Here are answers to common questions about HIPAA compliance (the acronym for the Health Insurance Portability and Accountability Act) that we receive from application developers who are looking to build ehealth and mhealth applications that use, transmit or store personal health information of their users.
The short answer is: if your application handles protected health information (PHI) then you need to be HIPAA compliant. If you do not, then you are subject to potential civil and criminal penalties as a result of HIPAA violations. The HIPAA rules apply to both Covered Entities and their Business Associates.
Covered entities are anyone who provides treatment, payment and operations in healthcare. Covered entities include companies and organizations such as: doctor's offices, dental offices, clinics, psychologists, health plans, insurance companies, HMOs and more.
Business associates are companies like you—if you're making an mHealth, eHealth or wearable applications that manages PHI, then you are a Business Associate under the HIPAA guidelines and you must be HIPAA compliant.
So how do you know if you're dealing with protected health information (PHI) or consumer health information? The test is pretty simple: if your device or application currently shares or will share the user's personal health data held in the app or device with a covered entity such as a doctor then you are dealing with protected health information and need HIPAA compliance software.
If you are building a wearable device or application that collects the user's personal health information, but do not plan on sharing it with a covered entity such as a doctor at any point in time, then you do not need to be HIPAA compliant and do not violate the HIPAA Privacy Rule.
For example, the Nike Fuelband is not HIPAA compliant because it does not track data considered to be protected health information nor allow data transmission from the device to a covered entity.
The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to enforce HIPAA requirement. The Privacy Rule addresses the use and disclosure of the health information for individuals by covered entities subject to the Rule. It also creates a standard for individual privacy rights to control and understand how their health information is used.
Within HHS, the Office for Civil Rights (OCR) has a responsibility to implement and impose the HIPAA Privacy Rule with respect to voluntary compliance activities and civil money penalties. Anyone can file a complaint to the OCR if they believe a HIPAA violation has occurred.
The HIPAA Security Rule requires appropriate Administrative, Physical, and Technical Safeguards to ensure the confidentiality, integrity, and security of protected health information (PHI).
In order to meet HIPAA compliance software requirements you need to ensure you're meeting the four main requirements of the HIPAA law. The four main requirements of the HIPAA Compliance Checklist are:
The short answer is no.
Unlike PCI compliance for financial information, there is no one that can "certify" that an organization with a HIPAA Compliance Certification. The OCR from the Department of Health and Human Services (HHS) is the federal governing body that oversees HIPAA compliance. HHS does not endorse or recognize the "HIPAA Compliance Certifications" made by private organizations.
It's up to you to determine if your administrative, technical, and physical safeguards meet HIPAA compliance requirements.
In order to meet HIPAA compliance software requirements you need to ensure you're meeting the four main requirements of the HIPAA law. The four main requirements of the HIPAA Compliance Checklist are:
Only TrueVault fulfills both the Technical and Physical safeguard requirements for HIPAA compliance. HIPAA compliant hosting providers do not. Hosting your app or service in a HIPAA compliant environment is not the same as being HIPAA compliant.
HIPAA violations can reach a maximum penalty of $50,000 per violation, with an annual maximum of $1.5 million, which underlies the importance of building HIPAA compliant software properly.
Read more about HIPAA hosting.
Ready to start building your HIPAA compliant application today? You can be up and running with our HIPAA compliant healthcare API in minutes, with no credit card and no trial expiration.
Skip the red tape and head straight to developing amazing new solutions for the healthcare industry with TrueVault.