Hacking accounted for 258 of the breaches reported to federal regulators between January and July 2025, exposing the data of 28.8 million people, according to BankInfoSecurity's analysis of HHS data. That covered almost everyone affected in the period. If your product handles patient records, healthcare app security best practices are the difference between a launch and a notification letter.
Most of what follows comes from the HIPAA Security Rule's technical safeguards and from how real incidents unfolded. We've kept it to what you can build into an app, not what a compliance binder says.
Where healthcare apps actually get breached
Attackers get in by hacking, and a large share of the damage runs through vendors rather than the covered entity itself. In the same mid-2025 data, business associates sat at the center of 37% of major breaches yet were responsible for more than half of the people affected.
The practical reading is simple. Your own code matters, but so does every analytics SDK, hosting provider and billing service that touches patient data. A secure app with a careless integration is still a breached app.
Episource, a medical coding vendor, reported the largest incident in that period: a ransomware attack affecting 5.4 million people. The victims were its clients' patients, who had never heard of the vendor.
What the HIPAA Security Rule requires of your app
The technical safeguards in 45 CFR 164.312 name five standards: access control, audit controls, integrity, person or entity authentication and transmission security. Each one translates into features your app either has or doesn't.
Two implementation specifications are required outright: unique user identification and an emergency access procedure. Automatic logoff and encryption are listed as addressable, which many teams misread as optional.
Addressable means you assess whether the measure is reasonable for your setup and document an alternative if you skip it. In practice, almost nobody has a defensible reason to skip encryption on a mobile app or a patient portal, so build it in.
Healthcare app security best practices that map to the Security Rule
Treat the rule as a feature list. The sections below cover the controls that carry the most weight, in the order we'd build them.
Role-based access and unique identities
Give every user a unique ID, then map roles to the minimum data each job needs. A front-desk coordinator shouldn't see clinical notes, and a billing analyst shouldn't be able to export full charts.
Accountable's guide to healthcare application security adds time-bound elevation for administrative actions, so nobody holds standing superuser rights. We agree with that, because standing admin accounts are what attackers hope to find.
Multi-factor authentication and session limits
Require multi-factor authentication for staff, administrators and anyone connecting remotely. Pair it with session timeouts and automatic logoff, which matters most on shared clinic tablets and kiosk devices where a previous user's session is one tap away.
Encryption in transit and at rest
Encrypt every connection and every store of patient data, including backups and local caches on phones. Keep the keys somewhere separate from the application: a dedicated hardware security module or a cloud key management service, rotated on a schedule.
Envelope encryption is worth the extra design work. If an attacker takes over an application server, they still don't walk away with the master keys.
Audit logs that don't leak the data they protect
Log sign-ins, record access, administrative actions and data exports, and keep clocks synchronised so the timeline is trustworthy. Redact sensitive fields before they hit the log, because a debug line containing a diagnosis turns your logging system into a second database of patient data.
API and mobile storage
Use short-lived tokens with OAuth 2.0 or OpenID Connect, scope them to the audience that needs them, and rate limit every endpoint. On mobile, encrypt the device store, support remote wipe, and block local caching of patient data you don't need offline.
Vendors, SDKs and business associate agreements
Every third party that handles patient data needs a current business associate agreement, and its encryption, logging and incident response should be assessed before you integrate it. That includes tools that seem harmless, such as analytics and session replay scripts embedded in a patient portal.
The mid-2025 numbers make the case on their own. When vendors account for most of the people affected by breaches, a vendor questionnaire is a security control, not paperwork.
Our guide to HIPAA compliant app development goes deeper on how these obligations shape architecture decisions from the first sprint.
What the proposed Security Rule update would change

Photo by Alexander Grigorian on Pexels
HHS proposed a rewrite of the Security Rule in a notice issued January 6, 2025. As summarised in Bradley's breakdown of the proposal, it would turn today's addressable items into hard requirements.
- Encryption on servers, laptops, mobile devices and in transmission, with limited exceptions.
- Multi-factor authentication across technology assets, with exceptions for certain legacy systems and older medical devices.
- Written asset inventories and data-flow maps, updated at least annually.
- Vulnerability scanning every six months and penetration testing annually.
- Restoration of critical systems within 72 hours of an incident.
- Business associates notifying covered entities within 24 hours of activating a contingency plan.
It is a proposal, so check its current status before you plan around specific deadlines. Even so, the direction is unambiguous, and an app designed to the proposed list will pass today's rule comfortably. Retrofitting encryption and logging later costs far more than building them in.
Testing, response plans and keeping evidence
Run vulnerability assessments continuously and commission penetration tests at least annually, plus after any major architectural change. That cadence is the one Accountable recommends, and it lines up with the annual testing in the proposed rule.
Write the incident response plan before you need it: who reports what, who contains it, who calls the covered entity. The proposal would require the plan to be reviewed and tested every 12 months, which is a sensible habit even if it never becomes law.
Finally, keep evidence. Auditors and clients ask to see the risk analysis, the access reviews and the test reports, not your assurance that they exist.
Building this into the product from the start
Security added after launch tends to be partial, because the data model and the permission structure are already set. When we designed and built OptimalMD's digital product end to end, covering the website, the members portal and the mobile app, those decisions had to be made across all three surfaces at once. You can read how that came together in the OptimalMD case study.
If you're scoping a product like this, our apps and SaaS development team can build the controls above into the first release. And if you're still choosing a partner, how to choose a healthcare app development company lists what to ask about security before you sign.
Frequently asked questions
Is encryption required under HIPAA?
Under the current rule, encryption is an addressable specification, meaning you must implement it where reasonable or document an equivalent measure. The proposed update would make it mandatory with limited exceptions.
Which safeguards are required rather than addressable?
Unique user identification and an emergency access procedure are required. Automatic logoff, encryption and integrity controls are addressable.
Do third-party analytics tools need a business associate agreement?
If the vendor handles patient data, yes. Each one needs a current agreement, and you should assess its encryption, logging and incident response before integrating it.
How often should a healthcare app be penetration tested?
At least annually and after major architectural changes, according to Accountable's guidance. The proposed Security Rule update would also require vulnerability scans every six months.
Cover photo by Stefan Coders on Pexels
Sources
- Hacks Lead Health Data Breach Trends So Far in 2025 — BankInfoSecurity
- 45 CFR 164.312 - Technical safeguards — Cornell Legal Information Institute





























