HIPAA U.S. Healthcare Privacy Compliance

HIPAA
U.S. Healthcare Privacy Compliance

The Health Insurance Portability and Accountability Act (HIPAA) governs the protection of protected health information (PHI). While it only applies to covered entities and business associates, many Life Sciences organizations handling ePHI must comply.

Watch our webinar

Our Experts Are Here To Help You!

Need support with HIPAA compliance?

Our HIPAA Services Include

  • HIPAA compliance assessments
  • Development of custom HIPAA compliance programs
  • Staff training on privacy and security rule requirements

Why Choose MyData-TRUST?

  • Multi-jurisdictional privacy expertise
  • Sector-specific experience in Life Sciences
  • Deep understanding of U.S. federal and state laws
  • Alignment with global standards like GDPR and ISO 27701

Frequently asked questions

Do I still need to comply with HIPAA?

Yes, if your organization handles PHI as defined by HIPAA. HIPAA applies regardless of state-level legislation and has specific security and breach requirements.

I’m not a covered entity, why would I need to worry about HIPAA?

If your company works with or provides services for a Covered Entity, you are likely required to be HIPAA compliant under the Business Associate Agreement (BAA).

We are SOC / ISO compliant, so we’re fine under HIPAA.

SOC and ISO certifications refer to your information security and quality management processes, not your data protection compliance.

We’ve been HIPAA compliant for years, we don’t need additional data protection services.

State laws apply even if you’re HIPAA compliant. The federal requirements set the floor, but states can, and do, pass laws that require additional compliance.

Need more information about MyData-TRUST? Get in touch with our experts.

MyData-TRUST offers global coverage

Overview of other regional regulations