Who the rules actually reach
HIPAA's rules attach to particular kinds of organizations, most health plans and many health care providers among them, and to the vendors that handle protected health information on their behalf, which the rules call business associates. Plenty of companies that work near health care sit outside it, such as many wellness apps that deal directly with consumers, while others are inside it without realizing. Being outside HIPAA does not mean no privacy law applies, since the Federal Trade Commission and state laws, including New York's, reach health data in other ways. Settling which category you fall into comes first, because the rest of the analysis follows from it. It is also a question worth revisiting whenever the business model changes.
What compliance looks like on paper
When regulators look at a HIPAA matter, they usually ask for documents rather than assurances. A written risk analysis of where electronic health information lives and how it could be exposed sits near the center of that, together with the policies built on it and records showing that staff were trained. Signed agreements with vendors who touch patient data matter as well, and so does a record of how past incidents were looked into. Many organizations have some of these in draft, or in a former employee's folder. Gathering what exists, and noting honestly what does not, is more useful to us than polishing a policy manual before we have seen it.
Setting the scope of the work
A first conversation usually settles why the question is coming up now. A request in a customer contract calls for a different kind of review than a patient complaint or a suspected incident, and the pace differs too. If information may already have been exposed, the conversation shifts toward breach assessment, because notification obligations can run on a clock that starts before every fact is known. If nothing has gone wrong, we can usually focus on the gaps that matter most for how your organization actually handles data. In both situations we tell you what we see in the documents and what we would need in order to say more.