Your HIPAA basics

Software or IT vendor

SaaS companies, IT providers, billing services, and anyone whose software touches patient data

This page is for you. 6 articles in your reading path.

Your reading path

Step 1 of 6 — check off articles as you finish (saved in this browser).

  1. 1

    What is HIPAA and why does it apply to my office?

    HIPAA is a federal law protecting patient health information. Here's what it means for your practice in plain English.

  2. 2

    Does HIPAA apply to my software company or service?

    A simple decision guide for vendors wondering if they are in HIPAA's world.

  3. 3

    Do we need to sign anything? Business Associate Agreements explained simply

    A plain-English look at BAAs — the contracts you need with vendors that touch patient information.

  4. 4

    What patient information do we need to protect?

    Understand what counts as protected health information in a real office — not just charts, but conversations, schedules, and more.

  5. 5

    HIPAA for software companies (the short version)

    If your product touches patient data for healthcare customers, here is how to think about BAAs, security, and subprocessors.

  6. 6

    What should I do if I think something went wrong?

    Wrong fax, strange email, lost phone, or coworker snooping — here's how to respond without making it worse.

Your checklist

Items most relevant to your role. Progress syncs with the full checklist.

See full checklist →

Your scenarios

See all scenarios →

Next steps

When you're ready to go deeper, explore intelligence articles and free tools.