How to develop a HIPAA compliant mobile application: Step-by-Step Guide

With an ever-increasing number of health apps on the market and newly introduced privacy laws, tech startups are called to re-evaluate the way they collect and store user data. If you are starting the process of healthcare app development, you must be familiar with the term “HIPAA compliance.”At Purrweb, we built several successful HIPAA-friendly apps for our clients. Based on our experience, we created a guide to explain what HIPAA stands for and answer the most asked questions about how to build a HIPAA compliant app from scratch. Bonus in the end: find a checklist for a HIPAA compliant app. Let’s go!

Reading time: 9 minutes

Table of contents

    What is HIPAA

    HIPAA stands for Health Insurance Portability and Accountability Act. It was passed by the U.S. Congress in 1996 to protect the medical records and the personal health information of patients.

    HIPAA is a federal law in America, which means it is applied in all 50 states. Regardless of where your company is registered or what state you operate in, you must consider both federal and local regulations.

    The main goal of HIPAA is to make sure the details about one’s health are confidential. Therefore the act applies to PHI (Protected Health Information) — all information that can help identify the patient, such as a name, date of birth, SSN number, and phone. HIPAA compliant mobile apps promise users that their sensitive data is under reliable protection. HIPAA-covered entities must have a business associate agreement with every partner to maintain PHI security and be HIPAA compliant.

    Why knowing about HIPAA is important 

    Fines for noncompliance can destroy early-stage startups. If you ignore HIPAA regulations, you will have to pay from $100 to $50,000 per each violation with a maximum fine of $1.5 million per year. Some violations can even result in jail time.

    If you don’t want to have trouble with the law — and no one does — it is crucial to know about HIPAA requirements.

    What happens if you fail HIPAA compliance 

    If you fail to secure HIPAA privacy for consumer health information, it will have major consequences.

    First, the law requires you to notify users about the breach, specify what information leaked and explain potential risks. If it influences more than 500 people, the startup must also notify media outlets. Just imagine all the bad PR that can come out of this and to what extent it can damage your business.

    Secondly, the app owner can be liable for fines and penalties that can put a burden on financial management, especially for startups at early stages.

    To prevent this, proper planning and knowledge of HIPAA compliance are required.

    What data is subject to HIPAA regulations

    The law references PHI — Protected Health Information. All data that can identify a particular user is protected under HIPAA requirements. It includes:

    💁‍♂️ Names 

    Full, first or last name, and initials would be protected by HIPAA regulations if it is accompanied by consumer health information.

    🌎 All geographical identifiers 

    Everything smaller than a state, for example, your city, county or neighborhood. But there is one exception: the first three digits of a zip code. So, the user’s address or place of birth would be covered.

    📅 Dates

    All dates, other than the year, are directly related to a user. For example, date of birth (if a patient is over 89 years old), as well as death date, and admission or discharge date.

    📞 Phone numbers

    Have you ever gotten a spam call and wondered where they got your number? Definitely not from your healthcare provider, because it would be a serious HIPAA violation. Also, if someone is so old-school to use fax these days, its number is considered to be a part of the PHI covered entities.

    💌 Email addresses

    It is self-explanatory — email can also identify a patient, so it is protected under HIPAA.

    🔒 Social Security number

    Breached Social Security numbers can lead to identity theft and other serious consequences.

    🩺 Medical record numbers

    The number consists of six digits and appears on most healthcare documents: bills, visit summaries, or referrals. It helps healthcare providers access patients’ electronic records.

    🏥 Health insurance information 

    Name of the provider, patient ID, group number — all is confidential and should be protected under HIPAA.

    😎 Account number

    This number is assigned by healthcare organizations during a medical visit and is also subject to HIPAA protection.

    👩🏻‍⚕️Certificate or license numbers

    HIPAA protects doctors as well — their educational and professional documents are subject to HIPAA compliance rules.

    🚗 Vehicle information

    Covered entities include a driver’s license number, license plate number, or the serial number of a car.

    🦾 Device identifiers and serial numbers

    If a user wears medical devices, for example, insulin pumps or health rate monitors, their serial numbers would be also considered confidential patient data.

    🧑🏻‍💻Web URLs

    Any URL that can be associated with patients needs to be protected. Don’t overlook it during HIPAA compliant app development.

    💻 IP addresses

    IP address identifies a device that accesses your mHealth app and, in the wrong hands, it can be traced to someone’s smartphone or laptop.

    READ MORE  Doctor appointment app development: features, benefits & costs

    ✋Biometric data

    Many healthcare organizations use biometric data scans to link an account to a specific user once and for all. Everyone has unique fingerprints, so if a patient adds them to their account, no one else can access the information. Covered entities here include a finger, retinal, voice prints, and other biometric identifiers.

    📸 Photos or videos

    This refers to any picture showing a full face of an individual, and he or she can be identified, but also a photo with identifiable PHI — a name, initials, or a patient number.

    🕵️‍♀️Any other identifying details

    All other characteristic and unique codes that can point out specific individuals and disclose their medical information.

     Important note: Demographic data, for example, name, date of birth, or insurance information are only protected when they are used in combination with medical information

    Should your mHealth app be HIPAA compliant

    Not all healthcare mobile and web solutions must be HIPAA compliant. For example, most yoga or meditation apps do not fall under the privacy act, because your identifiable information is for personal use. It is not intended to be shared with healthcare providers.

    The HIPAA Act only applies to the platforms that share your medical information with “covered entities” — other parties, for example, doctors, dentists, hospitals, and health insurance companies. They must use HIPAA compliant software.

    To check if the law applies to your startup, you need to answer three questions about your healthcare app:

    If you answer “yes” to all questions, you need a HIPAA compliant mobile app.

    What does HIPAA compliance for health applications mean for developers

    There are 3 types of requirements for HIPAA compliant apps: administrative, physical and technical safeguards. All of them regulate access control and data sharing. Let’s review each requirement in detail and discuss possible safety measures for the app.

    Administrative requirements

    These refer to internal regulations that can be done by startup owners, hospitals, and healthcare providers to ensure data privacy and security. For example, regular employee training and risk assessments. Administrative security measures can include:

    • Regular system audits;
    • Penalties for employees who fail to comply with HIPAA regulations;
    • Periodical security reminders;
    • Designated HIPAA supervisors on a team.

    Physical safeguards

    Physical safeguards refer to real-world policies that protect physical access to buildings, workstations, computer servers, and networks. Their main goal is to monitor who accesses the data in a HIPAA compliant app to prevent potential violations and unauthorized users. Such security measures include:

    • Building security;
    • Access control (for example, door passes and visitor log-in);
    • Emergency protocols if something goes south;
    • Procedures for data and device disposal.

    Technical safeguards

    The main problem for HIPAA violation is device theft — when your phone gets stolen, all information on it gets into the hands of scammers. Technical requirements ensure that personal information in the HIPAA compliant software is secured on the backend and will remain confidential even if someone takes your device.

    READ MORE  A Complete Guide to Healthcare Mobile App Development in 2023

    Technical safeguards in the HIPAA compliant app help to reduce data misuse and identity thefts or fraud. They include:

    • Unique user identification (for example, a unique name or an account number);
    • Automatic logout due to inactivity;
    • Emergency access procedures;
    • Encryption of electronic protected health information;
    • Protected data transfer networks;
    • Regular audit of information systems;
    • Password management;
    • Two-factor authentication to verify who opens the app.

    Babylon asks users to set up a PIN code in order to use the app. Face ID is optional

    Other data protection laws in the U.S.

    The United States does not have national privacy and data protection law, like GDPR in the European Union. But there are many detailed regulations focused on specific data types. Let’s take a look at some of them that can apply to your mobile app.

    FTC Act

    The FTC (Federal Trade Commission Act) protects users from “anticompetitive, deceptive, and unfair business practices.” Essentially, it requires you to be honest and upfront with users about the way you manage their information, as well as to notify users when their data is breached.

    State laws

    Some states have their own laws about data privacy. For example, New York introduced the SHIELD Act. It applies to any app that owns private information of a New York resident. In short, even if you don’t operate in New York, it is likely the SHIELD Act still applies to you if you have at least one user from the city. The act requires mobile apps to adopt certain administrative, technical, and physical safeguards for data protection.

    California also has a data privacy law for the residents — Consumer Privacy Act (CCPA). Under it, users have the right to know what information an app collects, the right to request information to be deleted, and the right to opt-out of sharing data.

    Important reminder: check data privacy laws in the states you operate in. California, Illinois, Colorado, Utah, Virginia, and Connecticut regulate the sensitive data of their residents.

    How to apply HIPAA to your mobile app 

    For startups in the healthcare industry the knowledge of HIPAA regulation is a must to avoid huge fines and tough penalties. To ensure that the personal health data of your users is protected and to make your app HIPPA compliant, we recommend these 4 steps.

    1. Do your research

      First things first, make sure to educate yourself about all possible laws, HIPAA compliance, and other data privacy regulations your app can be subject to. If your contractor makes a mistake, your startup will have to pay for it with money and reputation. To prevent this from happening, do your own research beforehand and learn about the subject — all information is accessible online.

    2. Evaluate patient health data

      Together with your development team, take a look at the types of personal data you use and decide what features and safeguards are needed for the solution to ensure HIPAA compliance. You can also use our checklist to make sure you include everything.

    3. Use HIPAA compliant consultants if needed

      There are third-party companies that can help your startup be HIPAA compliant. For example, they help with collecting and storing patient data, as well as staff training and expert guidance. Such companies include HIPAA consultants and audit firms.

    4. Work with experienced developers

      The professional team is crucial for HIPAA compliant app development because it helps to minimize the risk of mistakes. Choose wisely, read reviews from previous clients and check the portfolio of your future developer. Make sure the team has had relevant experience before — healthcare is a serious industry and there is no room to experiment.

    READ MORE  Not a rocket science: a guide to choosing your app development partner

    5 steps to make HIPAA compliant apps

    Step 1: Start with a solid idea. A HIPAA compliant mobile app starts with a creative and definite idea that will help you stand out in the marketplace. Before planning the platform, think about your target audience and how your solution will help them. Who is your user? What makes you different? How will your app make money? These questions are to start exploring the idea and turning it into a business plan.

    Step 2: Select a team. The right choice of developer matters. An experienced and skillful team can strengthen your idea of a HIPAA compliant app, assist in data privacy analysis and help you achieve the desired results. Take your time when choosing a developer, check the portfolio with relevant cases and verify the credentials from previous clients.

    Step 3: Check if you are subject to HIPAA compliance rules. As we mentioned previously, not all applications with medical data are subject to the HIPAA act. It depends on what information you collect and how you treat it. Verify all the requirements before you build a HIPAA compliant app.

    If you fall under the HIPAA act, don’t forget to ask users to accept HIPAA Privacy Notice — just like Babylon does

    Step 4: Develop an MVP. MVP is a helpful tool for startup founders. It stands for a minimum viable product and it helps to test an idea with real-world customers. Don’t confuse this stage with a prototype or a draft: MVP is a fully-functioning product, just the set of features is temporarily limited. However, they are enough for a user to complete a journey and provide you with feedback.

    Step 5: Improve and launch the product. After you receive feedback from the customers and analyze data, it is time to improve and grow. The team will help you plan future mobile app development and possible scale-up, provide post-launch support for your HIPAA compliant app, release updates, and fix any issues.

    Let’s wrap up

    For startup owners, it is important to understand that HIPAA compliance is not a one-time thing, but an ongoing process.

    HIPAA compliant application requires commitment, regular maintenance, and support, to make sure your safeguards stay up-to-date and patient information is protected. Any breach of data can cost a lot of money and a big chunk of the reputation to a startup. Therefore, it is better to plan attentively, anticipate challenges and stop them in the bud.

    Our experience 

    At Purrweb, we specialize in mobile and web development with a focus on user-friendly UI/UX design and habit-forming interfaces. We have some experience with mHealth and data laws compliant apps.

    Online psychotherapy app design

    One of our projects wasan online psychotherapy app, a telemedicine service for the UK market. Our team selected a reliable tech stack and encryption to make sure data protection met the requirements of both American HIPAA and European GDPR.

    READ MORE  How to develop an online psychotherapy service in the UK and not go crazy

    If you have been thinking about developing HIPAA compliant healthcare apps, we will be happy to help and share our experience.

    Bonus: HIPAA compliance checklist

    We put together a checklist that will help you check if your app has the most of these technical safeguards:

    ✅ Unique username or account number

    ✅ Emergency access to information

    ✅ Automatic logout when the user is inactive

    ✅ Encryption and decryption of sensitive data

    ✅ Automatic check-ups of information systems

    ✅ ePHI integrity policies

    ✅ Passcode and two-factor authentication

    ✅ Transmission security measures


    Leave your email in the form below to have a consultation with our team⬇️

    How useful was this post?

    Rate this article!

    2 ratings, аverage 5 out of 5.

    No votes so far! Be the first to rate this post.

    As you found this post useful...

    Follow us on social media!


    FAQ s

    • What is HIPAA?

      HIPAA stands for Health Insurance Portability and Accountability Act. It protects the medical records and the personal health information of patients.

    • Do all apps have to be HIPAA compliant?

      Not all healthcare applications must meet HIPAA compliance. But if your solution collects, stores, manages or shares personal health information, the regulations will apply.

    • What data is protected under the HIPAA act?

      18 identifiers are subject to HIPAA: Name Address, Dates, Phone and fax numbers, Email address, Social Security Number, Medical record number, Health plan beneficiary number, Account number, Certificate or license number vehicle identifiers, Medical device identifiers, URLs, Device IPs, Fingerprints, Photos, Other unique characteristics

    • What if I fail HIPAA compliance requirements?

      If your mobile app violates HIPAA compliance you can face a fine of up to $50,000 per violation and potential jail time. Also, the law requires you to send a notification to users and, in some cases, media outlets.

    • How to build a HIPAA compliant app?

      There are 4 main components behind a successful HIPAA compliant mobile app: extensive research of data privacy laws, experienced contractors, knowledge of patient data you work with, and HIPAA consultants when needed.

    • How do you make a HIPAA compliant application?

      Easy-peasy! Get a creative idea ➡️ select a team ➡️ check if HIPAA applies ➡️ develop an MVP ➡️ improve and launch.

    • How to choose a developer for a HIPAA compliant mobile app?

      Pay attention to reviews, the team’s specialization, and previous relevant experience. It is important that a developer has cases dealing with HIPAA regulations and healthcare apps in the portfolio.