Frequently Asked Questions
What makes an app subject to HIPAA?
HIPAA applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates (companies that handle PHI on their behalf). A consumer wellness app that does not interact with a covered entity is generally not subject to HIPAA. A telehealth app used by a covered entity provider is subject to HIPAA. An app that connects to an EHR to access patient data is subject to HIPAA. A mental health app that connects users with licensed therapists is subject to HIPAA. If uncertain, assume HIPAA applies — the cost of compliance is far lower than the cost of non-compliance.
What is a BAA and who needs one?
A Business Associate Agreement is a contract required by HIPAA between a covered entity (or business associate) and any third party that processes, stores or transmits PHI on their behalf. You need BAAs with: your cloud provider (AWS, GCP, Azure all offer them), your database vendor if managed, your email provider if you send PHI in emails, your video conference provider for telehealth, your logging/monitoring vendor if logs contain PHI, your analytics platform if you track any PHI. If a vendor refuses to sign a BAA, you cannot use them for any service that involves PHI.
What is HL7 FHIR and why does it matter?
HL7 FHIR (Fast Healthcare Interoperability Resources) is the modern healthcare data exchange standard. It defines a REST API specification and data formats (resources) for healthcare data — Patient, Observation, Condition, Medication, Appointment, etc. The ONC 21st Century Cures Act mandates FHIR R4 API support for EHR vendors, making it the standard path for accessing patient data. New healthcare app integrations should use FHIR R4 where available. SMART on FHIR adds OAuth 2.0 authorisation for app access to EHR data with patient or provider consent.
Can we use AWS for HIPAA-compliant healthcare apps?
Yes. AWS offers a Business Associate Agreement and designates specific services as HIPAA-eligible. Key HIPAA-eligible AWS services: EC2, RDS, S3, Lambda, Cognito, KMS, CloudTrail, CloudWatch, DynamoDB, ECS, EKS, SQS. Not all AWS services are HIPAA-eligible — check the AWS HIPAA compliance page before using any service in a PHI-processing workload. The BAA covers the AWS infrastructure; you are responsible for configuring it correctly (encryption enabled, access controls, logging).