HIPAAmart

Frequently Asked Questions

Answers to the everyday questions.

Clear, referenced answers to specific scenarios and edge cases that come up in practice.

Reviewed August 2026

Available guidance

  • What is PHI?

    PHI is individually identifiable health information held or transmitted by a covered entity or business associate in a form or medium covered by HIPAA. Coverage depends on the information, identifiability, and organization or service involved.

  • Is all health data PHI?

    No. HIPAA coverage depends on the information, whether it identifies an individual, and the type of organization or service involved. Other laws, contracts, or professional duties may still apply.

  • Does HIPAA require encryption?

    Encryption is an addressable implementation specification under the Security Rule. An organization must assess whether and how to implement it, document the decision, and consider reasonable alternatives where appropriate.

  • When do I need a BAA?

    A BAA is generally needed when a person or entity is a business associate performing covered functions or services involving PHI for a covered entity or business associate. Analyze the relationship and service rather than relying on a product label.

  • Does a BAA make a vendor HIPAA compliant?

    No. A BAA establishes obligations between parties. Each organization remains responsible for its own safeguards, oversight, configurations, workforce practices, and compliance decisions.

  • Can I put PHI into a public AI chatbot?

    Do not enter PHI into an AI service until the specific workflow's privacy, security, contractual, retention, access, and data-use questions have been reviewed and approved.

  • Do I need a BAA with a cloud provider?

    If the provider is a business associate because it handles PHI for the covered entity or business associate, the relationship should address the applicable business associate requirements and contractual arrangement. A BAA does not make the workload compliant by itself.

  • Is a ransomware event automatically a HIPAA breach?

    A ransomware event requires investigation. OCR guidance explains that ransomware can involve a breach analysis; document the facts, applicable presumption and exceptions, and the notification decision.

  • How do I perform a HIPAA risk assessment?

    Define scope, inventory ePHI and systems, identify reasonably anticipated threats and vulnerabilities, assess current controls and likelihood and impact, then use the result to prioritize documented risk management.

  • Does HIPAA apply to telehealth?

    A telehealth workflow can involve covered entities, business associates, PHI, and ePHI. Analyze the provider, platform, vendors, data flows, access, and applicable guidance rather than relying on the word telehealth alone.

  • How long do I need to keep HIPAA records?

    HIPAA includes documentation retention requirements, and other legal, contractual, operational, or state requirements may apply to particular records. Define and document a schedule for the record type rather than assuming one universal HIPAA period.