{"id":45269,"date":"2026-08-20T18:28:30","date_gmt":"2026-08-20T12:58:30","guid":{"rendered":"https:\/\/averybit.com\/?p=45269"},"modified":"2026-08-20T18:41:02","modified_gmt":"2026-08-20T13:11:02","slug":"hipaa-security-rule-healthcare-software","status":"publish","type":"post","link":"https:\/\/averybit.com\/de\/hipaa-security-rule-healthcare-software\/","title":{"rendered":"HIPAA Security Rule: 6 Essentials for Secure Healthcare Software"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"45269\" class=\"elementor elementor-45269\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6aeff42 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6aeff42\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3cd342f\" data-id=\"3cd342f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-27b97c7 elementor-widget elementor-widget-text-editor\" data-id=\"27b97c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>The HIPAA Security Rule for Healthcare Software: What Should Be Built Into the Product<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Even if a healthcare product looks to be sufficiently secure at the time of its demonstration, it can still be vulnerable when it is used on an everyday basis.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One of the employees can have more permissions than he actually needs to perform his duties. One of the administrators can fail to determine who modified a certain patient\u2019s record. There may be a backup but it was never checked. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">There may be a third-party service which manipulates health-related data but which was not sufficiently reviewed and did not enter the appropriate contracts.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That is what the HIPAA Security Rule is for. It obliges regulated organizations to implement reasonable and appropriate safeguards to ensure protection of electronic protected health information or ePHI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For healthcare entrepreneurs and developers, it means that security should not be an afterthought that is implemented only right before product release.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\"><br \/><\/span><b>What Is the HIPAA Security Rule?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The HIPAA Security Rule is a standard in the United States meant to safeguard ePHI. It is supposed to ensure the confidentiality, integrity and availability of the information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In more practical terms:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Confidentiality involves the protection of ePHI from disclosure to anyone else or system that does not have the authorisation to see it.<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Integrity involves the protection of information from any modification or destruction that should not occur.<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Availability entails ensuring authorised individuals are able to access the information.<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The rule applies to HIPAA covered entities and their business associates. Covered entities include, among others, health plans, healthcare clearinghouses and some healthcare providers. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Business associates are any persons performing certain functions involving the use of ePHI on the behalf of covered entities.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, an application for healthcare or wellness purposes is not necessarily a covered entity under HIPAA just because it holds health information.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is based on who owns the application, what it does and who it works with.<\/span><\/p>\n<p>\u00a0<\/p>\n<h2><b>The Three Categories of HIPAA Safeguards<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The HIPAA Security Rule organises safeguards into three categories.<br \/><br \/><br \/><\/span><\/p>\n<h3><b>Administrative Safeguards<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Administrative safeguards cover the policies and processes used to manage security. They include risk analysis, workforce access, security responsibility, staff training, incident response, contingency planning and periodic evaluation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Software cannot fulfil these responsibilities alone, but it must support them. For example, if an organisation defines different access rights for doctors, billing staff and support agents, the application needs a permission model capable of enforcing those decisions.<\/span><\/p>\n<h3><b>Physical Safeguards<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Physical safeguards concern access to facilities, devices, workstations and electronic media.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">They remain relevant even for cloud-based products. Staff may access patient information from shared clinical workstations, tablets, laptops or home offices. Session handling, local downloads, device security and screen exposure must therefore be considered during product design.<\/span><\/p>\n<h3><b>Technical Safeguards<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Technical safeguards control how technology protects ePHI. They cover access control, audit controls, data integrity, authentication and transmission security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These are the safeguards most visible within the software itself, but they must reflect the organisation\u2019s policies, risk assessment and real working environment.<\/span><\/p>\n<p>\u00a0<\/p>\n<h2><b>Six Essential Requirements for Healthcare Software<\/b><\/h2>\n<h3><b>1. Map the Complete ePHI Data Flow<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Security planning should begin with the data, not the interface.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Teams need to document where ePHI is collected, processed, stored, transmitted, backed up and deleted. This map should include more than the primary database.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Health information may also appear in:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Application logs<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Analytics platforms<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Customer-support tools<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Email or notification services<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Temporary files<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Data exports<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Connected medical devices<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Third-party integrations<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Mapping the complete data flow helps identify risks that would otherwise remain hidden and gives the team a stronger basis for architecture and vendor decisions.<\/span><\/p>\n<h3><b>2. Build Access Around Real User Responsibilities<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Not every employee needs access to every patient record.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A therapist may need clinical notes for assigned patients. A billing specialist may need insurance details without seeing complete treatment notes. A support agent may need limited account information to resolve a technical issue.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Healthcare software should therefore support:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Role-based access<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Least-privilege permissions<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Record-level restrictions<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Separate administrator controls<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Formal access approval and removal<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Automatic session expiration<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Permissions must be enforced on the server side. Hiding information in the interface does not prevent an unauthorised user or system from requesting it directly.<\/span><\/p>\n<h3><b>3. Use Reliable Authentication and Session Controls<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Security Rule requires regulated entities to verify that a person or system requesting access is who they claim to be.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Depending on the organisation\u2019s risk assessment, authentication controls may include unique user accounts, strong password policies, multi-factor authentication, secure account recovery and re-authentication for sensitive actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Session behaviour matters as well. The application should be able to terminate inactive sessions, revoke access after role changes and respond appropriately when credentials may have been compromised.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security must also fit the clinical workflow. If authentication is unnecessarily slow or confusing, users may share accounts or find unsafe workarounds.<\/span><\/p>\n<h3><b>4. Create Meaningful Audit Trails<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An audit trail should help the organisation reconstruct activity involving ePHI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It should be possible to identify:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Who accessed the information<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>What they viewed, changed, exported or deleted<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>When the action occurred<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Which account or system initiated it<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Whether the action was successful<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Whether a permission or role was changed<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Audit logs should be protected from unauthorised modification and should not collect unnecessary sensitive content.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Logging everything without a review process is not enough. Organisations also need appropriate retention, monitoring and investigation procedures.<\/span><\/p>\n<h3><b>5. Protect Data and Preserve Its Integrity<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Healthcare software must protect ePHI while it is being transmitted and stored.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Technical measures may include transport encryption, encrypted databases and backups, secure key management, protected API connections and proper secrets management.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The team should understand where encryption begins and ends, who controls the keys and when information becomes readable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Data integrity is equally important. Server-side validation, version histories, database constraints and controlled correction processes can reduce the risk of records being improperly altered or destroyed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For critical clinical information, silently replacing an earlier value may be less appropriate than recording who made the change, when it happened and why.<\/span><\/p>\n<h3><b>6. Plan for Vendors, Recovery and Ongoing Security<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Healthcare products often depend on cloud providers, telehealth services, analytics tools, identity platforms and EHR integrations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When a vendor creates, receives, maintains or transmits ePHI on behalf of a covered entity or business associate, a Business Associate Agreement may be required. A BAA defines responsibilities, but it does not replace technical due diligence or risk analysis.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Teams should review how each vendor handles data, subcontractors, incidents, retention and deletion.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">They also need a tested recovery plan. A backup is useful only when accurate data can be restored within an acceptable period.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After launch, organisations should continue reviewing access, monitoring logs, patching vulnerabilities, testing recovery and reassessing risks when the product or its environment changes.<\/span><\/p>\n<p>\u00a0<\/p>\n<h2><strong>Six Essential Requirements for Healthcare Software<\/strong><\/h2>\n<h3><b>1. Map the Complete ePHI Data Flow<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Security planning should begin with the data, not the interface.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Teams need to document where ePHI is collected, processed, stored, transmitted, backed up and deleted. This map should include more than the primary database.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Health information may also appear in:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Application logs<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Analytics platforms<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Customer-support tools<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Email or notification services<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Temporary files<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Data exports<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Connected medical devices<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Third-party integrations<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Mapping the complete data flow helps identify risks that would otherwise remain hidden and gives the team a stronger basis for architecture and vendor decisions.<\/span><\/p>\n<h3><b>2. Grant Access Based On Actual User Responsibilities<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Not everyone should have access to all patient records.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Therapist needs clinical notes of their assigned patients. A billing person might need insurance information without viewing treatment notes of a patient. The customer service representative needs partial account data in order to fix a technical problem.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a result, healthcare software should provide:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Role-based access<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Least privilege approach<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Record-level restrictions<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Admin tools for granting\/removing access and managing users<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Access request and removal process<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Session expiration feature<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Permission handling should be enforced at the server level. Obscuring data from the UI does not stop an unauthorized user from requesting that same data.<\/span><\/p>\n<h3><b>3. Use Reliable Authentication and Session Controls<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Security Rule requires regulated entities to verify that a person or system requesting access is who they claim to be.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Depending on the organisation\u2019s risk assessment, authentication controls may include unique user accounts, strong password policies, multi-factor authentication, secure account recovery and re-authentication for sensitive actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Session behaviour matters as well. The application should be able to terminate inactive sessions, revoke access after role changes and respond appropriately when credentials may have been compromised.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security must also fit the clinical workflow. When there is any issue with account verification due to excessive delay or complexity, users resort to sharing accounts.<\/span><\/p>\n<h3><b>4. Create Meaningful Audit Trails<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An audit trail should help the organisation reconstruct activity involving ePHI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It should be possible to identify:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Who accessed the information<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>What they viewed, changed, exported or deleted<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>When the action occurred<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Which account or system initiated it<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Whether the action was successful<\/strong><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>Whether a permission or role was changed<\/strong><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Audit logs should be protected from unauthorised modification and should not collect unnecessary sensitive content.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Logging everything without a review process is not enough. Organisations also need appropriate retention, monitoring and investigation procedures.<\/span><\/p>\n<h3><b>5. Secure Data and Maintain its Integrity<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Software used in healthcare should secure electronic Protected Health Information during transmission and storage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This can be achieved through the use of transport encryption, database and backup encryption, secure key management, and secured API connections among others.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It should be clear which part of the solution encrypts data and which decrypts it, who has access to keys and when data becomes readable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Maintaining data integrity is also very important. Server-side validation, version history of the records, DB-level constraints and corrections can help to avoid data modification and destruction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In case of critical clinical information, it might make more sense to track who changes data, what they change and why rather than silently overwriting it.<\/span><\/p>\n<h3><b>6. Plan for Vendors, Recovery and Ongoing Security<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Healthcare products often depend on cloud providers, telehealth services, analytics tools, identity platforms and EHR integrations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When a vendor creates, receives, maintains or transmits ePHI on behalf of a covered entity or business associate, a Business Associate Agreement may be required. A BAA outlines the obligations, but it is not a substitute for due diligence or risk assessment.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Teams should review how each vendor handles data, subcontractors, incidents, retention and deletion.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">They also need a tested recovery plan. A backup is useful only when accurate data can be restored within an acceptable period.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After launch, organisations should continue reviewing access, monitoring logs, patching vulnerabilities, testing recovery and reassessing risks when the product or its environment changes.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>What Does \u201cAddressable\u201d Mean?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Under the current HIPAA Security Rule, some implementation specifications are described as addressable. This does not mean they can be ignored.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The organisation must assess whether an addressable measure is reasonable and appropriate for its environment. If it is, the measure must be implemented. If it is not, the decision must be documented and an appropriate alternative may be required.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is especially important when discussing controls such as encryption. Decisions should be based on documented risk, not on the assumption that \u201caddressable\u201d means optional.<\/span><\/p>\n<h2><b>What About the Proposed HIPAA Security Rule Changes?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">In December 2024, the US Department of Health and Human Services announced proposed modifications that would enhance the cybersecurity safeguards for ePHI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Such areas include multi-factor authentication, asset management, network diagrams, vulnerability assessments, penetration tests, network segmentation and recovery strategies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is just a proposal and is not an official requirement as yet. At the moment, the HIPAA Security Rule still applies as the rulemaking process is ongoing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Healthcare organizations need to follow the official announcements from HHS while also taking into account the new cybersecurity measures in their risk management strategy.<\/span><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>Building Security Into the Product<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">HIPAA-oriented healthcare software is not created by adding a compliance label to a finished application.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It requires a clear understanding of the data, users, workflows, vendors and risks surrounding the product. Access controls, auditability, authentication, data protection and recovery should be planned before development begins and reviewed after launch.<\/span><\/p>\n<p><a href=\"https:\/\/averybit.com\/de\/\"><span style=\"font-weight: 400;\">AveryBit Solutions <\/span><\/a><span style=\"font-weight: 400;\">helps healthcare and wellness teams plan and develop secure digital products, including patient portals, telemedicine platforms, mental wellbeing applications, healthcare automation and system integrations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The goal is not to apply a generic \u201cHIPAA-compliant\u201d label. It is to build a technical foundation that reflects the product\u2019s real users, data flows and security responsibilities.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Planning a healthcare product that handles sensitive patient data? Talk to AveryBit Solutions about building security into the product from the beginning.\u00a0<\/span><\/p>\n<h2><b>Official Source<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">This article draws on publicly available guidance from the US Department of Health and Human Services, including its<\/span><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/laws-regulations\/index.html\"> <span style=\"font-weight: 400;\">Summary of the HIPAA Security Rule<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><b>Disclaimer:<\/b><span style=\"font-weight: 400;\"> This article is provided for general informational purposes only and does not constitute legal, regulatory or compliance advice. Organisations should consult qualified legal and compliance professionals regarding their specific circumstances.<\/span><\/p>\n<p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t<div class=\"elementor-element elementor-element-996c214 e-flex e-con-boxed e-con e-parent\" data-id=\"996c214\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-32bfb4a elementor-widget elementor-widget-n-accordion\" data-id=\"32bfb4a\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;expanded&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-5320\" class=\"e-n-accordion-item\" open>\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"true\" aria-controls=\"e-n-accordion-item-5320\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> 1. Does every healthcare app need to follow HIPAA? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-5320\" class=\"elementor-element elementor-element-cb81b26 e-con-full e-flex e-con e-child\" data-id=\"cb81b26\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-58a629c elementor-widget elementor-widget-text-editor\" data-id=\"58a629c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>No. HIPAA does not automatically apply to every app that collects health-related information. It generally depends on who operates the app, how the data is used and whether the organisation is a covered entity or business associate. Other privacy or consumer protection laws may still apply even when HIPAA does not.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-5321\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-5321\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> 2. What are the three main HIPAA Security Rule safeguards? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-5321\" class=\"elementor-element elementor-element-00e0a8d e-con-full e-flex e-con e-child\" data-id=\"00e0a8d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3af789e elementor-widget elementor-widget-text-editor\" data-id=\"3af789e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The three categories are administrative, physical and technical safeguards. Together, they cover how an organisation manages security, protects devices and workspaces, controls access, verifies users and secures electronic protected health information.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-5322\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-5322\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> 3. Is encryption required for healthcare software under HIPAA? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-5322\" class=\"elementor-element elementor-element-eff6d48 e-con-full e-flex e-con e-child\" data-id=\"eff6d48\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ba272a1 elementor-widget elementor-widget-text-editor\" data-id=\"ba272a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Encryption is listed as an addressable specification under the current Security Rule. However, \u201caddressable\u201d does not mean optional. An organisation must assess whether encryption is reasonable and appropriate for its risks, document the decision and consider a suitable alternative if it is not implemented.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-5323\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-5323\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> 4. Does signing a BAA make software HIPAA compliant? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-5323\" class=\"elementor-element elementor-element-a2e521d e-flex e-con-boxed e-con e-child\" data-id=\"a2e521d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7a4e972 elementor-widget elementor-widget-text-editor\" data-id=\"7a4e972\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>No. A Business Associate Agreement defines how protected health information may be handled and establishes responsibilities between the parties. It does not replace secure development, access controls, risk analysis, employee procedures, monitoring or incident-response planning.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-5324\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-5324\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><div class=\"e-n-accordion-item-title-text\"> 5. Can a healthcare application be officially HIPAA certified? <\/div><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewbox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-5324\" class=\"elementor-element elementor-element-92f152f e-flex e-con-boxed e-con e-child\" data-id=\"92f152f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-421a082 elementor-widget elementor-widget-text-editor\" data-id=\"421a082\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>HHS does not certify or endorse specific applications, technologies or software vendors as \u201cHIPAA compliant.\u201d An external assessment can help identify gaps, but compliance depends on the organisation\u2019s complete technical, administrative and operational environment.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Even if a healthcare product looks to be sufficiently secure at the time of its demonstration, it can still be vulnerable when it is used on an everyday basis. One of the employees can have more permissions than he actually needs to perform his duties. One of the administrators can fail to determine who modified&hellip;<\/p>","protected":false},"author":9,"featured_media":45271,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[390],"tags":[205,200,206],"class_list":["post-45269","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wellness","tag-wellness","tag-wellness-app-development","tag-wellness-industry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/posts\/45269","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/comments?post=45269"}],"version-history":[{"count":10,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/posts\/45269\/revisions"}],"predecessor-version":[{"id":45281,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/posts\/45269\/revisions\/45281"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/media\/45271"}],"wp:attachment":[{"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/media?parent=45269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/categories?post=45269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/averybit.com\/de\/wp-json\/wp\/v2\/tags?post=45269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}