Questions? Talk to a Real Person via our Live Chat
What Is a BAA? The HIPAA Business Associate Agreement Explained
By Monica Dircio, , HIPAA Blog, HIPAA Compliance, Resources

What Is a BAA? The HIPAA Business Associate Agreement Explained

A BAA — Business Associate Agreement — is a legally required contract under HIPAA between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. Without a signed BAA, using any third-party vendor for anything involving PHI is a direct HIPAA violation — regardless of how... Continue reading
What Does “HIPAA Certified” Mean? The Truth About HIPAA Certification
By Gil Vidals, , HIPAA Blog, HIPAA Compliance, Resources

What Does “HIPAA Certified” Mean? The Truth About HIPAA Certification

The short answer: There is no official government-issued “HIPAA certification.” The U.S. Department of Health and Human Services (HHS) does not offer, endorse, or recognize any HIPAA certification program. When a vendor, software provider, or service claims to be “HIPAA certified,” that certification comes from a private third-party organization — not from HHS or any... Continue reading
What Does HIPAA Stand For?
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

What Does HIPAA Stand For?

HIPAA stands for the Health Insurance Portability and Accountability Act. It is a federal law signed by President Bill Clinton on August 21, 1996. HIPAA establishes national standards for protecting sensitive patient health information — known as protected health information (PHI) — from being disclosed without a patient’s knowledge or consent. The law is administered... Continue reading
Who Needs to Be HIPAA Compliant?
By Brenda Medel, , HIPAA Blog, HIPAA Compliance, Resources

Who Needs to Be HIPAA Compliant?

Healthcare organizations often ask the same critical question: who needs to be HIPAA compliant? The answer is broader than many companies realize. HIPAA compliance applies to more than hospitals and doctor’s offices. Health insurance companies, healthcare software vendors, cloud hosting providers, medical billing companies, and even email providers may all fall under HIPAA regulations depending... Continue reading
Is Google Analytics HIPAA Compliant?
By Alicia Kelley, , HIPAA Blog, HIPAA Compliance, Resources

Is Google Analytics HIPAA Compliant?

No — Google Analytics is not inherently HIPAA compliant. Healthcare organizations can use Google Analytics only in limited circumstances, and only if no Protected Health Information (PHI) is transmitted. If PHI is disclosed to Google without proper safeguards and agreements, it may constitute a HIPAA violation. Because many healthcare websites collect appointment requests, include condition-specific... Continue reading