HIPAA compliance,
from risk analysis to BAA.
What HIPAA compliance means for healthcare organisations and the SaaS vendors that serve them: who must comply, what the Privacy, Security and Breach Notification Rules ask, how to run the risk analysis, what goes in a business associate agreement, and a checklist. A practitioner's summary, not legal advice.
Last updated Published by TryTrustableNot legal advice
HIPAA compliance means meeting the Health Insurance Portability and Accountability Act rules that protect health information in the United States. It applies to covered entities (health plans, healthcare clearinghouses and providers that bill electronically) and to their business associates, including SaaS vendors that handle protected health information for them. In practice it means a documented risk analysis, administrative, physical and technical safeguards for electronic health data, limits on how health information is used and disclosed, business associate agreements with vendors, and breach notification within 60 days. There is no official HIPAA certification.
What is HIPAA compliance?
HIPAA is a 1996 US federal law. Its Administrative Simplification rules, written by the Department of Health and Human Services (HHS), set national standards for protecting health information: the Privacy Rule (in force since 2003), the Security Rule (since 2005), the Breach Notification Rule (added after the HITECH Act of 2009) and the Enforcement Rule. HIPAA compliance means having the safeguards, policies, contracts and records those rules require, and being able to show them to the HHS Office for Civil Rights (OCR), which enforces them. State Attorneys General can enforce HIPAA too.
Who must comply with HIPAA?
- Covered entities: health plans, healthcare clearinghouses, and healthcare providers that conduct standard transactions, such as billing insurers, electronically.
- Business associates: anyone that creates, receives, maintains or transmits protected health information on a covered entity's behalf. That includes cloud hosting, EHR and practice-management software, billing companies, IT providers and many SaaS tools. Since the 2013 Omnibus Rule, business associates are directly liable, and so are their subcontractors.
A consumer health app that people use on their own, with no covered entity involved, is often outside HIPAA, though state laws and the FTC may still apply. Our Do I need HIPAA? checker walks through the tests.
The HIPAA rules at a glance
| Rule | Where | What it requires |
|---|---|---|
| Privacy Rule | 45 CFR 164 Subpart E | When protected health information (PHI) may be used and disclosed, the minimum necessary standard, the notice of privacy practices, and patients' rights to access and amend their records |
| Security Rule | 45 CFR 164 Subpart C | Administrative, physical and technical safeguards for electronic PHI, starting with a risk analysis |
| Breach Notification Rule | 45 CFR 164.400 to 164.414 | Notice to individuals, HHS and sometimes the media after a breach of unsecured PHI |
| Enforcement Rule | 45 CFR 160 Subparts C to E | Investigations, civil money penalties and hearings |
Protected health information (PHI) is individually identifiable health information held or sent by a covered entity or business associate, in any form. Electronic PHI (ePHI) is the subset the Security Rule covers.
The HIPAA Privacy Rule
The Privacy Rule controls how PHI is used and disclosed. Uses for treatment, payment and healthcare operations are allowed without the patient's authorisation; most others, such as marketing, need it. The minimum necessary standard (164.502(b)) requires limiting PHI to what a task needs, which in practice means role-based access. Covered entities must give patients a notice of privacy practices and honour their rights, including access to their records within 30 days, extendable once by 30 days (164.524).
The HIPAA Security Rule
The Security Rule requires covered entities and business associates to protect the confidentiality, integrity and availability of ePHI with safeguards scaled to their size, complexity and risks (164.306).
| Safeguard | Examples of what auditors and OCR look for |
|---|---|
| Administrative (164.308) | Risk analysis and risk management plan, a named security official, workforce training and sanctions, access authorisation, incident procedures, contingency and backup plans, periodic evaluation, business associate agreements |
| Physical (164.310) | Facility access controls, workstation use and security, device and media disposal and re-use |
| Technical (164.312) | Unique user IDs, emergency access, automatic logoff, encryption, audit logs, integrity controls, authentication, transmission security |
| Documentation (164.316) | Written policies and procedures, kept for six years from creation or last effective date, and reviewed periodically |
Some specifications are "required" and some "addressable". Addressable does not mean optional: you implement it, an equivalent, or document why neither is reasonable.
Status of the update. HHS proposed a major overhaul of the Security Rule on 6 January 2025, which would remove the addressable distinction and make encryption, multi-factor authentication, asset inventories and annual compliance audits explicit. As of October 2026 it remains a proposal: no final rule has been published in the Federal Register. Many organisations are adopting those controls anyway, because they reflect what OCR already expects.
How to do a HIPAA risk assessment
The risk analysis is the first required specification of the Security Rule (164.308(a)(1)(ii)(A)) and a failure OCR cites again and again in its settlements. It must be accurate and thorough, and cover all ePHI:
- Find every place ePHI lives or moves: systems, databases, backups, laptops, vendors and integrations.
- Identify threats and vulnerabilities for each, from ransomware and misconfiguration to lost devices and insider misuse.
- Assess current controls, then rate likelihood and impact to get a risk level.
- Write a risk management plan (164.308(a)(1)(ii)(B)) that reduces each risk to a reasonable and appropriate level, with owners and dates.
- Document and repeat regularly and whenever systems change. A risk register keeps it current; see also risk assessment.
The Breach Notification Rule
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor risk assessment shows a low probability that the data was compromised (164.402). PHI encrypted to HHS guidance is not "unsecured". After a breach:
- Individuals: without unreasonable delay and no later than 60 calendar days after discovery.
- HHS: at the same time for breaches affecting 500 or more people; smaller breaches can be logged and reported within 60 days of the end of the calendar year.
- Media: prominent outlets when more than 500 residents of one state or jurisdiction are affected.
- Business associates must tell the covered entity within 60 days of discovery; most BAAs set a much shorter limit.
See incident management, the free incident response plan and the breach deadline calculator.
Business associate agreements (BAAs)
A covered entity may share PHI with a business associate only under a written contract that meets 164.504(e). A BAA must, among other things, limit the vendor's use of PHI to the contracted services, require Security Rule safeguards, require reporting of breaches and security incidents, flow the same terms down to subcontractors, support patients' access and amendment rights, make records available to HHS, and require return or destruction of PHI at the end. If you are a SaaS vendor selling to US healthcare, expect a customer's BAA in the first contract, and check that each of your own subprocessors that touches PHI has signed one with you. See vendor risk management.
HIPAA compliance checklist
- Decide whether you are a covered entity, a business associate, or neither.
- Name a privacy official and a security official.
- Map where PHI and ePHI are created, stored and sent, including vendors.
- Run and document the Security Rule risk analysis, and a risk management plan.
- Implement the administrative, physical and technical safeguards: access control, MFA, encryption, audit logging, backups and a tested contingency plan.
- Write the policies and procedures, and keep them for six years.
- Train the workforce on hire and periodically, and apply sanctions for violations.
- Sign BAAs with every business associate and subcontractor that touches PHI.
- Apply minimum necessary access, and (covered entities) publish the notice of privacy practices.
- Set up breach response with the 60-day clocks and the four-factor assessment.
- Handle patient access requests within 30 days.
- Evaluate the programme periodically and after major changes.
HIPAA violation penalties
| Tier (culpability) | Per violation | Calendar-year cap |
|---|---|---|
| Did not know, and could not reasonably have known | $145 to $73,011 | $2,190,294 |
| Reasonable cause, not wilful neglect | $1,461 to $73,011 | $2,190,294 |
| Wilful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| Wilful neglect, not corrected | $73,011 to $2,190,294 | $2,190,294 |
Inflation-adjusted amounts in 45 CFR 102.3 (2025 adjustment). Caps apply per identical provision violated. Criminal penalties under 42 U.S.C. 1320d-6 are separate and enforced by the Department of Justice.
OCR resolves most cases with corrective action plans and settlements, and a missing or incomplete risk analysis features in many of them.
HIPAA vs GDPR
| HIPAA | GDPR | |
|---|---|---|
| Scope | Health information held by covered entities and their business associates in the US | All personal data of people in the EU, processed by almost any organisation |
| Who it binds | Covered entities and business associates only | Controllers and processors |
| Health apps outside healthcare | Often not covered | Covered; health data is special category data |
| Legal basis | Use and disclosure allowed for treatment, payment and operations without authorisation | Needs a lawful basis, and an Article 9 condition for health data |
| Breach notice | Individuals within 60 days; HHS and media for 500+ | Regulator within 72 hours; individuals if high risk |
| Vendor contract | Business associate agreement | Article 28 data processing agreement |
| Maximum penalty | $2,190,294 per year per provision (2025 figures) | EUR 20 million or 4% of global turnover |
A US health tech company with European users may need both: HIPAA for the PHI it handles for US covered entities, and GDPR for everyone in the EU. Health data processed outside HIPAA can also fall under state privacy laws, such as the CCPA and the other state laws, which exempt PHI governed by HIPAA but not other health data.
HIPAA vs SOC 2
HIPAA is a law; SOC 2 is a voluntary attestation by a CPA firm. Healthcare customers often ask vendors for both: a signed BAA for the legal duty, and a SOC 2 report as independent evidence that controls work. The controls overlap heavily, so one control set can serve both.
How TryTrustable supports HIPAA compliance
HIPAA's requirements are modelled in TryTrustable's shared control library, mapped to the same controls as SOC 2, ISO 27001 and the other frameworks you run. Evidence from GitHub, AWS and GCP lands in a timestamped evidence ledger, policies live alongside the controls they support, risks sit in a register with owners and dates, and the vendor register tracks tiers, reviews and the evidence on file for each supplier. See framework coverage and the platform. A tool supports the programme; it does not make you HIPAA compliant by itself.
The things people ask us
Is there an official HIPAA certification?
No. HHS does not certify organisations or products as HIPAA compliant. Third-party assessments exist, but they are opinions, not a government certification. What matters is your risk analysis, safeguards, BAAs and records.
Does HIPAA apply to SaaS companies?
Yes, if the SaaS company creates, receives, maintains or transmits protected health information for a covered entity or another business associate. It is then a business associate and must meet the Security Rule and sign BAAs.
What is the HIPAA minimum necessary rule?
A Privacy Rule standard (45 CFR 164.502(b)) that requires limiting uses, disclosures and requests for PHI to the minimum needed for the purpose. It does not apply to disclosures for treatment or to the patient.
How long do you have to report a HIPAA breach?
Individuals must be told without unreasonable delay and within 60 calendar days of discovery. Breaches of 500 or more must also go to HHS within that time; smaller ones within 60 days of the end of the year.
How often should a HIPAA risk assessment be done?
The rule does not set a fixed interval. It requires the analysis to be accurate and kept current, so review it at least yearly and whenever systems, vendors or threats change significantly.
Has the HIPAA Security Rule been updated?
HHS proposed an update on 6 January 2025. As of October 2026 no final rule has been published, so the existing Security Rule still applies.
What is the difference between HIPAA and GDPR?
HIPAA covers health information held by US healthcare organisations and their vendors. GDPR covers all personal data of people in the EU and treats health data as special category data. GDPR also requires regulator notification of breaches within 72 hours.
Run HIPAA on the controls you already have.
Thirty minutes: we map your SOC 2 or ISO 27001 controls to the Security Rule and show the evidence that already counts.