What is HIPAA compliance, in plain terms? The US law that governs how health information is protected, who has to follow it, and what happens when it is mishandled.
TL;DR
HIPAA is a US law that protects sensitive health information. Compliance means following its rules, chiefly the Privacy Rule, the Security Rule, and the Breach Notification Rule, if you handle protected health information (PHI).
It applies to covered entities like healthcare providers and health plans, and to their business associates, which includes most software vendors that touch PHI. Getting it wrong carries tiered civil penalties, so the security has to be real, not on paper.
On this page
What is HIPAA compliance?
HIPAA, the Health Insurance Portability and Accountability Act, is a US federal law that sets national standards for protecting sensitive patient health information. Compliance means meeting those standards: putting the required privacy and security protections in place, keeping them operating, and being able to show it. It is not a certificate you earn once. It is an ongoing obligation to protect health data and prove you are doing so.
The rules that make up HIPAA
HIPAA is often described as one thing, but in practice a handful of rules do most of the work. Three matter most for anyone handling health data.
The Privacy Rule governs how protected health information may be used and shared. The Security Rule requires specific safeguards for that information in electronic form. The Breach Notification Rule sets out who must be told, and how quickly, if the information is exposed.
Who has to comply with HIPAA?
HIPAA applies to two broad groups, and the second one catches many technology companies by surprise.
| Group | Who it covers | Examples |
|---|---|---|
| Covered entities | Those who provide care or handle health coverage | Hospitals, clinics, doctors, health plans, clearinghouses |
| Business associates | Vendors that handle PHI on their behalf | SaaS platforms, cloud hosts, billing and analytics providers |
PHI and ePHI: what HIPAA actually protects
The thing HIPAA protects is protected health information, PHI: health data that can be tied to a specific person. When that information is created, stored, or transmitted electronically, it is called ePHI, and it is the direct focus of the Security Rule. Names, medical records, diagnoses, and billing details tied to an individual are all PHI. If your systems touch any of it, that data is in scope.
The safeguards HIPAA requires
The Security Rule is where most of the technical work sits. It organises its requirements into three types of safeguards that work together.
Across all three, one requirement stands out in practice: the risk analysis. Regulators consistently find that missing or incomplete risk analysis is the most common failing, so it is the foundation the rest of your safeguards should build on.
Penalties for getting it wrong
HIPAA violations carry civil monetary penalties, structured in four tiers based on culpability, from an unknowing violation up to willful neglect that is never corrected. The more culpable the conduct, the higher the penalty. Serious or repeated failures can reach into the millions, and enforcement is active. This is why HIPAA compliance has to rest on controls that genuinely operate, not documentation describing controls that do not.
The lean-team path to HIPAA compliance
For a software company, most of HIPAA’s weight lands on the Security Rule’s technical and administrative safeguards, access control, encryption, audit logging, monitoring, and risk analysis. Assembling those from separate tools is slow and leaves gaps between them, which is exactly where compliance tends to fail.
Handle health data without the patchwork.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the safeguards HIPAA requires on one platform, with evidence collected automatically and mapped to the framework. No security team required.
Frequently asked questions
What is HIPAA compliance in simple terms?
It means following HIPAA’s rules for protecting health information: putting the required privacy and security protections in place, keeping them operating, and being able to demonstrate it. It applies if you handle protected health information, and it is an ongoing obligation rather than a one-time certificate.
Who needs to be HIPAA compliant?
Covered entities such as healthcare providers, health plans, and clearinghouses, and their business associates, vendors that handle PHI on their behalf. Most software companies touching health data are business associates and must comply directly.
What is the difference between PHI and ePHI?
PHI is protected health information, health data linked to a specific person. ePHI is that same information in electronic form. The Security Rule focuses specifically on protecting ePHI.
What are the HIPAA safeguards?
The Security Rule requires three types: administrative safeguards like policies, training, and risk analysis; physical safeguards like facility and device controls; and technical safeguards like access control, encryption, and audit logs. A thorough risk analysis underpins them all.
What are the penalties for HIPAA violations?
Civil monetary penalties structured in four tiers based on culpability, from unknowing violations up to uncorrected willful neglect. Higher culpability means higher penalties, and serious or repeated failures can reach into the millions, with active enforcement.
Is there a HIPAA certification?
There is no official government HIPAA certification. Compliance is demonstrated through implemented safeguards, documentation, and evidence, and often supported by third-party assessments, rather than a single certificate issued by regulators.

