Back to Frameworks
Frameworks

HIPAA

Framework Name

Health Insurance Portability and Accountability Act (HIPAA)

Type

Mandatory

Region / Jurisdiction

United States

Enforcing Body / Certifying Party

US Department of Health and Human Services, Office for Civil Rights (OCR)

Penalty / Consequence of Non-Compliance

Civil penalties on a tiered scale, ranging from roughly $100 to over $2 million per violation category per year depending on the level of negligence, adjusted periodically for inflation. Willful violations can also carry criminal penalties, including fines and imprisonment

What It Is & Why It Matters

HIPAA is the US federal law governing how healthcare providers, health plans, and their business partners protect patient health information. It applies to "covered entities," organizations like hospitals, doctors' offices, and insurers, and to their "business associates," any vendor or partner that handles patient data on their behalf, which is why many software companies serving healthcare end up under HIPAA even though they aren't a hospital themselves. In practice, HIPAA is made up of several distinct rules: the Privacy Rule governs how health information can be used and shared, the Security Rule sets safeguards for electronic health information specifically, and the Breach Notification Rule requires reporting when patient data is exposed.

It matters because health information is some of the most sensitive personal data that exists, and HIPAA has shaped how the entire US healthcare industry, and everyone selling into it, handles data since the late 1990s. Enforcement is active: OCR regularly investigates complaints and breaches, and fines are real and public. For any company selling software or services into healthcare, the ability to sign a Business Associate Agreement, meaning you can demonstrably meet HIPAA's requirements, is often a hard prerequisite before a deal can even begin.

Who Needs It

  • You are a healthcare provider, health plan, or healthcare clearinghouse in the US
  • You are a vendor, contractor, or software company that creates, receives, stores, or transmits patient health data on behalf of a healthcare organization
  • A healthcare customer or prospect has asked you to sign a Business Associate Agreement (BAA)
  • You are building a product in the digital health or health-tech space and need to understand your obligations from the start
Book A Demo