HIPAA
U.S. federal law governing the privacy and security of protected health information.
Definition
The Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the HITECH Act (2009) and the HIPAA Omnibus Rule (2013), establishes federal requirements for the privacy and security of Protected Health Information (PHI) in the United States. The HIPAA Security Rule (45 CFR Part 164 Subpart C) requires Covered Entities and Business Associates to implement administrative, physical, and technical safeguards for electronic PHI (ePHI). HHS Office for Civil Rights (OCR) enforces HIPAA.What this means in practice
Connected medical devices increasingly touch PHI - telemetry, patient identifiers, device-derived diagnostic data. The right design pattern is to minimize PHI on the device, encrypt in transit and at rest, segment from non-PHI workloads, and codify the BAA terms in product architecture decisions. Failure to recognize Business Associate status is a leading cause of OCR enforcement against MedTech companies.- •Assuming MedTech manufacturers aren't subject to HIPAA - Business Associate status is common.
- •Storing PHI in customer-support tooling or analytics platforms without BAAs and equivalent controls.
- •Treating de-identified data as 'not PHI' without meeting the Safe Harbor or Expert Determination standards.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.
U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.
International standard for information security management systems (ISMS), often required of MedTech vendors by enterprise customers.
Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
HHS HIPAA Security RuleVerifiedHHS OCRhhs.gov
- 2
45 CFR Part 164 Subpart CVerifiedeCFRecfr.gov
- 3
HIPAA Security Rule NPRM (2024)VerifiedFederal Registerfederalregister.gov
Inline markers like [1] jump to the matching reference above.