HIPAA
US health data compliance
What it is
HIPAA is the US law governing protected health information. If your product stores or processes health data for healthcare customers, you're a business associate: you sign a business associate agreement and meet the Security Rule's safeguards for access control, encryption, audit logging and breach notification. There is no official HIPAA certification. Buyers look at your controls, your BAA, and often a SOC 2 or HITRUST report.
Healthcare organisations legally can't share patient data with a vendor that won't sign a BAA.
What it takes
About 6–12 engineer-weeks to build in-house, or 3–6 using Aptible, Vanta or Drata with a HIPAA framework.
Usually three to six months before you can sign a BAA with confidence.
Answer these first
- Legal: Will we sign BAAs, and on what terms?
- Engineering: Which systems would touch protected health information?
- Engineering: Do all our vendors and cloud services sign BAAs with us?
- Security: How would we detect and report a breach?
- Product: Do we actually need health data, or can the product work without it?
- Sales: Are buyers asking for HITRUST, or is a BAA plus SOC 2 enough?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.