Hacker News new | ask | show | jobs
by hn_throwaway_99 1353 days ago
Yes, lots of data storage companies are - that's why these companies sign BAAs (Google HIPAA BAA for info).

There are some carve outs. For example, financial services companies don't have any additional privacy requirements if you buy a prescription with your Visa instead of cereal. That carve out was specifically added to the HIPAA legislation.