Framework Guide

HIPAA Guide

HIPAA is the framework most misunderstood by startups, because it inverts the usual compliance shape: no certificate, no annual audit, no finish line. Obligation attaches the moment protected health information touches your systems, and enforcement arrives after something goes wrong — a breach, a complaint, an investigation. The only preparation that counts is a program demonstrably operating before the incident.

The three rules that matter

The Privacy Rule governs how PHI may be used and disclosed. The Security Rule mandates administrative, physical, and technical safeguards for electronic PHI — this is where risk analyses, access controls, encryption, and audit logging live. The Breach Notification Rule sets the clock: affected individuals and HHS within 60 days of discovering a breach.

Why the risk analysis dominates enforcement

OCR’s first document request in nearly every investigation is the security risk analysis, and its absence or superficiality is the most-cited failure in resolution agreements. A defensible analysis is specific: every system touching ePHI, every reasonably anticipated threat, and documented decisions about each risk — reviewed when your environment changes, not once at founding.

Go Deeper

HIPAA Compliance Checklist — A HIPAA checklist for startups handling PHI — risk analysis, safeguards, BAAs, training, and breach readiness. Written for health-tech, not hospitals.

How HIPAA programs fail — The six HIPAA failure patterns in startups — stale risk analyses, missing sub-BAAs, PHI sprawl — and how each one surfaces in deals and incidents.

HIPAA for startups — A startup-sized HIPAA program — business associate reality, the minimum defensible posture, and the mistakes that surface in health-system procurement.

HIPAA vs SOC 2 — HIPAA is a law; SOC 2 is an attestation. Health-tech needs both — here's what overlaps, what doesn't, and how to build one program that satisfies each.

What HIPAA costs — What HIPAA compliance costs a health-tech startup — risk analysis, safeguards, BAAs, and training — and why 'no certificate' doesn't mean 'no budget.'

Frequently Asked
Who does HIPAA apply to?

Covered entities (providers, plans, clearinghouses) and their business associates — which includes most healthtech companies that touch PHI on a covered entity's behalf. Signing a BAA makes the Security Rule's requirements directly enforceable against you.

What are HIPAA penalties?

Civil penalties are tiered by culpability and reach seven figures per violation category per year, with amounts adjusted periodically for inflation. Beyond fines, OCR resolution agreements impose multi-year corrective action plans with ongoing monitoring.