Free tool · HIPAA

Do I need to comply with HIPAA?

HIPAA applies to health plans, clearinghouses and most US health care providers, and to the vendors that handle protected health information for them. Answer four questions to see which you are, whether you need a business associate agreement, and what follows.

Short answer

HIPAA applies if you are a covered entity (a health plan, a clearinghouse, or a provider that bills electronically) or a business associate: a vendor that creates, receives, maintains or transmits protected health information on a covered entity's behalf. A SaaS company storing patient data for US clinics is a business associate, must sign a BAA, and must meet the Security Rule.

Answer for your organisation

Names, contact details or record numbers tied to a person's health, care or payment for care.
Worked example: a SaaS company hosting patient records for US clinics

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Required: you are a business associate

A vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate, and a vendor doing so for a business associate is one too (a subcontractor). You are directly liable under the Security Rule and for breach notification, and you need a BAA with each customer. HIPAA sets no certification; buyers often ask for SOC 2 or HITRUST as evidence.

Sign a business associate agreement with each covered entity customer45 CFR 164.502(e), 164.504(e)
Comply with the Security Rule: risk analysis, safeguards, policies45 CFR 164.302–164.318
Use and disclose PHI only as the BAA allows45 CFR 164.502(a)(3)
Tell the covered entity about a breach within 60 days of discovery45 CFR 164.410
Flow the same terms down to subcontractors that handle PHI45 CFR 164.502(e)(1)(ii)
  • Now: sign BAAs before PHI flows, and list every sub-processor that will touch it.
  • Security Rule: do a written risk analysis first; every other safeguard follows from it.
  • Devices: laptops that reach PHI need encryption and remote wipe: see the MDM checker.
01

Covered entity or business associate

HIPAA's rules apply to covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in a standard transaction) and to business associates. A business associate is a person who, other than as a member of the workforce, creates, receives, maintains or transmits protected health information on behalf of a covered entity, or provides services such as legal, accounting, consulting, data aggregation or administration that involve disclosure of PHI. A subcontractor that handles PHI for a business associate is itself a business associate. The definitions are in 45 CFR 160.103.

02

What PHI is

Protected health information is individually identifiable health information, held or transmitted in any form or medium. It excludes education records under FERPA, employment records a covered entity holds as an employer, and information about a person dead for more than 50 years. Information de-identified under 164.514 is not PHI.

03

The business associate agreement

A covered entity may let a business associate handle PHI only with satisfactory written assurance, a BAA, that the associate will safeguard it. The BAA limits use and disclosure, requires Security Rule safeguards, breach reporting, return or destruction of PHI at the end, and the same terms for subcontractors. A business associate must report a breach of unsecured PHI to the covered entity without unreasonable delay and no later than 60 days after discovery.

04

Penalties

Civil penalties have four tiers by culpability, set in 45 CFR 160.404 and adjusted for inflation in 45 CFR 102.3. The 2025 adjusted amounts per violation are: did not know, $145 to $73,011; reasonable cause, $1,461 to $73,011; willful neglect, corrected within 30 days, $14,602 to $73,011; willful neglect, not corrected, $73,011 to $2,190,294. Identical violations are capped at $2,190,294 per calendar year. The amounts are adjusted annually.

05

A proposed Security Rule update

In January 2025 HHS proposed a major update to the Security Rule (90 FR 898), which among other things would remove the distinction between required and addressable specifications. It is a proposal. Until a final rule is published, the current text applies: encryption, for example, remains addressable.

06

Sources

Questions

The things people ask us

Does HIPAA apply to my company?

Only if you are a covered entity (a health plan, a clearinghouse, or a provider billing electronically) or a business associate handling PHI on behalf of one. Holding health data is not enough on its own: a consumer app used directly by individuals is usually outside HIPAA.

Is a SaaS company a business associate?

Yes, if it creates, receives, maintains or transmits PHI on behalf of a covered entity, which includes storing it. Hosting providers and other sub-processors of that SaaS company are business associates too.

Do I need a BAA?

Yes, before any PHI flows between a covered entity and a business associate, or between a business associate and its subcontractor. Without one, the covered entity cannot lawfully share the PHI with you.

Is there a HIPAA certification?

No. The HIPAA rules set no certification scheme, so no one can certify you as HIPAA compliant in the way ISO 27001 certifies. Buyers often ask for a SOC 2 report or HITRUST certification as evidence that your safeguards meet the Security Rule.

What are the HIPAA penalties in 2025?

Per violation, from $145 where the entity did not know, up to $2,190,294 for uncorrected willful neglect, with a calendar-year cap of $2,190,294 for identical violations. These are the inflation-adjusted figures in 45 CFR 102.3.

Does HIPAA apply outside the United States?

The business associate definition turns on what you do for a covered entity, not where you are. A company in India or Europe that stores PHI for a US hospital is treated as a business associate and will be asked to sign a BAA.

Is encryption required under HIPAA?

Under the current Security Rule it is addressable: you must implement it, or document why it is not reasonable and use an equivalent measure. A 2025 proposal would make it required; it is not final.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.