News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data Breach
Beginnervendor

HIPAA for software companies (the short version)

If your product touches patient data for healthcare customers, here is how to think about BAAs, security, and subprocessors.

TL;DR

Map where PHI lives in your stack, sign BAAs where required, log access, encrypt data in transit and at rest, and contractually pass duties to subprocessors.

Updated 2026-04-21

Product-led teams often discover HIPAA mid-sale when a hospital asks for a BAA. Use this page as a conversation starter with engineering and legal, not a substitute for counsel.

Know your data map

List every database, log store, support tool, and analytics pipeline that could hold identifiers + health context. If you cannot draw it on a whiteboard, you are not ready to sign attestations.

Security basics customers expect

  • Unique accounts and role-based access for your staff.
  • Encryption for data at rest and in transit for PHI systems.
  • Audit logs that prove who touched what.
  • Backups that are encrypted and tested.
  • Incident response runbooks with customer notification timelines from your BAA.

Subprocessors

If AWS, GCP, email, or ticketing vendors touch PHI, they need appropriate agreements and risk review. Customers will ask for your list.

Go deeper

Pair this Basics page with HIPAA for SaaS companies for a longer operational read.

Not legal advice. Educational overview only; consult qualified counsel for your situation.