Hacker News new | ask | show | jobs
by avgDev 1197 days ago
No. HIPPA applies to software as the software company would be considered a business associate.

"If you handle, store or transmit protected health information (PHI) to or from a covered entity then you need to be HIPAA compliant."

Source: https://github.com/truevault/hipaa-compliance-developers-gui...

2 comments

Business associate only comes into play when you're working with a covered entity. And, covered entities are far less inclusive than most people think.

----

The posted software is absolutely free to be non-HIPAA compliant. They're not a covered entity and without a relationship with a covered entity, they're not a business associate. However, without a relationship with a covered entity, they're also unlikely to generate any meaningful revenue.

This is not so clear-cut, though. There is a lot of gray area and doubt about this. HIPAA is not as complete protection as people think, and there are many situations where you'd think HIPAA would obviously apply, but it doesn't.