🇺🇸 HIPAA · 45 CFR Parts 160 + 164
HIPAA + HITECH scoping for medical AI Free. 2 minutes. Engineer-led.
HIPAA breaks startups when they discover their AI vendor isn't BAA-eligible, or that 'encryption in transit' didn't extend to a single legacy fax gateway. Get a clean list of safeguards, BAA requirements, breach SLAs and FDA SaMD overlap that apply to your specific stack.
In scope
What this covers
- 01 Privacy Rule — uses + disclosures of PHI, individual rights, marketing restrictions
- 02 Security Rule — technical safeguards (access control, audit, encryption, authentication, transmission)
- 03 Breach Notification Rule — 60-day SLA to HHS / media for ≥500 individuals
- 04 BAAs with every PHI-touching vendor (cloud, AI APIs, analytics, support tools)
- 05 Encryption-as-safe-harbor — encrypted PHI is not 'unsecured', dramatic breach-cost reduction
- 06 HITECH enforcement tiers — $100 to $50,000 per violation, $1.5M annual cap per type
- 07 State-law interaction — California CMIA, Texas HB 300, plus the breach laws of all 50 states
For · CTO / Head of Engineering at telehealth, medical-device AI, clinical decision support, or healthcare RCM startups