HIPAA· 6 briefs

HIPAA briefs.

You handle protected health information (PHI) — patient records, lab results, appointment data, or any individually identifiable health data — or you’re building a product that will. HIPAA (Health Insurance Portability and Accountability Act) is a federal law, not a certification programme. There is no “HIPAA certified” badge; there is a Security Rule governing technical and administrative safeguards for electronic PHI, a Privacy Rule covering how PHI can be used and disclosed, and a Breach Notification Rule specifying what happens when something goes wrong.

Business Associate Agreements (BAAs) are required before any vendor touches PHI on your behalf. Covered entities and their business associates are both in scope. If your product also serves EU users, HIPAA overlaps with GDPR in ways that are easier to manage as a unified programme than as two separate ones.

The briefs below cover the checklist, BAA requirements, and the HIPAA-GDPR overlap. If you’re handling PHI and need a structured review, visit the HIPAA service page.

60 days
Breach notification window
18
PHI identifiers
$50K
Max per-violation penalty

No deck. No sales pitch. We scope the programme, give you the gap analysis, and you decide if there’s a fit.

HIPAA briefs6
A clinician handing a patient a clipboard to sign — the kind of PHI handling a business associate agreement governs.
HIPAA10 min read

Business Associate Agreement: What a HIPAA BAA Is and Who Needs One

A business associate agreement is the HIPAA contract required before a vendor touches PHI. What a BAA must include, who signs one, and how it differs from an NDA or DPA.

Reviewing medical records — a HIPAA compliance audit scene for a SaaS vendor.

If one of these briefs reflects where you are right now, we run scoping calls without a deck. Book a scoping call.