AsteronAsteron

    HIPAA readiness for European healthtech

    Asteron helps European healthtech and SaaS companies determine how HIPAA applies to their US healthcare relationships and build the privacy, security, contractual and breach-response controls expected of a business associate. We map protected health information, customer and subcontractor responsibilities, Business Associate Agreements and operating evidence so that HIPAA becomes a working part of the service - not a collection of generic policies.

    View HIPAA pricing
    • HIPAA role and scope assessed
    • PHI and ePHI flows mapped
    • Privacy and security controls implemented
    • Customer assurance evidence prepared

    What is HIPAA?

    The Health Insurance Portability and Accountability Act and its implementing rules establish US requirements for certain health information handled by covered entities and their business associates.

    For a technology company, the most relevant components are usually:

    • The Privacy Rule, governing permitted uses and disclosures of protected health information and individual rights.
    • The Security Rule, requiring administrative, physical and technical safeguards for electronic protected health information.
    • The Breach Notification Rule, establishing responsibilities after a breach of unsecured protected health information.
    • Relevant Enforcement Rule obligations and direct liability for particular business-associate requirements.

    HIPAA is not a general security framework for every company processing health-related data. Applicability depends on who the customer is, what service is performed and whether the company creates, receives, maintains or transmits PHI on behalf of a regulated organisation.

    Does HIPAA apply to your company?

    US health plan, clearinghouse or qualifying healthcare provider
    May be a HIPAA covered entity
    SaaS company processing PHI for a covered entity
    Usually acts as a business associate
    Subcontractor handling PHI for another business associate
    May be a business-associate subcontractor with direct obligations
    Software vendor selling a product without access to customer PHI
    The sale alone does not create business-associate status
    Cloud provider maintaining ePHI for a regulated customer
    May be a business associate even when the data is encrypted and it does not hold the decryption key
    Consumer health application operating outside a covered-entity relationship
    May fall outside HIPAA but remain subject to FTC, state privacy and other laws

    Being incorporated or hosting infrastructure in Europe does not automatically remove HIPAA obligations. A European company can become part of the HIPAA business-associate chain through the services it performs for a US regulated customer.

    Health data is not always PHI

    HIPAA protects individually identifiable health information when it is created, received, maintained or transmitted by a covered entity or its business associate in the relevant context.

    The same information may not be PHI when held by an unrelated consumer application, employer or another organisation outside the HIPAA-regulated relationship. That does not mean it is unregulated: GDPR, the FTC Health Breach Notification Rule and US state laws may still apply.

    The readiness assessment must therefore identify:

    • The source and context of the information
    • The customer’s HIPAA status
    • The company’s contracted function
    • Whether the information is PHI or ePHI
    • Which systems and suppliers create, receive, maintain or transmit it
    • Where HIPAA scope ends and other privacy regimes continue

    Covered entity, business associate and subcontractor

    Covered entity

    A qualifying health plan, healthcare clearinghouse or healthcare provider conducting covered electronic transactions. It remains responsible for its own HIPAA programme and for obtaining appropriate assurances from business associates.

    Business associate

    A person or organisation performing functions or services for a covered entity that involve PHI. Business associates have contractual duties and direct liability for specific HIPAA requirements.

    Business-associate subcontractor

    A subcontractor that handles PHI on behalf of a business associate. Required restrictions and safeguards must flow down through the provider chain rather than stopping at the first vendor.

    What HIPAA readiness requires

    Privacy and permitted use

    The company must understand why it receives PHI, which uses and disclosures are permitted, how the minimum-necessary principle is applied and how it supports customer obligations concerning access, amendment and accounting.

    Security risk management

    A documented risk analysis must identify where ePHI is created, received, maintained and transmitted, along with relevant threats, vulnerabilities, current controls and residual risk. Risk analysis is the foundation for selecting reasonable and appropriate safeguards.

    Administrative safeguards

    Named security responsibility, workforce access, training, incident procedures, contingency planning, evaluation, supplier management and documented risk decisions must operate in practice.

    Physical safeguards

    Facilities, workstations, devices, remote-working environments and media containing ePHI require appropriate access, use, disposal and reuse controls.

    Technical safeguards

    Access control, authentication, audit controls, integrity protection and transmission security must reflect the identified risks and the organisation’s architecture.

    An “addressable” implementation specification is not automatically optional. The organisation must implement it when reasonable and appropriate, or document why an equivalent measure or alternative decision is appropriate.

    Business Associate Agreements

    A Business Associate Agreement is more than a sales appendix. It defines how PHI may be used and disclosed and establishes obligations relating to safeguards, incidents, subcontractors, individual rights, HHS access and return or destruction of information.

    Before signing, the company should confirm that it can operationally meet the proposed terms. Common problems include:

    • Reporting deadlines that do not match the incident process
    • Promises that are not reflected in cloud and subcontractor agreements
    • Unclear responsibility for individual-rights requests
    • Inconsistent data-retention and deletion commitments
    • Overly broad permitted uses of PHI
    • Missing flow-down obligations

    Asteron can map contractual requirements to operational controls. Formal US legal advice and BAA negotiation remain separate unless explicitly scoped.

    Breach and incident readiness

    A security incident is not automatically a reportable HIPAA breach, but the organisation needs a documented process to investigate, preserve facts, assess impermissible uses or disclosures and meet contractual and regulatory timelines.

    Business associates must notify the affected covered entity of relevant breaches. Covered entities may then need to notify affected individuals, HHS and, for certain large breaches, the media.

    The workflow should establish:

    • Immediate internal escalation
    • Decision authority and legal involvement
    • Evidence preservation and containment
    • Assessment of the information and individuals affected
    • Business-associate and subcontractor notifications
    • Customer-specific deadlines
    • Documentation of the final determination

    HIPAA, GDPR, ISO 27001 and SOC 2

    HIPAA
    US sector-specific privacy, security and breach duties for covered entities and business associates
    GDPR
    Broad European regulation governing personal-data processing based on controller and processor roles
    ISO 27001
    Certifiable information-security management system that can provide reusable governance and controls
    SOC 2
    Independent CPA assurance report frequently requested by US enterprise customers

    GDPR compliance does not automatically establish HIPAA readiness. The frameworks differ in scope, terminology, contractual roles, individual rights and breach processes.

    ISO 27001 or SOC 2 can reduce duplicated security work, but HIPAA applicability, PHI use, Business Associate Agreements and HIPAA-specific procedures still need to be addressed.

    Proposed Security Rule changes

    HHS proposed substantial updates to the HIPAA Security Rule in December 2024. As of July 2026, the proposal has not replaced the existing rule, and HHS states that the current Security Rule remains in effect.

    The organisation should comply with current requirements while monitoring the rulemaking and avoiding control designs that would be difficult to strengthen. Proposed requirements are not presented here as current law.

    How Asteron delivers the project

    1. Role and applicability assessment

      Determine covered-entity, business-associate and subcontractor relationships and confirm where HIPAA applies to the company.

    2. PHI and system scope

      Map protected health information, systems, locations, users and providers that create, receive, maintain or transmit PHI.

    3. Risk and requirement assessment

      Evaluate current safeguards, contracts and operating evidence against the Privacy, Security and Breach Notification Rules.

    4. Control implementation

      Establish proportionate privacy, security and supplier controls that the organisation can operate and defend during customer reviews.

    5. Incident and BAA alignment

      Connect contractual promises to breach and operational workflows so obligations, timelines and notifications are consistent.

    6. Readiness validation

      Test representative controls, review evidence and prepare the customer-assurance pack for US healthcare buyers.

    Deliverables

    Scope and governance

    • HIPAA role and applicability assessment
    • PHI and ePHI data-flow map
    • System and supplier scope
    • HIPAA risk analysis
    • Responsibility and subcontractor matrix
    • Prioritised remediation roadmap

    Operational readiness

    • Privacy and Security Rule control map
    • Policy and procedure set
    • BAA operational-requirement review
    • Incident and breach-response workflow
    • Training and control-owner guidance
    • Customer assurance and readiness pack

    HIPAA readiness pricing

    Scoped readiness project
    From €9,900

    Covers US health-data operational readiness for one principal organisation, one defined service and an agreed covered-entity or business-associate scope.

    Final pricing depends on the number of products, US customer relationships, PHI flows, subcontractors, locations, existing control maturity and contractual complexity.

    HIPAA does not have an official certification audit or certificate.

    Typical milestones
    • 40% at signing
    • 40% after delivery of the scope and risk baseline
    • 20% after the contracted readiness deliverables

    Prices exclude VAT where applicable.

    Asteron guarantees completion and correction of its agreed deliverables within the contracted scope. It cannot provide a legal guarantee of compliance or of control decisions made by HHS, customers, courts or other authorities.
    View full pricing

    What remains separate

    • Formal US legal opinions
    • Negotiation or execution of Business Associate Agreements
    • Technical remediation and product development
    • Penetration testing
    • State-law and FTC assessments outside the agreed scope
    • Representation before HHS or other authorities
    • Customer-specific audits and onsite assessments
    • Work for additional products or legal entities

    No third party can issue an official HIPAA compliance certificate. Optional assessments or badges must not be presented as HHS approval.

    Responsibilities

    Asteron

    • Assess the proposed HIPAA role and scope
    • Map requirements into practical controls
    • Prepare risk, supplier and incident documentation
    • Review operating evidence
    • Support customer-assurance readiness

    Your organisation

    • Confirm customer relationships, PHI uses and data flows
    • Approve risks, policies and permitted uses
    • Implement and operate controls
    • Manage workforce and subcontractors
    • Obtain appropriate legal advice
    • Make breach and regulatory decisions

    Frequently asked questions

    Does HIPAA apply to European companies?

    HIPAA can apply to a European company when it creates, receives, maintains or transmits protected health information on behalf of a US covered entity or another business associate. Being incorporated or hosted in Europe does not automatically remove HIPAA obligations; the relevant test is the service relationship and the information handled.

    What is a HIPAA business associate?

    A business associate is a person or organisation performing functions or services for a covered entity that involve protected health information. Business associates have contractual duties through a Business Associate Agreement and direct liability under HIPAA for specific requirements including certain Security Rule and Breach Notification obligations.

    Is every software vendor a business associate?

    No. Selling software to a covered entity does not by itself create business-associate status. The status arises when the vendor creates, receives, maintains or transmits PHI on behalf of the covered entity. A pure off-the-shelf software sale without access to customer PHI generally does not make the vendor a business associate.

    Is all health data considered PHI?

    No. HIPAA protects individually identifiable health information created, received, maintained or transmitted in the context of a covered-entity or business-associate relationship. The same information held by an unrelated consumer app, employer or other organisation may not be PHI, though GDPR, the FTC Health Breach Notification Rule and US state laws may still apply.

    Does a cloud provider need a BAA?

    Yes. HHS has confirmed that a cloud service provider maintaining ePHI for a regulated customer is a business associate and requires a Business Associate Agreement. This applies even when the data is encrypted and the provider does not hold the decryption key.

    Is HIPAA certification available?

    No. HHS does not endorse, recognise or issue HIPAA certifications. Optional third-party assessments, attestations or badges can support customer conversations but must not be presented as official HIPAA certification or HHS approval.

    Is GDPR compliance enough for HIPAA?

    No. GDPR compliance does not automatically establish HIPAA readiness. The frameworks differ in scope, terminology, controller and processor roles, individual rights, contractual obligations and breach processes. HIPAA-specific requirements need to be addressed separately.

    Does ISO 27001 or SOC 2 replace HIPAA?

    No. ISO 27001 and SOC 2 can reduce duplicated security work and support customer assurance, but neither replaces HIPAA. Applicability, permitted uses of PHI, Business Associate Agreements, breach procedures and other HIPAA-specific obligations still need to be established.

    What is required in a HIPAA risk analysis?

    The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic PHI that the organisation creates, receives, maintains or transmits. It should identify ePHI locations, threats, current controls, likelihood, impact and residual risk, and inform the selection of reasonable and appropriate safeguards.

    What happens after a breach?

    A security incident is not automatically a reportable breach. The organisation must investigate, preserve facts and assess whether an impermissible use or disclosure of unsecured PHI occurred. Business associates must notify the affected covered entity within contractual and regulatory timelines; covered entities may then need to notify individuals, HHS and, for certain large breaches, the media.

    Are the proposed Security Rule changes already effective?

    No. HHS proposed substantial updates to the HIPAA Security Rule in December 2024. As of July 2026, the proposal has not replaced the existing rule and HHS states that the current Security Rule remains in effect. Organisations should comply with current requirements while monitoring the rulemaking.

    How much does HIPAA readiness cost?

    A scoped HIPAA readiness engagement starts from €9,900. Final pricing depends on the number of products, US customer relationships, PHI flows, subcontractors, locations, existing control maturity and contractual complexity. HIPAA does not have an official certification audit or certificate; prices exclude VAT where applicable.

    Official references

    • – HHS — Covered entities and business associates
    • – HHS — HIPAA Privacy Rule
    • – HHS — HIPAA Security Rule
    • – HHS — Breach Notification Rule
    • – HHS — Business Associate Agreements guidance
    • – HHS — HIPAA Security Rule Notice of Proposed Rulemaking (December 2024)

    Last reviewed: July 2026

    Asteron is not a law firm. HIPAA does not have an official certification audit or certificate and HHS does not endorse third-party HIPAA certifications.

    Prepare for US healthcare customers without false assurances

    Determine how HIPAA applies, understand where PHI moves and establish controls that your team can operate and defend during customer reviews and incidents.

    View pricing