Digital Health and Healthcare IT
Your customers audit you harder than any regulator does, and they do it before they sign.
Digital health companies usually meet their security obligations through a customer rather than through an enforcement action. A health system sends a questionnaire, a procurement process asks for evidence, and a deal that was closing pauses while somebody assembles answers nobody has had to give before.
The obligations underneath are real either way. Business associates are directly liable for Security Rule compliance, not only through the agreement they signed, and the risk analysis is the control most often cited when enforcement does happen.
What this sector is actually under
The Security Rule wants a named person
A security official responsible for developing and implementing the policies and procedures. One person, not a committee and not the managed provider. It is the first thing a questionnaire asks and the easiest gap to see.
Risk analysis, not a checklist
An accurate and thorough assessment of risk to electronic protected health information everywhere it lives, moves and is backed up, with the reasoning written down. What usually exists instead is a questionnaire somebody filled in once.
Tenant separation in a shared system
If more than one customer’s data lives in a shared database, how one organization is prevented from reaching another’s records. This is an architecture answer, and it is the question a competent reviewer reaches quickly.
Authorization on every request
Not "role-based access control" as a phrase, but how the check runs, where it runs, and what happens when it is absent. Enterprise security reviews increasingly ask this directly.
Audit logging before somebody asks
Who accessed what, when, and the ability to answer that for a specific patient record on request. Retrofitting it under deal pressure is considerably more expensive than having it.
Vendors, in both directions
The business associate agreements you hold with your subprocessors and the ones your customers hold with you, plus whether your providers are doing what those agreements assume.
Which side of the practice you need
If the pressure is a questionnaire, an audit or a program that does not exist, that is the fractional CISO side, and a HIPAA security program is often the scoped version of it.
If the answers exist but the system cannot support them, the gap is architectural and the CTO side is where it gets closed.
The two pillars
Where this usually starts
Questions I get asked first
We are a business associate, not a covered entity. How much of this is ours?
Most of it. Business associates are directly liable for Security Rule compliance. In practice your customers enforce it harder than anyone, because their diligence is what surfaces it and their contract is what depends on it.
Our cloud provider is HIPAA eligible. Does that cover us?
It covers their side of the line. A provider’s compliance posture applies to the provider, not to your configuration of it, and the shared responsibility boundary is one of the things a serious reviewer will ask you to state explicitly.
A deal is blocked on a security questionnaire right now. Can that be unblocked quickly?
The answers usually can be, because most questionnaires are asking a smaller number of real questions than they appear to. What cannot be rushed is making an answer true that currently is not, which is why the questionnaire is worth reading as a to-do list rather than as a form.
Written on this
Start with a conversation
Tell me what’s going on. I will tell you which of these it actually is, and whether you need me for it.
Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.
Not ready for a call? Send a message instead.
For companies looking to engage BATO. Vendors, please email.