code/+/trust primary logo full color svg

HIPAA Software

Definition

HIPAA software is any application that creates, receives, maintains, or transmits Protected Health Information (PHI) and must comply with the HIPAA Security Rule's administrative, physical, and technical safeguards. Healthcare software companies that handle PHI must sign a Business Associate Agreement (BAA) with covered entities -- violations carry fines of $100-$50,000 per violation up to $1.9 million annually.

HIPAA compliance is not a certification -- it is an ongoing operational requirement. The HHS Office for Civil Rights enforces HIPAA through audits, complaints, and breach investigations. The largest HIPAA fines (Anthem: $16M; Community Health Systems: $5M) involve inadequate technical safeguards for PHI at rest and in transit.

Key technical safeguards for HIPAA software

  • Encryption of PHI at rest (AES-256) and in transit (TLS 1.2+)
  • Unique user identification and automatic logoff
  • Audit controls: logs of all access to PHI with user, timestamp, and action
  • Integrity controls: PHI cannot be altered or destroyed without detection
  • Transmission security: end-to-end encryption for all PHI over networks

HIPAA and AI

Using an LLM API (OpenAI, Anthropic) to process PHI requires a BAA with the LLM provider. Both OpenAI and Anthropic offer BAAs for enterprise plans. Sending PHI to a model without a BAA is a HIPAA violation regardless of the model's security posture. Self-hosted models eliminate the BAA requirement at the cost of significant infrastructure overhead.

Related terms

See how we implement this

Need help implementing this in your business?

Code and Trust translates AI concepts like hipaa software into working implementations, starting with a workflow audit that shows exactly where it creates ROI.

Schedule AI Audit →