
HIPAA
HIPAA is a US law from 1996 that sets out how hospitals, insurers, and their service providers must handle patients' health data. For technology companies it's crucial, because any software that processes such data must comply with its requirements.
HIPAA is a law of the United States from the year 1996. Its full name is Health Insurance Portability and Accountability Act. It regulates who may view, store, and share patients' health data. This includes diagnoses, lab results, prescriptions, medical letters, and billing. Affected are hospitals, doctors' offices, health insurers, and all companies that work for them. Anyone who violates the law must expect steep fines.
Why health data is especially protected
Health data is among the most sensitive information about a person. A mental illness, an HIV diagnosis, or addiction treatment can affect a person’s entire life. In the US this is even sharper than in Germany. There, private insurers and sometimes even employers help determine how expensive treatment becomes. A data leak can therefore not only expose someone, but financially ruin them.
That’s why HIPAA provides for penalties that seriously hit a company. Up to around 2 million dollars per year are possible per violation category. In cases of willful misuse, prison sentences are also threatened. Major data breaches at clinics have already cost tens of millions of dollars.
A common misconception: HIPAA is not the American counterpart to the European General Data Protection Regulation. The GDPR applies to almost all data and almost all industries. HIPAA applies only to health data and only to a clearly defined circle of organizations. A fitness band that your company sells itself is usually not covered by it at all.
The three rule sets within the law
HIPAA essentially consists of three parts. The Privacy Rule defines what health data may be used for in the first place. Allowed are mainly treatment, billing, and normal clinical operations. For almost everything else, the patient’s written consent is required. In addition, the principle applies of always disclosing only the smallest possible amount of data.
The Security Rule concerns the technical side. Data must be encrypted both when stored and when transmitted. Every access requires its own user account and is logged. This makes it possible to later trace who opened which record. Backups and emergency plans are also mandated.
The Breach Notification Rule governs the worst case. If data goes missing, those affected must be informed within 60 days. From 500 affected individuals onward, the incident must additionally be reported publicly. Also important is the contract known as the Business Associate Agreement. Through it, a hospital obligates every service provider, such as a cloud provider, to the same rules.
HIPAA in cloud services and AI products
The term today appears mainly in the tech industry. Amazon Web Services, Microsoft Azure, and Google Cloud advertise offering HIPAA-compliant environments. AI model providers such as OpenAI or Anthropic also sign corresponding agreements with customers from the healthcare sector. Without this agreement, a clinic simply may not upload its patient data there.
This becomes especially interesting with language models. Doctors increasingly use programs that transcribe conversations and generate a medical letter from them. Such systems record diagnoses along the way and thus fall fully under the law. The provider then may not, for example, simply use the recordings to train new models without further ado.
One point often causes confusion. There is no official HIPAA seal awarded by an authority. No product is inherently compliant — only the way it is used can be. Marketing claims like HIPAA-certified should therefore be read with caution. Ultimately, responsibility remains with the clinic or practice itself.