The healthcare industry is primed to benefit mightily from the ever-expanding influx of medical apps, transforming areas such as personal fitness, information storage, and even complex medical procedures. However, many app developers fail to realize the the role of the Health Insurance Portability And Accountability Act (HIPAA) and the full extent of HIPAA’s applicability to their activities. This article aims to provide app developers with information on how to develop a HIPAA compliant app and related products.
If your app transmits personal information covered by HIPAA, failure to follow HIPAA requirements can be costly. HIPAA violations can result in civil damages up to $50,000 and criminal fines up to $250,000 and imprisonment.
HIPAA compliance for mobile applications hinges on two consideration:
HIPAA was created to protect individual privacy by regulating the dissemination of personal health information (PHI). PHI includes any individually identifiable information concerning health, health care, and payment for said care. For more information on the history of HIPAA and the legal definition of PHI, see Part 1 of this series.
Not all health-related apps need to be HIPAA compliant.
Only usage involving PHI must abide by HIPAA’s Privacy Rule and other requirements.
If your app allows users to collect information on their physical fitness, follow a medical regimen, or receive depersonalized medical data from a health care provider, you do not need to maintain compliance. On the other hand, if, for example, your app allows physicians to share information on specific medical procedures with one another or to follow up with their patients regarding individual treatment, you’ll need to design for compliance.
HIPAA’s Privacy Rule (insert link) places restrictions on the collection, storage, and sharing of PHI by “covered entities” such as plans and health providers that transmit PHI via electronic transaction, as well as “business associates” that handle PHI on a covered entity’s behalf. Under HIPAA’s Privacy Rule, mobile healthcare applications that collect, store, or share PHI with covered entities must comply with HIPAA provisions. If your app’s client base includes covered entities or business associates, you may need to design for HIPAA compliance.
The prevalence of smartphones, tablets, and other mobile devices pose unique challenges for mobile applications tasked with protecting PHI. Some of the difficulties associated with wearable and mobile technology include:
If you’ve reviewed the above information and determined that you’ll need to build HIPAA compatibility into your app, you can achieve compliance by following these steps.
1. Think through possible user activity and analyze your clients’ business needs so you can identify potential trouble spots. It is always better to err on the side of compliance, even at the price of a lengthy and convoluted design process.
2. Design appropriate administrative, physical, and technical security measures to protect PHI. To accomplish this, incorporate the following best practices into your app design to develop a HIPAA compliant app:
3. Draft a carefully thought-out privacy policy that discusses how you will collect, store, and share PHI.
4. Perform regular privacy audits to ensure your administrative, physical, and technical security measures are functioning properly.
DISCLAIMER: The information in this article is provided for informational purposes only and should not be construed or relied upon as legal advice. This article may constitute attorney advertising under applicable state laws.