Hacker News new | ask | show | jobs
by ceejayoz 1197 days ago
If the provider wants to use the extension for patient care, the extension maker must be prepared to enter into an agreement to comply with the HIPAA rules.

https://www.hhs.gov/hipaa/for-professionals/covered-entities...

> If a covered entity engages a business associate to help it carry out its health care activities and functions, the covered entity must have a written business associate contract or other arrangement with the business associate that establishes specifically what the business associate has been engaged to do and requires the business associate to comply with the Rules’ requirements to protect the privacy and security of protected health information.