Framework · Health Insurance Portability and Accountability Act

HIPAA compliance

HIPAA reaches any company that handles protected health information for a hospital, clinic, or insurer, not just healthcare providers.

What is HIPAA

HIPAA is the US federal law governing how protected health information is handled.

It applies if your product touches patient data for a hospital, clinic, or insurer, whatever industry you consider yourself in.

What HIPAA includes

Five categories of obligation. Scadable runs all of them, keeps the evidence current, and hands you the documentation when a customer or an investigator asks.

CategoryWhat it covers
TeamTraining, role-based access, offboarding, sanctions
TechEncryption, MFA, audit logs, backups, disposal
CompanyRisk analysis, data inventory, vendor management, named officials
PoliciesWritten policy set, documented decisions, 6-year retention
Outside obligationsSigned BAAs, patient rights requests, breach notification machinery

How long it takes

These are Scadable timelines. Getting there on your own, or with a tool that hands you a checklist instead of doing the work, typically takes considerably longer.

Onboarding30 min
Platform setup2 hours
CompliantEvidence stays current

Get HIPAA-ready. Without the busywork.

Frequently asked questions

Yes, if your product creates, stores, or transmits protected health information on behalf of a covered entity. That makes you a Business Associate under HIPAA, with real obligations, even though you are not a hospital, clinic, or insurer yourself.
A BAA is the contract required before a covered entity can share PHI with a vendor. If a hospital or clinic customer asks you to sign one, HIPAA applies to your company now, not hypothetically.
Any pipeline that touches protected health information, including access logs, analytics, and support tooling, needs the same Security Rule safeguards as the primary data store: encryption, access control, audit logging. This is the most common gap, because those systems are usually built before anyone decides patient data will flow through them.
Civil penalties scale with the violation, but the more immediate cost for a vendor is usually contractual: no signed BAA means a covered-entity customer legally cannot send you data, which typically means the deal does not close.
Yes. Any subprocessor that also touches PHI, a cloud provider, an analytics tool, a support platform, needs its own BAA with you, flowing the same obligations down the chain. This chain is easy to lose track of, and it is a common place gaps surface during a security review.

This page is educational information, not legal advice. Confirm your company's HIPAA posture with qualified counsel.