Skip to content
Find my data room
Data room terms / Security and compliance

HIPAA

The short version

The 1996 US federal law, with its Privacy and Security Rules, covering patient records held by health plans, providers and their vendors. A room that stores such records needs a business associate agreement in place.

How it plays out on a deal

Health care deals, clinical trial partnerships and some insurance transactions put patient data in the room, sometimes only by accident inside a spreadsheet. If that data is protected health information, the room provider handles it as a business associate.

There is no official HIPAA certification. What a buyer needs is a signed business associate agreement and evidence of the relevant safeguards. Many sellers also prefer to redact or remove patient-level data before upload, which reduces the problem at the source.

What to check in a review or demo

  1. 1Whether the vendor will sign a business associate agreement, and on which plans.
  2. 2Which safeguards the vendor documents for health data, such as access logging and encryption.
  3. 3Whether redaction tools can remove patient identifiers before documents are shared.

HIPAA: where the reviewed providers stand

Based on the certifications and attestations each provider lists publicly, as recorded in our review data. Ask for the current report or certificate and check its scope before relying on it.

Read alongside

Where this comes up on Data Room Review