Compliance & Regulatory

    HIPAA

    HIPAA is the US law governing how patient health information is collected, stored, and shared. Any platform handling patient data needs HIPAA-compliant architecture from day one, since encryption, access controls, and audit logging have to be built into the system design, not added after launch.

    Key takeaways

    • US law governing use and protection of patient health data
    • Requires administrative, physical, and technical safeguards together
    • Encryption, access controls, and audit logging must be designed in
    • Every vendor touching patient data needs a signed BAA
    • Retrofitting compliance after launch is expensive and risky

    What HIPAA means

    HIPAA is best understood as a set of obligations that follow the data rather than a single feature you can toggle on. Its Security Rule expects reasonable and appropriate safeguards across three areas: administrative controls like policies and workforce training, physical controls over where systems live, and technical controls such as encryption, access management, and logging. For a software team, that means the law reaches into how you design infrastructure, not just how you write a privacy policy.

    In practice, satisfying HIPAA is less about a certificate and more about being able to show your work. You need to demonstrate who can access patient data, prove that access is logged and reviewed, and show that data is encrypted in transit and at rest. Every vendor in the chain that touches patient data, including your cloud host, has to be under contract to uphold the same standards, which is why the paperwork and the architecture have to line up.

    The costly mistake is treating compliance as a launch checklist. Retrofitting encryption, tightening access roles, or adding audit trails after a product is live usually forces changes to the data model and infrastructure that are far more expensive than building them in from the first sprint. When evaluating a development partner, look for teams that treat these controls as default engineering practice rather than an add-on.

    Explore this on Agnotic

    Where HIPAA shows up in how we build.

    Frequently asked questions

    There is no single government-issued HIPAA certificate that permanently marks a product as compliant. Compliance is an ongoing posture you maintain and can demonstrate through documented safeguards, risk assessments, and audit evidence. Third-party attestations and frameworks can support your case, but the responsibility to keep controls in place is continuous, not one-time.

    Talk through your build with an engineer

    Tell us what you're building and the systems it needs to talk to, and we'll map a clear, compliant path to launch.