← Back to glossary

What HIPAA requires

HIPAA's Privacy Rule governs the use and disclosure of Protected Health Information. The Security Rule governs the safeguards required to protect electronic PHI: access controls, audit controls, integrity controls, transmission security. The Breach Notification Rule requires notification of certain breaches.

The BAA mechanism

HIPAA-covered entities (health plans, healthcare clearinghouses, most healthcare providers) cannot share PHI with third-party service providers unless a Business Associate Agreement is in place. The BAA establishes the third party's obligations under HIPAA — including the requirement to implement the same Security Rule safeguards.

The "BAA-able" architecture question

For a cloud provider to be BAA-able, the architecture must support HIPAA's safeguards: encryption of PHI at rest and in transit, access controls with audit, integrity verification, breach detection and notification. Most major hyperscalers will sign BAAs for specific service tiers.

SkyeConnex's zero-knowledge architecture exceeds HIPAA's baseline by construction: the storage operator cannot access PHI in any operational mode. This simplifies the BAA negotiation — there's less for the covered entity to worry about because there's less surface where the business associate could fail.

Cross-border health data

HIPAA does not require US residency for PHI, but most healthcare organisations apply additional residency requirements driven by state laws, provider agreements, and risk management. For organisations operating across PIPEDA, PHIPA, and HIPAA simultaneously, SkyeConnex's per-jurisdiction policy makes residency a configuration rather than a contract.

HITECH and OCR enforcement

The HITECH Act (2009) strengthened HIPAA penalties and tied them to corrective-action requirements. The Office for Civil Rights enforces HIPAA aggressively; multi-million-dollar settlements are common. Architectures that prevent breaches by construction reduce both the probability and severity of OCR enforcement exposure.

How SkyeConnex maps

The HIPAA-BAA preset pack pre-configures encryption, audit, breach-detection, and PHI-handling defaults. The BAA-able architecture is documented for covered-entity legal review. See the healthcare industry page →

Related terms

See also

Want to see this in production?