HIPAA compliance
HIPAA reaches any company that handles protected health information for a hospital, clinic, or insurer, not just healthcare providers.
What is HIPAA
HIPAA is the US federal law governing how protected health information is handled.
It applies if your product touches patient data for a hospital, clinic, or insurer, whatever industry you consider yourself in.
What HIPAA includes
Five categories of obligation. Scadable runs all of them, keeps the evidence current, and hands you the documentation when a customer or an investigator asks.
How long it takes
These are Scadable timelines. Getting there on your own, or with a tool that hands you a checklist instead of doing the work, typically takes considerably longer.
Get HIPAA-ready. Without the busywork.
Frequently asked questions
- Yes, if your product creates, stores, or transmits protected health information on behalf of a covered entity. That makes you a Business Associate under HIPAA, with real obligations, even though you are not a hospital, clinic, or insurer yourself.
- A BAA is the contract required before a covered entity can share PHI with a vendor. If a hospital or clinic customer asks you to sign one, HIPAA applies to your company now, not hypothetically.
- Any pipeline that touches protected health information, including access logs, analytics, and support tooling, needs the same Security Rule safeguards as the primary data store: encryption, access control, audit logging. This is the most common gap, because those systems are usually built before anyone decides patient data will flow through them.
- Civil penalties scale with the violation, but the more immediate cost for a vendor is usually contractual: no signed BAA means a covered-entity customer legally cannot send you data, which typically means the deal does not close.
- Yes. Any subprocessor that also touches PHI, a cloud provider, an analytics tool, a support platform, needs its own BAA with you, flowing the same obligations down the chain. This chain is easy to lose track of, and it is a common place gaps surface during a security review.
This page is educational information, not legal advice. Confirm your company's HIPAA posture with qualified counsel.
