Frameworks /  US

HIPAA

HIPAA is the US federal law governing the privacy and security of protected health information (PHI), binding both healthcare organisations and the vendors that handle health data on their behalf, including non-US companies acting as business associates.

What it requires

The Security Rule (45 CFR Part 164, Subpart C) requires administrative, physical and technical safeguards for electronic PHI, beginning with a risk analysis and risk management process; its implementation specifications are marked either "required" or "addressable", where addressable means you must assess it and, if you do not implement it, document why and what equivalent measure you used instead. The Privacy Rule (Subpart E) governs permitted uses and disclosures of PHI, the minimum necessary standard, and individuals' rights of access to their records. The Breach Notification Rule (Subpart D) requires notice to affected individuals without unreasonable delay and no later than 60 days from discovery of a breach of unsecured PHI; breaches affecting 500 or more individuals must also be reported to HHS and to prominent media in the state within 60 days, while smaller breaches are logged and reported to HHS annually. Covered entities must have a signed Business Associate Agreement (BAA) with every vendor that creates, receives, maintains or transmits PHI on their behalf, and business associates are directly liable for much of the Security Rule. Enforcement is by the HHS Office for Civil Rights (OCR); a substantial update to the Security Rule was proposed in a January 2025 notice of proposed rulemaking and, as of this writing, has not been finalised.

HIPAA applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with covered transactions) and to their business associates and subcontractors. For Israeli companies, the route in is almost always the business associate path: a digital-health, medical-device, AI-diagnostics or health-data analytics company signs a BAA with a US hospital, payer or health-tech customer and inherits direct HIPAA obligations. There is no size threshold and no exemption for being a foreign company.

The controls people actually fail

  • No documented, current security risk analysis covering all systems that touch ePHI. This is the single most frequently cited failure in OCR enforcement actions.
  • ePHI is stored or backed up in cloud services that were never covered by a BAA, or in developer environments and support tools that nobody realised held real patient data.
  • Audit logging of access to ePHI exists but is never reviewed, so inappropriate access by internal staff is never detected.
  • Encryption is treated as optional because it is an "addressable" specification, with no documented assessment and no alternative safeguard implemented, which is not what addressable means.
  • Workforce access is not terminated promptly on departure, and there are no periodic reviews of who retains access to PHI.
  • The breach response process cannot meet the 60-day clock because there is no defined mechanism for determining whether an incident constitutes a breach of unsecured PHI.
  • Subcontractors handling PHI on the business associate's behalf have no downstream BAA in place.
HIPAA has no certification body and no annual audit for most organisations, so the only forcing function is an OCR investigation, which arrives after the breach, and begins by asking for your risk analysis. Risk analyses go stale the moment a new system, a new integration or a new cloud region touches PHI, and most do so quietly. The organisations that lose are rarely the ones with no controls; they are the ones whose controls were accurate two years ago.

Does HIPAA apply to companies outside the United States?

Yes. HIPAA obligations follow the data and the relationship, not the geography. An Israeli or European company that creates, receives, maintains or transmits protected health information on behalf of a US covered entity is a business associate, signs a Business Associate Agreement, and is directly liable for the Security Rule and for much of the Breach Notification Rule. There is no foreign-company exemption, and OCR has taken the position that business associate obligations attach regardless of where the entity sits.

Can you be "HIPAA certified"?

No. HHS does not recognise or endorse any HIPAA certification, and no body can grant one. What exists is third-party assessment: an independent auditor can evaluate your programme against the Security Rule and issue a report or attestation, and vendors often present such an assessment, or a SOC 2 report scoped to include HIPAA criteria, to satisfy customers. Treat any vendor claiming to be "HIPAA certified" as a signal to ask what was actually assessed, by whom, and against what.

What is a Business Associate Agreement and when do we need one?

A BAA is the contract required between a covered entity and any vendor that creates, receives, maintains or transmits PHI on its behalf, and between a business associate and its own subcontractors doing the same. It obliges the business associate to safeguard PHI, to use and disclose it only as permitted, to report security incidents and breaches, and to ensure downstream subcontractors are bound by equivalent terms. You need one before PHI flows, including to cloud providers, support tooling and analytics vendors, all of which count if they can access PHI even incidentally.

What is the HIPAA breach notification deadline?

Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. Breaches affecting 500 or more individuals must also be reported to HHS contemporaneously (within 60 days) and notice must be provided to prominent media outlets serving the relevant state or jurisdiction. Breaches affecting fewer than 500 individuals are logged and reported to HHS within 60 days after the end of the calendar year. A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days from discovery.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.