What Is HIPAA Compliance?

What is HIPAA compliance, a clear guide
What Is HIPAA Compliance? A Clear Guide for 2026 | Osto

What is HIPAA compliance, in plain terms? The US law that governs how health information is protected, who has to follow it, and what happens when it is mishandled.

Osto Security Team8 min readCompliance & Trust

TL;DR

HIPAA is a US law that protects sensitive health information. Compliance means following its rules, chiefly the Privacy Rule, the Security Rule, and the Breach Notification Rule, if you handle protected health information (PHI).

It applies to covered entities like healthcare providers and health plans, and to their business associates, which includes most software vendors that touch PHI. Getting it wrong carries tiered civil penalties, so the security has to be real, not on paper.

What is HIPAA compliance?

HIPAA, the Health Insurance Portability and Accountability Act, is a US federal law that sets national standards for protecting sensitive patient health information. Compliance means meeting those standards: putting the required privacy and security protections in place, keeping them operating, and being able to show it. It is not a certificate you earn once. It is an ongoing obligation to protect health data and prove you are doing so.

The core idea
HIPAA exists to keep health information private and secure. Compliance is the practical work of protecting that data, controlling who can access it, securing it technically, and responding correctly if it is ever exposed.

The rules that make up HIPAA

HIPAA is often described as one thing, but in practice a handful of rules do most of the work. Three matter most for anyone handling health data.

The rules that make up HIPAA
Three rules do most of the work
🔒
Privacy Rule
Governs how protected health information may be used and disclosed.
🛡️
Security Rule
Requires safeguards to protect electronic protected health information.
📣
Breach Notification
Sets who to tell, and how fast, when PHI is exposed.

The Privacy Rule governs how protected health information may be used and shared. The Security Rule requires specific safeguards for that information in electronic form. The Breach Notification Rule sets out who must be told, and how quickly, if the information is exposed.

Who has to comply with HIPAA?

HIPAA applies to two broad groups, and the second one catches many technology companies by surprise.

GroupWho it coversExamples
Covered entitiesThose who provide care or handle health coverageHospitals, clinics, doctors, health plans, clearinghouses
Business associatesVendors that handle PHI on their behalfSaaS platforms, cloud hosts, billing and analytics providers
The part startups miss
If your software stores, processes, or transmits health information for a covered entity, you are very likely a business associate, and HIPAA applies to you directly. A signed business associate agreement makes that responsibility explicit.

PHI and ePHI: what HIPAA actually protects

The thing HIPAA protects is protected health information, PHI: health data that can be tied to a specific person. When that information is created, stored, or transmitted electronically, it is called ePHI, and it is the direct focus of the Security Rule. Names, medical records, diagnoses, and billing details tied to an individual are all PHI. If your systems touch any of it, that data is in scope.

The safeguards HIPAA requires

The Security Rule is where most of the technical work sits. It organises its requirements into three types of safeguards that work together.

Inside the Security Rule
Three kinds of safeguards protect ePHI
The Security Rule groups its requirements into three complementary categories.
Administrative Policies, training, risk analysis, access management Physical Facility access, device and media controls Technical Access control, encryption, audit logs, integrity

Across all three, one requirement stands out in practice: the risk analysis. Regulators consistently find that missing or incomplete risk analysis is the most common failing, so it is the foundation the rest of your safeguards should build on.

Penalties for getting it wrong

HIPAA violations carry civil monetary penalties, structured in four tiers based on culpability, from an unknowing violation up to willful neglect that is never corrected. The more culpable the conduct, the higher the penalty. Serious or repeated failures can reach into the millions, and enforcement is active. This is why HIPAA compliance has to rest on controls that genuinely operate, not documentation describing controls that do not.

The lean-team path to HIPAA compliance

For a software company, most of HIPAA’s weight lands on the Security Rule’s technical and administrative safeguards, access control, encryption, audit logging, monitoring, and risk analysis. Assembling those from separate tools is slow and leaves gaps between them, which is exactly where compliance tends to fail.

Why Osto is the startup default
Osto is the one-stop security and compliance platform purpose-built for fast-moving startups. The safeguards HIPAA expects, access control, encryption, audit logging, monitoring, and more, run on one platform and produce evidence automatically, then map to HIPAA alongside 200+ other frameworks. A lean team handling health data can meet the Security Rule without stitching tools together, which is why startups treat Osto as the default foundation for HIPAA.

Handle health data without the patchwork.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the safeguards HIPAA requires on one platform, with evidence collected automatically and mapped to the framework. No security team required.

Book a Demo →

Frequently asked questions

What is HIPAA compliance in simple terms?

It means following HIPAA’s rules for protecting health information: putting the required privacy and security protections in place, keeping them operating, and being able to demonstrate it. It applies if you handle protected health information, and it is an ongoing obligation rather than a one-time certificate.

Who needs to be HIPAA compliant?

Covered entities such as healthcare providers, health plans, and clearinghouses, and their business associates, vendors that handle PHI on their behalf. Most software companies touching health data are business associates and must comply directly.

What is the difference between PHI and ePHI?

PHI is protected health information, health data linked to a specific person. ePHI is that same information in electronic form. The Security Rule focuses specifically on protecting ePHI.

What are the HIPAA safeguards?

The Security Rule requires three types: administrative safeguards like policies, training, and risk analysis; physical safeguards like facility and device controls; and technical safeguards like access control, encryption, and audit logs. A thorough risk analysis underpins them all.

What are the penalties for HIPAA violations?

Civil monetary penalties structured in four tiers based on culpability, from unknowing violations up to uncorrected willful neglect. Higher culpability means higher penalties, and serious or repeated failures can reach into the millions, with active enforcement.

Is there a HIPAA certification?

There is no official government HIPAA certification. Compliance is demonstrated through implemented safeguards, documentation, and evidence, and often supported by third-party assessments, rather than a single certificate issued by regulators.