Aboutwhy sjkplawyerspracticesInsightsCase StudyNewsLocations
Medical

HIPAA Compliance

A clinic adds a patient portal, a software company signs its first hospital customer, a billing service takes on a dental group, and suddenly someone asks whether the business is HIPAA compliant.

Reviewed

01 GUIDE

HIPAA Compliance: what usually happens

Who the rules actually reach

HIPAA's rules attach to particular kinds of organizations, most health plans and many health care providers among them, and to the vendors that handle protected health information on their behalf, which the rules call business associates. Plenty of companies that work near health care sit outside it, such as many wellness apps that deal directly with consumers, while others are inside it without realizing. Being outside HIPAA does not mean no privacy law applies, since the Federal Trade Commission and state laws, including New York's, reach health data in other ways. Settling which category you fall into comes first, because the rest of the analysis follows from it. It is also a question worth revisiting whenever the business model changes.

What compliance looks like on paper

When regulators look at a HIPAA matter, they usually ask for documents rather than assurances. A written risk analysis of where electronic health information lives and how it could be exposed sits near the center of that, together with the policies built on it and records showing that staff were trained. Signed agreements with vendors who touch patient data matter as well, and so does a record of how past incidents were looked into. Many organizations have some of these in draft, or in a former employee's folder. Gathering what exists, and noting honestly what does not, is more useful to us than polishing a policy manual before we have seen it.

Setting the scope of the work

A first conversation usually settles why the question is coming up now. A request in a customer contract calls for a different kind of review than a patient complaint or a suspected incident, and the pace differs too. If information may already have been exposed, the conversation shifts toward breach assessment, because notification obligations can run on a clock that starts before every fact is known. If nothing has gone wrong, we can usually focus on the gaps that matter most for how your organization actually handles data. In both situations we tell you what we see in the documents and what we would need in order to say more.

02 ATTORNEYS

Who you would be working with

Attorneys at our New York and Washington, D.C. offices handle matters like this one.

03 CASE RESULTS

Matters we have handled

Prior results do not guarantee a similar outcome.

05 HOW WE WORK

Client-centered service across jurisdictions

Global Coordination & Expertise

We deliver coordinated and effective legal services to our clients, utilizing our extensive legal resources and experienced attorneys in our well-integrated global network. Through our Washington D.C. and New York offices, together with our alliance

Multilingual & Cross-Border Communication

Our attorneys are experienced in both domestic and international matters and, with fluency in various languages, provide clear and consistent communication at every stage of your legal process.

Client-Centered Approach

Client service lies at the heart of our operations. From the initial consultation, we prioritize understanding your situation, listening to your goals, and providing regular updates and strategies tailored to your individual case.

Multidisciplinary & Efficient Solutions

Our multidisciplinary approach and established processes enable us to address cross-border challenges with efficiency.

06 OFFICES

Where we meet clients

Consultations are available in person or remotely.

New York

285 Fulton Street, New York, NY 10007
(855) 529-7557

Washington, D.C.

Suite 985, 1717 K Street NW, Washington, DC 20006
(855) 529-7557

Los Angeles

1901 Avenue of the Stars, Suite 820, Los Angeles, CA 90067
(424) 561-7557

Attorney Advertising. This page is general information about HIPAA compliance and is not legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on the facts of each matter, and prior results do not guarantee a similar outcome. Laws differ by state and change over time.