Skip to main content
Category: Regulatory Frameworks

Health Insurance Portability and Accountability Act

Also known as: HIPAA, Health Insurance Portability and Accountability Act of 1996
Simply put

HIPAA is a U.S. federal law passed in 1996 that sets standards for protecting sensitive patient health information and also addresses the ability to transfer and continue health insurance coverage. It regulates how certain organizations handle, use, and disclose protected health information (PHI). It applies within the United States and is not a global standard.

Formal definition

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a U.S. federal statute that establishes federal standards for protecting sensitive health information and reforms aspects of the health insurance industry, including the portability and continuity of coverage. Its regulatory standards govern the lawful use and disclosure of protected health information (PHI). In a third-party risk context, HIPAA obligations typically extend to covered entities and their vendors that handle PHI, meaning organizations may need to assess suppliers for HIPAA-relevant safeguards; however, HIPAA addresses health information privacy and security within U.S. jurisdiction and does not, by itself, cover financial, operational, geopolitical, or broader ESG risk categories. Note that HIPAA sets requirements rather than conferring a certification, and adherence is generally demonstrated through compliance programs rather than a single attestation.

Why it matters

HIPAA matters to third-party risk professionals because its obligations do not stop at the boundary of the organization that first collects protected health information (PHI). When a covered entity engages vendors that handle PHI on its behalf, HIPAA-relevant safeguards typically become a consideration in how those suppliers are assessed, contracted, and monitored. This makes HIPAA a recurring reference point in vendor due diligence for organizations operating in or servicing the U.S. healthcare sector, where a supplier's handling of health information can create exposure that flows back to the engaging organization.

It is important to be precise about what HIPAA does and does not cover. HIPAA addresses the privacy and security of health information within U.S. jurisdiction; it is not a global standard, and it does not by itself cover financial, operational, geopolitical, or broader ESG risk categories that a comprehensive third-party risk program must also evaluate. Treating HIPAA as a proxy for overall vendor risk would leave material risk categories unaddressed.

A further point of care for expert readers: HIPAA sets requirements rather than conferring a certification. Adherence is generally demonstrated through ongoing compliance programs rather than a single attestation, so a vendor's claim of being "HIPAA compliant" is a self-representation that typically warrants verification rather than acceptance at face value. Because such representations can be point-in-time and self-reported, they may not reflect a supplier's current safeguards without independent validation and ongoing monitoring.

Who it's relevant to

Third-party risk and vendor management teams
Teams assessing suppliers that handle PHI on behalf of a covered entity typically incorporate HIPAA-relevant safeguards into due diligence and ongoing monitoring. Because HIPAA compliance is demonstrated through programs rather than a single attestation, these teams generally need to look beyond a vendor's self-reported claim and consider independent validation appropriate to the risk tier.
Compliance and privacy officers
Professionals responsible for regulatory adherence rely on HIPAA's federal standards for the lawful use and disclosure of PHI. They should be aware that HIPAA applies within U.S. jurisdiction and is not a global standard, so vendors and data flows outside the United States may fall under different regimes that must be assessed separately.
Procurement and contract owners in healthcare-related supply chains
Those onboarding suppliers whose services touch health information consider HIPAA obligations when structuring contractual terms and safeguards. HIPAA addresses health information privacy and security only, so it does not substitute for evaluating financial, operational, geopolitical, or ESG risks that a broader vendor assessment should cover.
Information security and resilience practitioners
Security teams supporting covered entities and their vendors address the safeguards HIPAA expects for protecting sensitive health information. They should note that HIPAA's scope centers on health information rather than conferring a certification, and that point-in-time evidence of controls may become stale absent continuous monitoring.

Inside HIPAA

Privacy Rule
Establishes standards governing the use and disclosure of protected health information (PHI) by covered entities, and defines individuals' rights over their health information. In a third-party context, it constrains how PHI may be shared with and handled by service providers.
Security Rule
Sets administrative, physical, and technical safeguards for electronic protected health information (ePHI). It addresses information security controls but does not, on its own, cover broader vendor risks such as financial stability, operational resilience, or geopolitical exposure.
Breach Notification Rule
Requires notification following a breach of unsecured PHI. Business associates typically must notify the covered entity, which carries downstream reporting obligations, making breach notification terms a common element of third-party contracting.
Business Associate
A third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This is the primary construct through which HIPAA obligations extend into third-party relationships, distinct from vendors that never touch PHI.
Business Associate Agreement (BAA)
A contract that establishes the permitted uses of PHI and the safeguards a business associate must apply. It is a contractual control that allocates obligations but does not itself verify that the business associate has implemented those safeguards.
Subcontractor / downstream flow
Business associates that engage their own subcontractors handling PHI typically must extend comparable obligations through further agreements, creating a chain relevant to fourth-party and Nth-party risk beyond the direct contractual relationship.

Common questions

Answers to the questions practitioners most commonly ask about HIPAA.

Does signing a HIPAA business associate agreement (BAA) certify that a vendor is HIPAA compliant?
No. A BAA is a contractual arrangement in which a business associate agrees to safeguard protected health information (PHI) and accept certain HIPAA obligations; it is an attestation of commitment, not independent verification of a vendor's controls. HIPAA has no government-issued certification, so a signed BAA does not confirm that safeguards are actually implemented or effective. Programs typically supplement the BAA with due diligence, evidence review, and ongoing monitoring rather than relying on the agreement alone.
Is HIPAA a broad data privacy law that covers all personal or health-related data a vendor might handle?
No. HIPAA applies to protected health information (PHI) created, received, maintained, or transmitted by covered entities and their business associates. It does not govern all health-related data; information held outside those relationships, such as data in certain consumer health apps or wellness platforms, may fall outside HIPAA's scope and be addressed by other laws instead. Assessing a vendor against HIPAA does not necessarily cover other privacy, financial, operational, or security risks.
When does a third party become a business associate that requires a BAA?
Generally, a third party becomes a business associate when it creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a function or service. In many programs, identifying these relationships is part of onboarding due diligence, and the presence of PHI access, rather than the vendor's label, drives the need for a BAA. Whether a specific engagement qualifies can depend on the nature of the service and the data involved, so scoping is typically assessed case by case.
How should a program handle HIPAA obligations that extend to a business associate's subcontractors?
HIPAA obligations can flow down to subcontractors that handle PHI on behalf of a business associate, which introduces fourth-party or Nth-party considerations distinct from the direct third-party relationship. Many programs address this by requiring the business associate to obtain BAAs with its own subcontractors and by seeking assurance about those downstream arrangements. Visibility beyond the direct vendor is often limited, so this flow-down is frequently a point of reduced assurance rather than direct oversight.
What evidence beyond a signed BAA can support ongoing HIPAA assurance for a vendor?
Depending on the risk tier, programs may review documentation of administrative, physical, and technical safeguards, security assessments, breach notification procedures, and independent audit or examination reports where available. Because much of this evidence can be self-reported or point-in-time, it may become stale and often benefits from independent validation. No single artifact confirms compliance, so assurance typically rests on a combination of contractual, procedural, and evidentiary review sustained over time.
Does a HIPAA-focused vendor assessment address the vendor's full risk profile?
No. A HIPAA-focused assessment centers on the protection of PHI and related privacy and security obligations. It does not, on its own, cover financial stability, operational resilience, geopolitical exposure, ESG factors, or security risks unrelated to PHI. In many programs, HIPAA-specific due diligence is one component within a broader third-party risk assessment rather than a substitute for it.

Common misconceptions

A signed Business Associate Agreement means a vendor is HIPAA compliant and its safeguards are verified.
A BAA is a contractual attestation of obligations, not independent verification that controls are in place or effective. Confirming compliance typically requires additional due diligence and, where appropriate, independent assessment rather than reliance on the contract alone.
HIPAA covers all third-party risk posed by a healthcare vendor.
HIPAA focuses on the privacy and security of protected health information. It does not address a vendor's financial viability, operational continuity, concentration risk, or ESG exposure, which typically require separate assessment within a broader TPRM program.
HIPAA obligations stop with the organization's direct vendor.
When a business associate engages subcontractors that handle PHI, obligations typically flow further down the chain. Managing this requires attention to fourth-party and Nth-party relationships, not just the direct contractual party.

Best practices

Identify which third parties actually create, receive, maintain, or transmit PHI so business associate status is assigned based on data flows rather than assumption, and scope obligations accordingly.
Execute Business Associate Agreements before PHI is shared, and treat them as one control among several rather than as proof of implemented or effective safeguards.
Supplement contractual attestations with due diligence proportionate to the risk tier, and where warranted seek independent evidence rather than relying solely on the vendor's self-reported representations.
Address downstream subcontractors that handle PHI by confirming that comparable obligations flow through the chain, extending visibility beyond the first tier where feasible.
Complement HIPAA-focused review with assessment of financial, operational, resilience, and other risks that HIPAA does not cover, so vendor evaluation is not limited to information privacy and security.
Move beyond point-in-time review by monitoring business associates on an ongoing basis, since a control state confirmed at onboarding can become stale over the life of the relationship.
Establish breach notification expectations and timelines contractually, recognizing that downstream reporting obligations may be triggered by an incident at a business associate.
Promotional banner for the Pentest Readiness checklist download