing or inadequate risk analysis is a frequent cause of enforcement findings.

Does SOC 2 cover HIPAA?+

They overlap on security controls but are not the same — SOC 2 is a broad attestation, HIPAA is a specific legal requirement for PHI. Much of the security evidence can be reused across both.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.