HIPAA governs how protected health information (PHI) is handled in the United States. If you are a health-tech company, you are most often a business associate — a vendor handling PHI on behalf of a covered entity — which means HIPAA applies to you directly. This checklist covers what you need in place.
Understand the three rules
- Privacy Rule: governs the use and disclosure of PHI, and individuals' rights over their health information.
- Security Rule: sets requirements for protecting electronic PHI (ePHI) through administrative, physical and technical safeguards.
- Breach Notification Rule: requires notification of breaches of unsecured PHI within defined timeframes.
The Security Rule safeguards
The Security Rule is where most technical work sits. It is organised into three safeguard categories, each with required and addressable specifications.
| Safeguard | Examples |
|---|---|
| Administrative | Risk analysis, workforce training, access management, contingency planning |
| Physical | Facility access controls, workstation and device security, media disposal |
| Technical | Access controls, audit logging, encryption, integrity and transmission security |
Business Associate Agreements
A Business Associate Agreement (BAA) is the contract that flows HIPAA obligations down the chain. You need a BAA in place with covered entities you serve, and with any of your own subcontractors that touch PHI. No BAA, no lawful sharing of PHI.
Run a risk analysis — it's the anchor
The Security Rule requires an accurate, thorough risk analysis of the risks to ePHI, and a plan to manage them. This is not a one-off document; it is expected to be maintained. Enforcement actions frequently cite a missing or inadequate risk analysis as the root failure, so treat it as the anchor of your programme rather than a formality.
Evidence it continuously
As with every framework here, meeting the safeguards is only half the job — you have to demonstrate them, and demonstrate that your business associates do too. Mapping HIPAA safeguards to linked evidence, and tracking the risk of the vendors that touch PHI, is what makes HIPAA sustainable. HIPAA also overlaps heavily with ISO 27001 and SOC 2, so most of the security work is reusable.
SOC 2
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding HIPAA
~55% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
Frequently asked questions
Who must comply with HIPAA?+
Covered entities (such as healthcare providers, health plans and clearinghouses) and their business associates — vendors that handle protected health information on their behalf. Health-tech companies are usually business associates.
What are the HIPAA Security Rule safeguards?+
Three categories: administrative (risk analysis, training, access management), physical (facility and device controls) and technical (access controls, audit logging, encryption). Each has required and addressable specifications.
What is a Business Associate Agreement?+
A BAA is the contract that passes HIPAA obligations to a vendor handling PHI. You need one with the covered entities you serve and with any subcontractors that touch PHI on your behalf.
Is a HIPAA risk analysis mandatory?+
Yes. The Security Rule requires an accurate and thorough risk analysis of risks to electronic PHI, maintained over time. A missing or inadequate risk analysis is a frequent cause of enforcement findings.
Does SOC 2 cover HIPAA?+
They overlap on security controls but are not the same — SOC 2 is a broad attestation, HIPAA is a specific legal requirement for PHI. Much of the security evidence can be reused across both.