HIPAA
HIPAA (the Health Insurance Portability and Accountability Act of 1996) is the US federal law that sets privacy, security, and breach-notification rules for protected health information held by healthcare organizations and their vendors.
- Enacted 1996; Privacy, Security, and Breach Notification Rules do the work
- Binds covered entities and their business associates via BAAs
- Not a general privacy law — non-care health data often falls outside it
- Enforced by HHS Office for Civil Rights, with state AGs alongside
What HIPAA actually regulates
Three rules do the work. The Privacy Rule governs how protected health information (PHI) may be used and disclosed. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI. The Breach Notification Rule dictates who must be told, and how fast, when data is compromised. The rules bind covered entities — providers, plans, clearinghouses — and their business associates under signed BAAs.
What HIPAA is not
HIPAA is not a general health-privacy law. Data collected outside the care relationship — a wellness app with no provider behind it, a fitness tracker, an advertising pixel on a marketing page — often falls outside HIPAA entirely, landing under FTC rules and state privacy laws instead. Serious digital-health companies treat all patient-adjacent data to the HIPAA standard anyway, because the reputational blast radius of “technically not PHI” is identical.
The practical checklist for a telehealth program: a BAA with every vendor touching PHI, access controls and audit logs, encryption in transit and at rest, a breach-response plan, and marketing analytics kept strictly out of authenticated care surfaces.
Compliance handled, so you can build
Lithos runs the clinicians, pharmacies, and 50-state rules behind your care program — one API.
Frequently asked questions
Does HIPAA apply to my telehealth startup?
If patient care happens through your product, effectively yes — you will hold PHI as a covered entity or business associate, and vendors need BAAs.
Is HIPAA compliance a certification?
No — there is no official HIPAA certificate. Compliance is an ongoing posture of safeguards, policies, and contracts, verified through audits and attestations.
What are the penalties?
Civil penalties scale with negligence into the millions per violation category per year; criminal penalties exist for knowing misuse. Enforcement usually follows breaches or complaints.