Aadit Technologies

HIPAA

Compliance

Health Insurance Portability and Accountability Act

HIPAA (the Health Insurance Portability and Accountability Act) is a US law whose privacy, security, and breach-notification rules protect health information held by covered entities and their business associates. The rules address permitted uses of protected health information, safeguards for electronic health information, and notification duties for breaches of unsecured protected health information.

HIPAA is enforced through several rules. The Privacy Rule governs how PHI may be used and disclosed; the Security Rule sets safeguards for electronic PHI; and the Breach Notification Rule dictates how and when breaches must be reported to individuals and regulators.

Compliance applies not only to covered entities such as hospitals and insurers, but also to business associates — vendors and service providers that handle PHI on their behalf. Violations can carry substantial civil and, in some cases, criminal penalties.

How HIPAA works in practice

HIPAA obligations depend on the organisation's role and the relevant US healthcare information. Covered entities and business associates have different responsibilities, and not every company handling any health-related data falls within those categories. Identify the service, information flows and contractual relationships first. Determine whether the information is protected health information and whether the organisation acts as a business associate for a covered entity.

For electronic protected health information, the Security Rule addresses administrative, physical and technical safeguards. A risk analysis helps identify relevant threats and vulnerabilities, while risk management addresses the findings. Policies need operational support: workforce access, device handling, incident response and supplier relationships should be reviewed in the actual environment. A generic policy pack cannot establish that these safeguards are working.

Who needs to examine HIPAA responsibilities

An Indian technology provider supporting a US covered entity may need to assess business-associate obligations. The assessment depends on the service and access to protected information, not simply the provider's location or an industry label. Review business associate agreements, subcontractors and the responsibilities assigned in contracts. Seek appropriate legal advice where applicability or notification duties are uncertain.

HIPAA should not be described as an official organisational certification issued by the US Department of Health and Human Services. HHS does not require a private Security Rule certification as a substitute for compliance. A readiness review can identify gaps and improve safeguards, but its deliverables should be described accurately. Customers should request relevant evidence and contractual commitments rather than relying on a claimed badge.

Putting safeguards into daily operations

Map where electronic protected health information is received, stored, used and transmitted. Review access for employees, administrators and suppliers, including the process for removing permissions when duties change. Decide how devices and backups are protected and how records are retained or destroyed. Operational resilience matters because unavailability can affect care or the customer's service; recovery arrangements should be appropriate to the business context.

Maintain an incident process with defined technical, privacy and legal decision-makers. Test how the organisation would assess an event, preserve evidence and notify relevant parties where required. Review safeguards when systems, customer contracts or subcontractors change. Security monitoring and access controls can support the programme, but they do not replace risk analysis, workforce procedures or accurate legal interpretation of applicable duties.

HIPAA vs. GDPR

AspectHIPAAGDPR
Who it concernsUS covered entities and their business associates handling protected health information.Controllers and processors handling personal data within the GDPR's territorial scope.
First scoping questionAre you a covered entity or business associate under the HIPAA rules?Do your processing activities fall within GDPR's scope?

Common misconceptions

  • HIPAA does not automatically apply to every health-related business worldwide. Covered-entity and business-associate roles and relevant information must be assessed.
  • A private HIPAA certificate is not official HHS approval and does not prove continuing compliance. Review scope, operating safeguards and evidence.
  • A business associate agreement is important but not sufficient alone. Relevant safeguards, supplier oversight and incident procedures must operate in practice.

Frequently asked questions

Does HIPAA apply to every company that handles health data?

Not automatically. HIPAA duties depend on whether the organisation is a covered entity or business associate and on the activity involved.

Does a HIPAA certificate establish compliance?

HHS does not recognise private certifications as a substitute for compliance with the HIPAA rules. Evaluate actual safeguards and obligations instead.

Reference sources

Practical context

Using HIPAA in a real decision

Definitions are most useful when they help a team decide what to scope, who should own the work, and what evidence supports the next step. Use these questions to turn the term into a practical conversation.

  • Which customers, data, services, or contracts make this requirement relevant?
  • What controls and evidence would demonstrate that the requirement is operating in practice?
  • Who is accountable for the scope, reviews, and any remediation work?