I've been building web applications for some time now and I'm reading through a contract that requires me to be HIPAA compliant; even though they dont state what form fields require this. So I obviously started doing some research and found this article (https://www.hipaajournal.com/what-is-considered-protected-health-information-under-hipaa/) that states the 18 fields that could be considered PHI.
This got me thinking, items 1, 2, 4, and 6, are common identifiers we use when creating new accounts for almost all of our applications... so should we all be following HIPAA compliance rules? Or is this stating that health information including those 18 identifiers.
Thoughts? comments? advice? All are welcome.
I'm somewhat knowledgable in this as I work in the medical field and have done consulting with Health IT companies in the past. I can't recall the fields off the top of my head, but I will tell you that handling ePHI and and HIPAA compliant data on your servers requires a TON of specific security considerations. This includes having a Security Risk Assessment completed in accordance with HHS requirements and being on the hook for huge fines if there was ever a security breach. If you are going to go down that route, make sure you are 100% on the costs and risks and price your project accordingly.
Start your research here:
https://www.hhs.gov/hipaa/for-professionals/index.html
I did a bit of research and since we arent taking in medical data and we arent consuming ALL of the fields within that list, we are not required to be HIPAA compliant. Although we are consuming some PII, which most of us do within our applications so we have to take those precautions to keep our customers safe.
Also, just as a CYA, I'm having my attorney review the contract and to discuss what fields we are consuming prior to signing. Rather measure twice