Do I need to comply with HIPAA?
HIPAA applies to health plans, clearinghouses and most US health care providers, and to the vendors that handle protected health information for them. Answer four questions to see which you are, whether you need a business associate agreement, and what follows.
HIPAA applies if you are a covered entity (a health plan, a clearinghouse, or a provider that bills electronically) or a business associate: a vendor that creates, receives, maintains or transmits protected health information on a covered entity's behalf. A SaaS company storing patient data for US clinics is a business associate, must sign a BAA, and must meet the Security Rule.
Result
A vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate, and a vendor doing so for a business associate is one too (a subcontractor). You are directly liable under the Security Rule and for breach notification, and you need a BAA with each customer. HIPAA sets no certification; buyers often ask for SOC 2 or HITRUST as evidence.
- Now: sign BAAs before PHI flows, and list every sub-processor that will touch it.
- Security Rule: do a written risk analysis first; every other safeguard follows from it.
- Devices: laptops that reach PHI need encryption and remote wipe: see the MDM checker.
Covered entity or business associate
HIPAA's rules apply to covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in a standard transaction) and to business associates. A business associate is a person who, other than as a member of the workforce, creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides services such as legal, accounting, consulting, data aggregation or administration that involve disclosure of PHI. A subcontractor that handles PHI for a business associate is itself a business associate. The definitions are in 45 CFR 160.103.
What PHI is
Protected health information is individually identifiable health information, held or transmitted in any form or medium. It excludes education records under FERPA, employment records a covered entity holds as an employer, and information about a person dead for more than 50 years. Information de-identified under 164.514 is not PHI.
The business associate agreement
A covered entity may let a business associate handle PHI only with satisfactory written assurance, a BAA, that the associate will safeguard it. The BAA limits use and disclosure, requires Security Rule safeguards, breach reporting, return or destruction of PHI at the end, and the same terms for subcontractors. A business associate must report a breach of unsecured PHI to the covered entity without unreasonable delay and no later than 60 days after discovery.
Penalties
Civil penalties have four tiers by culpability, set in 45 CFR 160.404 and adjusted for inflation in 45 CFR 102.3. The 2025 adjusted amounts per violation are: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. Identical violations are capped at $2,190,294 per calendar year. The amounts are adjusted annually.
A proposed Security Rule update
In January 2025 HHS proposed a major update to the Security Rule (90 FR 898), which among other things would remove the distinction between required and addressable specifications. It is a proposal. Until a final rule is published, the current text applies: encryption, for example, remains addressable.
Sources
- eCFR: 45 CFR 160.103 Definitions
- eCFR: 45 CFR 160.404 Amount of a civil money penalty
- eCFR: 45 CFR 102.3 Penalty adjustment table
- eCFR: 45 CFR 164.504 Uses and disclosures: organizational requirements (BAA)
- eCFR: 45 CFR Part 164 Subpart C, Security Rule
- eCFR: 45 CFR 164.410 Notification by a business associate
- Federal Register: HIPAA Security Rule proposed rule, 90 FR 898 (6 January 2025)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Does HIPAA apply to my company?
Only if you are a covered entity (a health plan, a clearinghouse, or a provider billing electronically) or a business associate handling PHI on behalf of one. Holding health data is not enough on its own: a consumer app used directly by individuals is usually outside HIPAA.
Is a SaaS company a business associate?
Yes, if it creates, receives, maintains or transmits PHI on behalf of a covered entity, which includes storing it. Hosting providers and other sub-processors of that SaaS company are business associates too.
Do I need a BAA?
Yes, before any PHI flows between a covered entity and a business associate, or between a business associate and its subcontractor. Without one, the covered entity cannot lawfully share the PHI with you.
Is there a HIPAA certification?
No. The HIPAA rules set no certification scheme, so no one can certify you as HIPAA compliant in the way ISO 27001 certifies. Buyers often ask for a SOC 2 report or HITRUST certification as evidence that your safeguards meet the Security Rule.
What are the HIPAA penalties in 2025?
Per violation, from $145 where the entity did not know, up to $2,190,294 for uncorrected willful neglect, with a calendar-year cap of $2,190,294 for identical violations. These are the inflation-adjusted figures in 45 CFR 102.3.
Does HIPAA apply outside the United States?
The business associate definition turns on what you do for a covered entity, not where you are. A company in India or Europe that stores PHI for a US hospital is treated as a business associate and will be asked to sign a BAA.
Is encryption required under HIPAA?
Under the current Security Rule it is addressable: you must implement it, or document why it is not reasonable and use an equivalent measure. A 2025 proposal would make it required; it is not final.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.