Hacker News new | past | comments | ask | show | jobs | submit login

There are criteria for which organizations are covered by HIPAA’s privacy protections. It is not attached to the data wherever the data goes.



Yes, those are covered entities. Their subcontractors who touch HIPAA data are business associates.

See https://www.hhs.gov/hipaa/for-professionals/covered-entities... and https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-...

In my experience, covered entities are really serious about signing BAAs with any of their hosting vendors and partners, as afaik the liability falls on the covered entity if they didn't have an agreement in place and data leaked from a vendor/partner.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: