Security HubHIPAA for Non-US Companies: When It Applies to You

HIPAA for Non-US Companies: When It Applies to You

Netru Compliance7 min read

Most non-US companies meet HIPAA the same way: a US healthcare customer sends a Business Associate Agreement during procurement and expects it signed. That document is not a formality. It makes you directly liable under US federal law for the security of protected health information, regardless of where your company is incorporated. This explains when HIPAA reaches you, what it actually requires, and what your existing certifications do and do not cover.

How it reaches an overseas supplier

HIPAA binds covered entities, meaning health plans, healthcare clearinghouses and healthcare providers who transmit health information electronically. It also binds business associates, meaning anyone who creates, receives, maintains or transmits protected health information on behalf of a covered entity. Since the HITECH changes, business associates are directly liable rather than merely contractually bound.

There is no territorial limit that helps you. A software vendor in Manchester or Berlin processing patient data for a US hospital is a business associate. So is its own subprocessor, through a chain of agreements that must flow the obligations down.

The trigger is protected health information specifically, meaning individually identifiable health information. Data that has been properly de-identified under the standard falls outside, which is why de-identification is often the cheapest compliance strategy available if your product does not genuinely need identifiable data.

What the Security Rule requires

The Security Rule is organised into administrative, physical and technical safeguards, and its distinguishing feature is that specifications are either required or addressable. Required means implement it. Addressable does not mean optional: it means implement it, or document why it is not reasonable and appropriate and implement an equivalent alternative. Treating addressable as optional is the single most common failure, and it is exactly what an investigation looks for.

Administrative safeguards include a formal risk analysis, risk management, sanction policy, workforce security, training and contingency planning. The risk analysis is the foundational requirement and the one most often found inadequate, because a generic questionnaire is not a risk analysis of your specific systems and data flows.

Technical safeguards cover access control, audit controls, integrity, authentication and transmission security. Encryption is addressable rather than required, which surprises people, but in practice the safe harbour it provides against breach notification makes it effectively mandatory: encrypted data breached to the standard is not a reportable breach.

What a BAA commits you to

A Business Associate Agreement obliges you to safeguard protected health information, to use and disclose it only as permitted, to report breaches and security incidents to the covered entity, to flow equivalent terms to your own subprocessors, to make records available for investigation, and to return or destroy the information at termination.

Read the breach reporting timeline before signing. Many BAAs require notification to the covered entity considerably faster than the statutory outer limits, because the covered entity needs time to meet its own deadlines. Agreeing to a short window you cannot operationally meet is a contractual failure waiting to happen.

Also read the indemnity and the subprocessor terms. HIPAA itself does not set commercial liability, so that is negotiated, and healthcare BAAs are frequently more aggressive on indemnity than the customer's standard commercial contract.

How it relates to SOC 2 and ISO 27001

Neither one makes you HIPAA compliant, and any vendor claiming otherwise should be treated with suspicion. HIPAA is a statutory regime with specific required and addressable implementation specifications; SOC 2 is an auditor opinion against criteria you partly select, and ISO 27001 is a management system certification.

That said, the overlap is substantial and worth using. A mature ISO 27001 or SOC 2 programme means your access control, audit logging, encryption, incident response, workforce training and vendor management already operate. What remains is the HIPAA-specific work: the risk analysis in the form the rule expects, documented decisions on every addressable specification, BAA management including flow-down to subprocessors, and a breach assessment process that applies the four-factor test the rule sets out.

The honest sequencing for a company already certified is a gap assessment against the Security Rule rather than a fresh programme. For a company with neither, building the security management system first and mapping to HIPAA second is usually cheaper than the reverse, because the management system is what makes every subsequent framework an exercise in evidence rather than construction.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call