HIPAA readiness for European healthtech
Asteron helps European healthtech and SaaS companies determine how HIPAA applies to their US healthcare relationships and build the privacy, security, contractual and breach-response controls expected of a business associate. We map protected health information, customer and subcontractor responsibilities, Business Associate Agreements and operating evidence so that HIPAA becomes a working part of the service - not a collection of generic policies.
- HIPAA role and scope assessed
- PHI and ePHI flows mapped
- Privacy and security controls implemented
- Customer assurance evidence prepared
What is HIPAA?
The Health Insurance Portability and Accountability Act and its implementing rules establish US requirements for certain health information handled by covered entities and their business associates.
For a technology company, the most relevant components are usually:
- – The Privacy Rule, governing permitted uses and disclosures of protected health information and individual rights.
- – The Security Rule, requiring administrative, physical and technical safeguards for electronic protected health information.
- – The Breach Notification Rule, establishing responsibilities after a breach of unsecured protected health information.
- – Relevant Enforcement Rule obligations and direct liability for particular business-associate requirements.
HIPAA is not a general security framework for every company processing health-related data. Applicability depends on who the customer is, what service is performed and whether the company creates, receives, maintains or transmits PHI on behalf of a regulated organisation.
Does HIPAA apply to your company?
Being incorporated or hosting infrastructure in Europe does not automatically remove HIPAA obligations. A European company can become part of the HIPAA business-associate chain through the services it performs for a US regulated customer.
Health data is not always PHI
HIPAA protects individually identifiable health information when it is created, received, maintained or transmitted by a covered entity or its business associate in the relevant context.
The same information may not be PHI when held by an unrelated consumer application, employer or another organisation outside the HIPAA-regulated relationship. That does not mean it is unregulated: GDPR, the FTC Health Breach Notification Rule and US state laws may still apply.
The readiness assessment must therefore identify:
- – The source and context of the information
- – The customer’s HIPAA status
- – The company’s contracted function
- – Whether the information is PHI or ePHI
- – Which systems and suppliers create, receive, maintain or transmit it
- – Where HIPAA scope ends and other privacy regimes continue
Covered entity, business associate and subcontractor
Covered entity
A qualifying health plan, healthcare clearinghouse or healthcare provider conducting covered electronic transactions. It remains responsible for its own HIPAA programme and for obtaining appropriate assurances from business associates.
Business associate
A person or organisation performing functions or services for a covered entity that involve PHI. Business associates have contractual duties and direct liability for specific HIPAA requirements.
Business-associate subcontractor
A subcontractor that handles PHI on behalf of a business associate. Required restrictions and safeguards must flow down through the provider chain rather than stopping at the first vendor.
What HIPAA readiness requires
Privacy and permitted use
The company must understand why it receives PHI, which uses and disclosures are permitted, how the minimum-necessary principle is applied and how it supports customer obligations concerning access, amendment and accounting.
Security risk management
A documented risk analysis must identify where ePHI is created, received, maintained and transmitted, along with relevant threats, vulnerabilities, current controls and residual risk. Risk analysis is the foundation for selecting reasonable and appropriate safeguards.
Administrative safeguards
Named security responsibility, workforce access, training, incident procedures, contingency planning, evaluation, supplier management and documented risk decisions must operate in practice.
Physical safeguards
Facilities, workstations, devices, remote-working environments and media containing ePHI require appropriate access, use, disposal and reuse controls.
Technical safeguards
Access control, authentication, audit controls, integrity protection and transmission security must reflect the identified risks and the organisation’s architecture.
Business Associate Agreements
A Business Associate Agreement is more than a sales appendix. It defines how PHI may be used and disclosed and establishes obligations relating to safeguards, incidents, subcontractors, individual rights, HHS access and return or destruction of information.
Before signing, the company should confirm that it can operationally meet the proposed terms. Common problems include:
- – Reporting deadlines that do not match the incident process
- – Promises that are not reflected in cloud and subcontractor agreements
- – Unclear responsibility for individual-rights requests
- – Inconsistent data-retention and deletion commitments
- – Overly broad permitted uses of PHI
- – Missing flow-down obligations
Asteron can map contractual requirements to operational controls. Formal US legal advice and BAA negotiation remain separate unless explicitly scoped.
Breach and incident readiness
A security incident is not automatically a reportable HIPAA breach, but the organisation needs a documented process to investigate, preserve facts, assess impermissible uses or disclosures and meet contractual and regulatory timelines.
Business associates must notify the affected covered entity of relevant breaches. Covered entities may then need to notify affected individuals, HHS and, for certain large breaches, the media.
The workflow should establish:
- – Immediate internal escalation
- – Decision authority and legal involvement
- – Evidence preservation and containment
- – Assessment of the information and individuals affected
- – Business-associate and subcontractor notifications
- – Customer-specific deadlines
- – Documentation of the final determination
HIPAA, GDPR, ISO 27001 and SOC 2
GDPR compliance does not automatically establish HIPAA readiness. The frameworks differ in scope, terminology, contractual roles, individual rights and breach processes.
ISO 27001 or SOC 2 can reduce duplicated security work, but HIPAA applicability, PHI use, Business Associate Agreements and HIPAA-specific procedures still need to be addressed.
Proposed Security Rule changes
The organisation should comply with current requirements while monitoring the rulemaking and avoiding control designs that would be difficult to strengthen. Proposed requirements are not presented here as current law.
How Asteron delivers the project
Role and applicability assessment
Determine covered-entity, business-associate and subcontractor relationships and confirm where HIPAA applies to the company.
PHI and system scope
Map protected health information, systems, locations, users and providers that create, receive, maintain or transmit PHI.
Risk and requirement assessment
Evaluate current safeguards, contracts and operating evidence against the Privacy, Security and Breach Notification Rules.
Control implementation
Establish proportionate privacy, security and supplier controls that the organisation can operate and defend during customer reviews.
Incident and BAA alignment
Connect contractual promises to breach and operational workflows so obligations, timelines and notifications are consistent.
Readiness validation
Test representative controls, review evidence and prepare the customer-assurance pack for US healthcare buyers.
Deliverables
Scope and governance
- – HIPAA role and applicability assessment
- – PHI and ePHI data-flow map
- – System and supplier scope
- – HIPAA risk analysis
- – Responsibility and subcontractor matrix
- – Prioritised remediation roadmap
Operational readiness
- – Privacy and Security Rule control map
- – Policy and procedure set
- – BAA operational-requirement review
- – Incident and breach-response workflow
- – Training and control-owner guidance
- – Customer assurance and readiness pack
HIPAA readiness pricing
Covers US health-data operational readiness for one principal organisation, one defined service and an agreed covered-entity or business-associate scope.
Final pricing depends on the number of products, US customer relationships, PHI flows, subcontractors, locations, existing control maturity and contractual complexity.
HIPAA does not have an official certification audit or certificate.
- – 40% at signing
- – 40% after delivery of the scope and risk baseline
- – 20% after the contracted readiness deliverables
Prices exclude VAT where applicable.
What remains separate
- – Formal US legal opinions
- – Negotiation or execution of Business Associate Agreements
- – Technical remediation and product development
- – Penetration testing
- – State-law and FTC assessments outside the agreed scope
- – Representation before HHS or other authorities
- – Customer-specific audits and onsite assessments
- – Work for additional products or legal entities
No third party can issue an official HIPAA compliance certificate. Optional assessments or badges must not be presented as HHS approval.
Responsibilities
Asteron
- – Assess the proposed HIPAA role and scope
- – Map requirements into practical controls
- – Prepare risk, supplier and incident documentation
- – Review operating evidence
- – Support customer-assurance readiness
Your organisation
- – Confirm customer relationships, PHI uses and data flows
- – Approve risks, policies and permitted uses
- – Implement and operate controls
- – Manage workforce and subcontractors
- – Obtain appropriate legal advice
- – Make breach and regulatory decisions
Frequently asked questions
Does HIPAA apply to European companies?
HIPAA can apply to a European company when it creates, receives, maintains or transmits protected health information on behalf of a US covered entity or another business associate. Being incorporated or hosted in Europe does not automatically remove HIPAA obligations; the relevant test is the service relationship and the information handled.
What is a HIPAA business associate?
A business associate is a person or organisation performing functions or services for a covered entity that involve protected health information. Business associates have contractual duties through a Business Associate Agreement and direct liability under HIPAA for specific requirements including certain Security Rule and Breach Notification obligations.
Is every software vendor a business associate?
No. Selling software to a covered entity does not by itself create business-associate status. The status arises when the vendor creates, receives, maintains or transmits PHI on behalf of the covered entity. A pure off-the-shelf software sale without access to customer PHI generally does not make the vendor a business associate.
Is all health data considered PHI?
No. HIPAA protects individually identifiable health information created, received, maintained or transmitted in the context of a covered-entity or business-associate relationship. The same information held by an unrelated consumer app, employer or other organisation may not be PHI, though GDPR, the FTC Health Breach Notification Rule and US state laws may still apply.
Does a cloud provider need a BAA?
Yes. HHS has confirmed that a cloud service provider maintaining ePHI for a regulated customer is a business associate and requires a Business Associate Agreement. This applies even when the data is encrypted and the provider does not hold the decryption key.
Is HIPAA certification available?
No. HHS does not endorse, recognise or issue HIPAA certifications. Optional third-party assessments, attestations or badges can support customer conversations but must not be presented as official HIPAA certification or HHS approval.
Is GDPR compliance enough for HIPAA?
No. GDPR compliance does not automatically establish HIPAA readiness. The frameworks differ in scope, terminology, controller and processor roles, individual rights, contractual obligations and breach processes. HIPAA-specific requirements need to be addressed separately.
Does ISO 27001 or SOC 2 replace HIPAA?
No. ISO 27001 and SOC 2 can reduce duplicated security work and support customer assurance, but neither replaces HIPAA. Applicability, permitted uses of PHI, Business Associate Agreements, breach procedures and other HIPAA-specific obligations still need to be established.
What is required in a HIPAA risk analysis?
The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic PHI that the organisation creates, receives, maintains or transmits. It should identify ePHI locations, threats, current controls, likelihood, impact and residual risk, and inform the selection of reasonable and appropriate safeguards.
What happens after a breach?
A security incident is not automatically a reportable breach. The organisation must investigate, preserve facts and assess whether an impermissible use or disclosure of unsecured PHI occurred. Business associates must notify the affected covered entity within contractual and regulatory timelines; covered entities may then need to notify individuals, HHS and, for certain large breaches, the media.
Are the proposed Security Rule changes already effective?
No. HHS proposed substantial updates to the HIPAA Security Rule in December 2024. As of July 2026, the proposal has not replaced the existing rule and HHS states that the current Security Rule remains in effect. Organisations should comply with current requirements while monitoring the rulemaking.
How much does HIPAA readiness cost?
A scoped HIPAA readiness engagement starts from €9,900. Final pricing depends on the number of products, US customer relationships, PHI flows, subcontractors, locations, existing control maturity and contractual complexity. HIPAA does not have an official certification audit or certificate; prices exclude VAT where applicable.
Official references
- – HHS — Covered entities and business associates
- – HHS — HIPAA Privacy Rule
- – HHS — HIPAA Security Rule
- – HHS — Breach Notification Rule
- – HHS — Business Associate Agreements guidance
- – HHS — HIPAA Security Rule Notice of Proposed Rulemaking (December 2024)
Last reviewed: July 2026
Asteron is not a law firm. HIPAA does not have an official certification audit or certificate and HHS does not endorse third-party HIPAA certifications.
Prepare for US healthcare customers without false assurances
Determine how HIPAA applies, understand where PHI moves and establish controls that your team can operate and defend during customer reviews and incidents.
