The Health Insurance Portability and Accountability Act sets national standards for the protection of individually identifiable health information, called Protected Health Information or PHI. It applies to covered entities: healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses. It also applies to business associates, which are third-party vendors that handle PHI on behalf of covered entities. If you are a software vendor, a billing company, a transcription service, or any other business that processes health information on behalf of a healthcare provider, HIPAA applies to you even if you are not a healthcare provider yourself.
The practical scope of who must comply is broader than many founders realize. A therapist in private practice who uses a scheduling app, an electronic health record system, and a telehealth platform is a covered entity. Each of those technology vendors is a business associate. The therapist needs a Business Associate Agreement with each vendor before allowing that vendor to access patient data. Using a non-HIPAA-compliant tool for patient scheduling, telehealth, or record-keeping is a violation regardless of whether any data is ever actually breached.
The most common HIPAA violations for small healthcare practices involve the use of non-compliant communication tools. Regular Gmail, standard Zoom, and free Dropbox are not HIPAA-compliant. Google Workspace for Healthcare, Zoom for Healthcare, and Dropbox Business with a Business Associate Agreement are compliant versions of the same tools at higher price points. The compliance is not in the software itself but in the vendor's willingness to sign a Business Associate Agreement and in the specific privacy and security configurations applied to the account.
Penalties for HIPAA violations are tiered based on knowledge and intent. Unintentional violations resulting from reasonable diligence can result in fines from one hundred to fifty thousand dollars per violation. Violations resulting from willful neglect that are not corrected range from ten thousand to fifty thousand dollars per violation with no maximum cap. The Office for Civil Rights at the Department of Health and Human Services enforces HIPAA and investigates complaints from patients and employees. State attorneys general also have enforcement authority.
If you are building a business in healthcare or serving healthcare providers, consult with a HIPAA compliance consultant or healthcare attorney before you write a single line of code or send your first patient communication. The cost of compliant infrastructure is real but predictable. The cost of a HIPAA violation is unpredictable and potentially business-ending for a year-one company without reserves to absorb a significant fine.
HIPAA compliance is not optional for businesses that handle protected health information, and the standard for compliance is not whether a breach has occurred but whether you have implemented the administrative, physical, and technical safeguards the law requires.