HIPAA for Health Tech: The New Sales Reality

With decades of experience advising healthcare organizations and health technology companies on Certified EHR Technology standards, HIPAA compliance, risk assessments, and regulatory strategy,…

Read More

Jim Hook, MPH

By Jim Hook, MPH | June 10, 2026

Healthcare technology and HIPAA compliance concept image featuring digital circuitry, data networks, and medical and security icons representing health tech systems, data protection, and regulatory compliance.

With decades of experience advising healthcare organizations and health technology companies on Certified EHR Technology standards, HIPAA compliance, risk assessments, and regulatory strategy, we’ve seen firsthand how quickly innovation can outpace governance. As AI-driven solutions accelerate across the healthcare landscape, organizations are entering a more complex regulatory environment, one that directly impacts how products are developed, sold, and implemented.

Executive Summary – Key Takeaways

  • AI adoption is accelerating faster than governance.
  • Many Health Tech companies will become HIPAA-regulated business associates.
  • Compliance readiness is increasingly required to win healthcare business.
  • HIPAA violations, OCR investigations, and security incidents create significant risk.

Entering the Healthcare Market Means Entering a HIPAA-Regulated Environment

There is little doubt we are on the cusp of a brave new world in health tech applications. Artificial intelligence in healthcare delivery is one such example.

Some people see virtually unlimited horizons for adapting AI to tasks that are repetitive (i.e., boring) but costly. Others see AI as dehumanizing what used to be interpersonal interactions, sacrificed to increasing efficiency and saving money. In any case, the headlong rush into AI implementation is coming to dominate discussions in and among healthcare organizations and systems, and among healthtech companies developing and selling applications.

One thing most other sectors of the economy don’t have is HIPAA, the Health Insurance Portability and Accountability Act. After 23 years, HIPAA compliance has become second nature to covered entities (now referred to as “regulated entities“) in the healthcare sector.

Healthtech companies come from the tradition of “move fast and break things”. Now they are entering an arena where they too, are going to be regulated entities, depending on the nature of their offerings. Both parties have a lot to learn as they sally forth into this brave new world.

A Snapshot in Time

So what is the state of play in health tech AI development? What is the state of play in the adoption of AI-supported applications by healthcare covered entities such as health plans and health care providers? On the part of health systems, a survey by the Healthcare Financial Management Association in 2025 showed upwards of 88% of health systems are using AI in some form. But only 18% claim to have a mature governance structure and fully formed AI strategy.

On the health tech side, there are an estimated 1,300 to 1,700 US companies engaged in developing products. These products qualify them as business associates when they are utilized by HIPAA-covered entities.

So healthtech companies have to learn the language of the HIPAA Security Rule. They also have to understand how to be in compliance with it. And healthcare providers have to make sure they ask the right questions of health tech developers when considering implementing an AI application.

What are the HIPAA Rules?

There are three distinct federal Rules (regulations) related to HIPAA: the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. 

The HIPAA Privacy Rule

The HIPAA Privacy Rule covers protected health information or PHI, created or maintained by HIPAA-covered entities. Those include health plans/health insurance companies, healthcare providers, and healthcare clearinghouses.

The HIPAA Security Rule

The HIPAA Security Rule covers electronic protected health information or ePHI, created, transmitted, maintained, or stored in electronic form by HIPAA covered entities, including Business Associates.

The HIPAA Breach Notification Rule

The HIPAA Breach Notification Rule covers the notifications necessary when unauthorized disclosures of PHI or ePHI have occurred, or when data becomes unsecured PHI. 

What HIPAA Rules are HealthTech Companies Exposed To?

Healthtech companies are mostly going to be covered by the HIPAA Security Rule and the Breach Notification Rule. Naturally, the Security Rule is the most extensive of the HIPAA rules.

HIPAA Security Rule structure diagram showing a central “HIPAA Security Rule” box branching into three equal components: Administrative Safeguards, Physical Safeguards, and Technical Safeguards.

The HIPAA Security Rule is organized into three main sections.

Technical Safeguards

The Technical Safeguards cover the “technology and policies and procedures for its use that protect electronic protected health information and control access to it.” The technical safeguards address security measures such as access control, audit controls, integrity controls, transmission security, and person or entity authentication.

Physical Safeguards

The Physical Safeguards “are physical measures, policies, and procedures to protect a covered entity’s electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.” Physical safeguards address Facility Access Controls, Workstation Use, Workstation Security, and Device and Media Controls.

Administrative Safeguards

The HIPAA Administrative Safeguards outline the management activities covered entities should undertake to successfully manage the security of ePHI under their control. They include activities such as the requirement to conduct risk assessments and business associate agreements. They also include sanction policies and procedures, information activity review, workforce security, security awareness training for workforce members, and how to address security incidents, among others.

Mandatory vs. Addressable Standards

Current HIPAA Security Rule requirements are divided into mandatory and addressable standards and implementation specifications. Addressable does not mean optional; it means covered entities can utilize another method to comply with the standard. But stay tuned because a proposed update to the Privacy and Security Rules will make all standards and specifications mandatory.

Health Tech Sector Recent Growth

The growth of the U.S. digital health market increased substantially in 2025 compared to 2023 and 2024. Digital health startups raised $14.2 billion in 2025 compared to $10.1 billion and $10.9 billion in 2024 and 2023, respectively. The top three types of applications funded included non-clinical workflows, clinical workflows, and data infrastructure. And this is still just a small part of the estimated $197b in total software market size in 2025. But the market for health tech is just beginning.

From a compliance and go-to-market perspective, the health tech market can be segmented based on how products interact with PHI and HIPAA requirements.

Health Tech Market Segments

The Health Tech vendor/developer market can be divided into three market segments based on their exposure to PHI/ePHI.

Likely Subject to HIPAA

Boxes recommending health tech market segments as they relate to exposure to PHI. They include, subject to HIPAA, HIPAA adjacent, not HIPAA driven.

These are systems or applications that come into contact with PHI when they are used by HIPAA-covered entities. Healthtech companies will be considered business associates of healthcare providers, health plans/insurance companies, and healthcare clearinghouses.

Examples of the types of services/capabilities provided include ambient documentation, coding/CDI, and claims processing and prior authorizations automation. Other services include remote monitoring platforms and care management platforms. And of course, enterprise-wide applications such as OpenAI’s ChatGPT for Healthcare and Anthropic’s Healthcare Enterprise AI are definitely business associates of the healthcare providers who implement them. This segment accounted for about two-thirds of the market investment in digital health tech.

Note: You don’t have to have signed a business associate agreement to be considered a business associate. If you receive, maintain, or transmit ePHI from or to a covered entity, you are a business associate regardless of whether or not you actually sign a business associate agreement.

Likely Adjacent to HIPAA but Commercially Compliance-Sensitive

These are healthtech companies whose offerings may not be required to be HIPAA compliant. But buyers may still demand privacy/security maturity, diligence support, and contracting readiness. This segment accounted for about 20% of the market investment in digital health tech.

Examples include: some employer health navigation tools, some pharmacy benefits or alternative health benefits platforms, certain device software vendors, or analytics or AI vendors selling into healthcare workflows not part of services by covered entities.

Likely Not Driven by HIPAA

These include general wellness, consumer fitness, lifestyle nutrition, longevity, and wearable products and direct-to-consumer tools with weak or non-existent covered entity integration. This segment accounted for about 13% of the market investment in digital health tech.

What are the penalties for HIPAA Violations?

HIPAA violations are no joke, and the penalties for violations are not a joke, either. For some healthtech companies, this may be the first time they have encountered an environment where regulations that come with civil and criminal penalties apply to the products they are developing and furnishing. HIPAA regulations also require them to report themselves when they fail to protect PHI. And hacking/IT issues are the most common types of HIPAA breaches, affecting literally hundreds of millions of people in the U. S. annually.

In recent years, federal law has provided for annual updates to fines and penalties assessed by federal agencies. Civil penalties for HIPAA violations apply to instances of unauthorized disclosure of PHI where the covered entity/business associate was unaware of the breach and could not have avoided this violation with reasonable care. The penalty in this case starts at $145.

For violations where the disclosures were due to willful neglect and the covered entity/business associate did not correct a flagged issue, the civil penalty can be up to $2.19 million!

And there are criminal penalties, too! Selling or transferring PHI for commercial or personal gain, or to do so with malicious intent, can result in up to 10 years in jail and a fine of $250,000.

Where Do We Go from Here?

The most amazing statistic in this piece is the finding that while 88% of health systems have incorporated some form of AI into their clinical and/or non-clinical systems, only 18% have mature governance.

Healthcare providers are already installing applications, finding they are not working well, and moving on to alternates. But this is an ad-hoc approach; for one of our clients, it was a response to an unhappy experience by physicians and other users. The client was much happier with the new application, but there was still no organized governance approach to new systems.

If your healthcare provider is in a similar state, one place to start is to learn about guidance on governance put out by the Joint Commission.

There are no statistics on HIPAA compliance among healthtech companies, but it would be surprising if many of them have grappled thoroughly with how the HIPAA rules affect their products and their products’ users.

In almost 20 years of HIPAA compliance consulting, we have performed HIPAA Risk Assessments and provided HIPAA Privacy and Security policies and procedures for a handful of non-provider entities. Their offerings were in the HIPAA-adjacent or HIPAA-subject categories mentioned above. In every case, the breadth and depth of the HIPAA administrative, physical, and technical safeguards were a revelation to the client.

As noted above, the healthcare industry must begin to grapple with how to select, implement, and pay for new technologies that employ AI. Healthtech companies must look carefully at the market segment they are focused on and evaluate just how their product integrates into customer systems. And then be prepared to become a regulated entity, with regular risk assessments, policies, and procedures to become HIPAA compliant.

Don’t leave for a sales meeting without your HIPAA compliance solution in place!

And let’s not forget about the regulatory scrutiny that covered entities and business associates are under. The healthcare sector continues to have the most incidents of hacking and security measure failings of any industry sector in the country.

The average ransom demand was $18.2m, with the average payment of $1.15m. This is accompanied by enforcement actions by the Office for Civil Rights (OCR) against business associates. 

Healthtech companies that have never been the subject of an OCR investigation after a breach of PHI should be prepared when the OCR comes to their offices.

OCR investigations do not focus solely on the direct or indirect causes of breaches. They audit your HIPAA compliance from top to bottom, from policies and procedures to actual practices to risk assessments. And, since a breach happened, they always find one or more deficiencies, small or large. And that’s how your fine will be: small or large.