HIPAA applies to a much wider range of businesses than most people realize. If your business handles protected health information (PHI) in any capacity — either as a covered entity or a business associate — you have legal compliance obligations.
Covered Entities (Directly Regulated by HIPAA)
- Healthcare providers — doctors, dentists, chiropractors, mental health practitioners, pharmacies
- Health plans and insurance companies
- Healthcare clearinghouses
Business Associates (Also Subject to HIPAA)
- IT companies and MSPs that have access to systems containing PHI
- Billing and coding services
- Medical transcription services
- Attorneys and accountants who access PHI in their work
- Cloud storage providers used by covered entities
- Shredding companies handling medical records
The Cost of Non-Compliance
HIPAA violations can carry significant regulatory, legal, operational, and reputational consequences, and penalty structures change over time. Organizations should confirm current requirements and potential exposure with qualified legal and compliance advisers. More importantly, a breach can destroy patient trust that took years to build.
Not sure if your business needs HIPAA compliance? Call GlobalTSS for a free assessment — we'll tell you exactly where you stand and what, if anything, you need to do.