Regulation · Filed · New York · 8 min read
HIPAA Compliance Requirements: What US Health-Tech Founders Miss
The Privacy, Security, and Breach Notification Rules translated into the specific controls, contracts, and evidence a modern digital-health company must maintain.
By Cyber Inspect Editorial Board
The three rules, in operating terms
The Privacy Rule governs use and disclosure of protected health information. The Security Rule mandates administrative, physical, and technical safeguards. The Breach Notification Rule prescribes the timing and content of disclosures to affected individuals, HHS, and, in some cases, the media.
Where founders most often fall short
- Business Associate Agreements missing with lower-tier sub-processors (analytics, error tracking, LLM providers).
- No documented risk analysis under 45 CFR § 164.308(a)(1)(ii)(A) — this is the single most cited deficiency in OCR enforcement actions.
- Audit logs retained for less than the six-year regulatory minimum.
- Access provisioning that relies on Google Workspace groups without periodic review evidence.
- AI features that route PHI to model providers without BAAs or de-identification.
A pragmatic path to defensibility
We recommend a HIPAA program anchored to NIST SP 800-66 Rev. 2, with quarterly control testing and annual risk analysis refresh. For companies that also pursue SOC 2, the two programs share roughly 70% of controls when scoped correctly.