BC Advantage - 2019 Issue 9
HIPAA and Health Apps and APIs Oh My
Subscribe or sign in to view the full article.
Article Overview
This article reviews recent HHS guidance on health apps and APIs and explains how it fits within HIPAA, the HITECH Act, and broader healthcare technology regulation. It is aimed at healthcare providers, covered entities, business associates, EHR developers, app developers, and compliance professionals who need a general understanding of privacy, security, liability, and risk mitigation topics in digital health. The article also touches on FDA mobile medical app guidance, FTC and FCC initiatives, and general compliance practices for reducing risk in technology-enabled healthcare settings.
Why This Topic Matters
As healthcare organizations increasingly rely on apps, APIs, and connected systems, understanding the surrounding privacy, security, and liability framework is important for compliance and risk reduction. This article helps readers orient themselves to the major federal guidance sources affecting health technology and protected health information.
Article Sections
-
Recent HHS Guidance
Introduces the HHS health app FAQs and frames the article’s focus on HIPAA-related responsibilities in technology-enabled information exchange.
-
Q1: Covered entity liability when transmitting ePHI to an app
Addresses the first HHS FAQ concerning liability questions that may arise when an individual asks a covered entity to send electronic health information to an application.
-
Q2: Unsecure transmission to a designated app
Summarizes the second HHS FAQ on whether a covered entity faces liability when fulfilling an access request through an unsecure channel.
-
Q3: EHR system developer liability
Discusses the third HHS FAQ regarding the role of an EHR system developer in transmitting information to an app at a covered entity’s direction.
-
Q4 & Q5: Refusal to disclose and business associate agreements
Covers the final HHS FAQs on whether disclosure can be refused based on app concerns and whether a business associate agreement is required in this setting.
-
FDA, FTC, and FCC
Reviews other federal agencies’ technology-related guidance and initiatives affecting healthcare apps, mobile medical software, and telemedicine access.
-
Compliance Factors and Risk Mitigation
Outlines general compliance and risk-reduction practices relevant to HIPAA and the HITECH Act in technology environments.
-
Conclusion
Brings together the article’s main themes on healthcare technology, regulatory guidance, and privacy and security compliance.
What You Will Learn
- How HHS guidance addresses health apps and APIs in a HIPAA context
- How federal agencies approach healthcare technology oversight at a high level
- What general compliance and risk mitigation themes are emphasized for digital health
- How the article situates HIPAA and HITECH within broader technology and privacy discussions
Who Should Read This
- Healthcare providers
- Covered entities
- Business associates
- EHR system developers
- App developers
- Compliance professionals
- Healthcare technology stakeholders
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com