HIPAA Security Rule Update Get ahead of the rule.

    Shareable worksheet · Ungated

    Before you put PHI in a new app.

    A polished login screen used to mean there was a privacy and security program behind it. That signal is gone. These ten questions still work.

    Read the full essay
    1. 01

      Will they sign a Business Associate Agreement before any PHI moves?

      A covered entity may disclose PHI to a business associate only with satisfactory assurance, documented in a written contract.

      45 CFR 164.502(e), 164.308(b), 164.504(e)

      Answer for question 01

      What a yes looks like

      A BAA that tracks the required terms — permitted uses, Security Rule safeguards, breach reporting, subcontractors, access/amendment/accounting, HHS access, return-or-destroy — not a one-page 'HIPAA addendum.'

    2. 02

      Who else creates, receives, maintains, or transmits this PHI — host, model, email, analytics, error logs, support — and do they have assurances from each?

      A subcontractor that handles PHI on behalf of a business associate is itself a business associate. The vendor you hired has to bind that chain.

      45 CFR 160.103; 164.308(b)(2); 164.502(e)(1)(ii)

      Answer for question 02

      What a yes looks like

      A current subprocessor list, plus BAAs (or equivalent written assurances) behind each party that can see PHI. 'We don't look at your data' is not a list.

    3. 03

      Have they conducted an accurate and thorough risk analysis of this system?

      Risk analysis is required for covered entities and business associates. A generated UI is not an assessment of threats to ePHI.

      45 CFR 164.308(a)(1)(ii)(A)

      Answer for question 03

      What a yes looks like

      A dated analysis of this product: where ePHI lives, who can reach it, what was found, what was mitigated. A generic 'AI safety' PDF does not count.

    4. 04

      Does every person get a unique user ID — no shared 'clinic' login?

      Unique user identification is a required implementation specification. If you cannot name the person, you cannot produce a meaningful access report.

      45 CFR 164.312(a)(2)(i) — Required

      Answer for question 04

      What a yes looks like

      Named accounts, a way to provision and terminate access, and authentication that verifies the person is who they claim (164.312(d)).

    5. 05

      Do they record activity in this system — and regularly review those records?

      Audit controls are a Security Rule standard. Information system activity review is required. Keeping logs nobody reads is half the job.

      45 CFR 164.312(b); 164.308(a)(1)(ii)(D) — Required

      Answer for question 05

      What a yes looks like

      Who opened which record, when. A review cadence. A sample of what they did the last time something looked wrong.

    6. 06

      Is ePHI encrypted at rest and in transit — or did they document why not and implement an equivalent alternative?

      Encryption is addressable, not optional. Addressable means implement it if reasonable and appropriate, or document why not and adopt an equivalent alternative.

      45 CFR 164.306(d); 164.312(a)(2)(iv); 164.312(e)(2)(ii) — Addressable

      Answer for question 06

      What a yes looks like

      Encryption in transit and at rest for ePHI, or a written addressable decision plus the equivalent alternative. 'HIPAA doesn't require encryption' is the wrong sentence.

    7. 07

      When this relationship ends, can they return or destroy your PHI and retain no copies — including backups and logs?

      The BAA requires return or destruction at termination, or a documented reason it is not feasible, with protections extended to whatever remains.

      45 CFR 164.504(e)(2)(ii)(J)

      Answer for question 07

      What a yes looks like

      A written offboarding path that names the database, backups, log drains, model-provider logs, and support tickets. 'We'll delete the project' is not a path.

    8. 08

      How will they notify you of a breach, and in what window?

      A business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, identifying affected individuals to the extent possible.

      45 CFR 164.410

      Answer for question 08

      What a yes looks like

      A written incident procedure, a clock shorter than or equal to 60 days, and the fields they will send you (who, what, when, mitigation). Sixty days is the ceiling, not a target.

    9. 09

      Are pixels, SDKs, session replay, or analytics running on screens where PHI is entered or viewed?

      If a tracker receives PHI, that disclosure has to be permitted under the Privacy Rule — typically a BAA with the tracking vendor, or a valid authorization. A privacy policy is not a BAA.

      45 CFR 164.502(a); OCR tracking-technologies guidance

      Answer for question 09

      What a yes looks like

      A current inventory of trackers on authenticated and intake screens, plus BAAs or a documented reason PHI never reaches them. Default analytics on a chart view is a tell.

    10. 10

      Can they show written policies and a documentation trail — not the landing page?

      Policies and procedures must exist in writing and be retained for six years. A periodic evaluation is required when operations change. A weekend rewrite is an operational change.

      45 CFR 164.316; 164.308(a)(8)

      Answer for question 10

      What a yes looks like

      Named security official, written policies that mention this product, retention of six years, and an evaluation after the last material change (new host, new model, new support widget).

    How to read this

    Fill it with the vendor on the phone.

    A BAA is how you document satisfactory assurances. It is not the assurance. The UI is not evidence. Covered entities still own the outcome when a vendor's gap surfaces — most of these shops are well-intentioned and have never been walked through this list.

    0 of 10 answered

    Accuracy & legal note. Plain-language summary of HIPAA (45 CFR Parts 160 and 164) and related HHS/FTC guidance as of August 2026. Regulations change. This is general educational information, not legal advice — verify current requirements at hhs.gov/hipaa or with your compliance counsel. Last updated: August 2026.