Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Compliance & regulations

Does HIPAA apply to my software or business?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

HIPAA applies to 'covered entities' — US healthcare providers, health plans, and clearinghouses — and to 'business associates,' the vendors and software providers that create, receive, store, or process protected health information (PHI) on a covered entity's behalf. If your software handles US PHI for a healthcare customer, you are very likely a business associate and must comply with HIPAA's Security and Privacy Rules and sign a Business Associate Agreement (BAA). If you never touch US PHI, HIPAA generally does not apply — though Canadian health data falls under laws like PHIPA and PIPEDA instead.

On this page

Covered entities vs business associates

HIPAA directly regulates covered entities: healthcare providers that transmit health data electronically, health plans, and healthcare clearinghouses. It also reaches business associates — any organization that handles PHI to provide a service to a covered entity, including SaaS platforms, hosting providers, analytics vendors, and consultants.

If you are a business associate, you must comply with the HIPAA Security Rule and applicable parts of the Privacy Rule, and enter a Business Associate Agreement (BAA) with your customer that contractually binds you to those obligations.

When HIPAA likely applies to you

  • Your software stores, processes, or transmits PHI for US healthcare clients.
  • A healthcare customer has asked you to sign a BAA.
  • You provide services (hosting, support, analytics) that give you access to PHI.

When it may not — but another law might

If your business does not handle US protected health information, HIPAA generally does not apply. But health information in Canada is governed by other laws — PHIPA in Ontario and similar provincial health-privacy statutes, alongside PIPEDA — so 'HIPAA doesn't apply' rarely means 'no privacy law applies.' Identify the regimes that match where your data and customers actually are.

An important caveat about cloud providers

Using a 'HIPAA-compliant' cloud provider does not make your business HIPAA compliant. Your provider can satisfy certain infrastructure safeguards under a BAA, but you remain responsible for administrative safeguards, your own application security, access control, policies, and breach response. Compliance is shared, not outsourced.

Frequently asked questions

No. A compliant provider helps with infrastructure safeguards through a BAA, but your organization remains responsible for administrative safeguards, application-level security, policies, training, and breach response. You must implement and document your own controls.

Only if you handle US protected health information (for example, serving US healthcare clients). For Canadian health data, PHIPA and other provincial health-privacy laws and PIPEDA apply instead. Many organizations need to consider both.

Cybersecurity basics

What's the difference between data privacy and cybersecurity?

Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.

Read
Compliance & regulations

Does GDPR apply to my business if we're outside Europe?

The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do.

Read
Compliance & regulations

What is a HIPAA security risk assessment, and do you need one?

What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it.

Read
Compliance & regulations

What is PIPEDA, and does it apply to my business?

What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.

Read
Compliance & regulations

How do we prepare for a customer security questionnaire?

Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.

Read
Compliance & regulations

What is a cybersecurity risk assessment, and how often should we do one?

A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.

Read

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.