“Is our app HIPAA compliant?”
If you work in Health IT, this is a common and important question.
At Big Fish, we’ve been designing and developing secure, custom mobile apps since 2014 – including apps for healthcare organizations that manage protected health information.
As a healthcare app development company, we understand what it takes to support HIPAA compliance and build technology that’s both secure and user-friendly.
So how can you ensure your custom app is HIPAA compliant? And what does it really mean for an app to be HIPAA compliant?
Let’s start by looking at what the HIPAA regulation actually says.
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a suite of regulations that are officially known as 45 CFR parts 160, 162, and 164.
In brief, the regulation establishes national standards to safeguard protected health information (PHI) and defines standards around who can access that information.
Full details on the HIPAA regulations is available here, along with a “simplified” 115 page guide here.
The regulation starts off with an important detail – who or what must comply with HIPAA?
(1) a health plan,
(2) a health care clearinghouse,
(3) a health care provider who transmits any health information, and
(3b) in many cases a business associate of that provider.
What stands out as missing from that list? Software!
HIPAA compliance applies to covered entities (e.g. health plans and healthcare providers) and business associates, not to software or apps in isolation.
A piece of software, in and of itself, cannot be ruled HIPAA compliant or not compliant. Your business, and by extension, many of your business associates, are governed by HIPAA regulations. Your software itself is not. Share on X
If apps cannot be HIPAA compliant, what should you be asking?
HIPAA Compliance Checklist for Your App
Before starting or integrating any custom app that handles protected health information, walk through the following checklist to ensure you are compliant with HIPAA.
1. Have you signed a Business Associate Agreement with your developer?
Typically, many of your software vendors will be considered Business Associates if they host, access or maintain systems that contain PHI. In those cases, you’re required to have a signed Business Associate Agreement (BAA) in place.
However, not all app developers meet the definition of a Business Associate. If your developer never handles PHI – such as when you’re hosting the software yourself and they only provide code – then a BAA may not be necessary. But if there’s any access to PHI (even for support or debugging), a BAA is a must.
Questions to ask:
- Will they sign a BAA with you?
- Are you expected to sign theirs, or can you provide your own?
- Does the BAA clearly define responsibilities and liabilities?
The Department of Health and Human Services (HHS) offers sample BBA provisions and a Business Associate Agreement template you can use.
2. What technical safeguards are in place to protect PHI?
HIPAA requires that you implement appropriate technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI).
Whether you’re hosting data yourself or working with a third-party vendor, these protections need to be clearly defined – and someone needs to be responsible for them.
If a Business Associate is hosting your data, they’ll typically bear that responsibility. If you’re hosting it yourself, the burden is on you.
A signed Business Associate Agreement should clarify these responsibilities and outline what security controls are in place. Be sure it spells out liability and obligations on both sides.
Key areas to evaluate include:
- How access to PHI is managed and logged (more on this in point #4)
- What protections are in place to detect and respond to unauthorized access
- The security of your infrastructure and any APIs or integrations
3. Is Your PHI properly encrypted in transit and at rest?
Encryption is one of the most critical technical safeguards under HIPAA. It ensures that even if data is intercepted or improperly accessed, it remains unreadable and protected.
Ask these specific questions:
- Is PHI encrypted as it moves across networks?
- Is it encrypted at rest on servers and devices?
- Where are backups stored, and are they encrypted?
If you’re managing your own infrastructure, make sure your internal security policies are up-to-date and robust enough to prevent breaches. Encryption practices should be documented and regularly reviewed as part of your HIPAA compliance plan.
4. Does your app maintain an audit trail of PHI access?
HIPAA requires that covered entities and their business associates implement audit controls that track access to ePHI. That means your app should be able to log:
- Who accessed patient data
- When they accessed it
- What was viewed, added or modified
- Where the access came from (e.g., IP address or device)
If your app doesn’t support access logging, you may not be able to meet your compliance obligations.
Be sure your developers have built audit trail functionality into the system and that logs are securely stored, reviewable and retained according to your internal policies.
—
While your app itself can’t be declared HIPAA compliant, it must include key capabilities that enable your organization to comply with HIPAA requirements. If your software can’t generate audit logs, encrypt PHI, or control access, then you simply can’t meet your obligations under the law – no matter how good your policies are.
Real-World Example of a HIPAA Violation
In 2015, Cottage Health, a California-based healthcare provider, experienced a significant data breach.
The breach occurred when a server was misconfigured following an IT response to a troubleshooting ticket, exposing unsecured ePHI over the internet.
This ePHI included patient names, addresses, dates of birth, Social Security numbers, diagnoses, conditions and other treatment information.
The breach impacted more than 5,000 individuals and resulted in a $3 million settlement with the Office for Civil Rights.
The Department of Health provides a set of HIPAA violation case examples for your review.
HIPAA is Really About Your Policies and Documentation
In many cases, what you are really asking is “Does this app cause me any additional burden for my business to comply with the HIPAA regulations?”
- You are required to have a BAA in place with everyone you exchange PHI with.
- You are required to have policies and procedures for how you and your staff will safeguard the PHI you maintain.
You should never undertake a new software project without understanding the impact that new piece of software or service will have on those policies and procedures.
The Bottom Line: HIPAA Compliance is About More Than the App
Your software or app is not HIPAA compliant. It is the policies and procedures you have in place to safeguard protected health information that determine whether your organization complies with the HIPAA regulations.
Your app is not #HIPAA compliant. It's the policies and procedures you have in place to protect PHI that determine whether your organization complies with the HIPAA regulations. Share on X
About This Article
We originally published this article in 2016, with updates made in 2022 and again in 2025 to ensure continued relevance and accuracy.
As of early 2025, the U.S. Department of Health and Human Services (HHS) has proposed updates to the HIPAA Security Rule aimed at strengthening protections around electronic protected health information (ePHI).
If finalized, these changes may require covered entities and business associates to implement annual technical inventories, enhanced risk assessments and stronger safeguards such as multi-factor authentication and advanced encryption.
While these proposals are not yet law, they reflect the direction HIPAA compliance is heading – making it more important than ever to assess not just whether your app supports HIPAA compliance, but whether your policies, technical practices and vendor relationships are ready for what’s next.
You can download a fact sheet on the proposed rule updates for an easier read.


