Skip to content

HIPAA Compliant App Development: What It Actually Takes

Juwel Rana

By Juwel Rana · CEO & Founder

1,736 views
A laptop screen shows a coding application with a calculator design in a tech office setting.

Most teams starting HIPAA compliant app development assume the health data itself decides whether the law applies. It doesn't.

What decides it is the relationship between the developer and whoever holds the patient relationship. Get that wrong, and a build either ships without the safeguards it needed, or carries rules it never triggered.

The test is simple to state. When a covered entity such as a hospital contracts with a developer to build an app that handles patient data on its behalf, that developer becomes a business associate and the full Security Rule applies.

A patient who downloads a symptom tracker on their own and connects it to their records themselves usually isn't dealing with anyone's business associate, and HIPAA never covers that data.

Why HIPAA Compliant App Development Starts With the Contract, Not the Code

HIPAA Journal has pointed out the sharper edge of that test. Once a covered entity shares a patient's data with an app the patient chose, and the developer isn't that provider's business associate, the data stops being covered the moment it lands in the app.

That's the gap a lot of patient-facing health apps live in.

It doesn't mean no rules apply there. The FTC's updated Health Breach Notification Rule, finalized in April 2024, covers exactly the apps HIPAA misses: fitness trackers, period trackers, direct-to-consumer apps with no covered entity behind them.

It requires notifying affected users without unreasonable delay once a breach is discovered. The FTC has already enforced it, against GoodRx for sharing health data with advertisers and against Easy Healthcare's Premom for disclosing ovulation data the same way.

Settling which side of that line a build sits on comes before any technical decision below.

What the Proposed Security Rule Changes Would Require

Assuming the business associate relationship exists, HHS's Office for Civil Rights proposed sweeping changes to the Security Rule in January 2025. Arnold & Porter's analysis of the proposal lays out what changes for developers.

Today's rule treats safeguards like encryption and multi-factor authentication as "addressable," meaning a covered entity can adopt an alternative or document why one doesn't apply. The proposal would erase that flexibility for the safeguards that matter most to how an app gets built.

Comments closed in March 2025 and it hasn't been finalized since. Whatever its fate, the safeguards it names are a reasonable baseline for any build handling ePHI.

SafeguardToday's ruleUnder the 2025 proposal
EncryptionAddressable, alternatives allowedRequired for all ePHI at rest and in transit
Multi-factor authenticationAddressableRequired to reach any system touching ePHI
Patch managementNo fixed timelineWritten policy, reviewed annually
Network segmentationNot addressedRequired to limit ePHI access to authorized systems

That table doubles as a checklist. Encrypting ePHI at rest and in transit, and requiring MFA for anyone who can reach the database, covers most of it. Segmenting that database from the rest of the network closes the gap.

None of it is exotic, and our guide to healthcare software development covers building it in from day one rather than retrofitting it later.

Building the Agreements In From the Start

View of high-rise buildings and cranes at a construction site during daytime, capturing urban development.

Photo by Dextar Studio ™ on Pexels

None of the technical work replaces the paperwork. A covered entity needs a signed business associate agreement with the developer, and the developer needs matching agreements with its own vendors, starting with the cloud host and the database provider.

That's the part that gets skipped when a build starts as a fast MVP and only becomes a healthcare product later. Our guide to compliance-first healthcare software development covers sequencing that work so the agreements exist before the first patient record does.

Access control had to hold up before our OptimalMD case study platform could launch at all. Building in-house versus bringing in a team that has already done the paperwork is worth settling that early. Our apps and SaaS team can usually tell within a conversation which one your app needs.

Cover photo by Eduardo Rosas on Pexels

Latest Blog

A smiling woman patient during a dental checkup in a modern clinic setting.Dental Marketing • Healthcare Web Design

Dental Practice Client FAQ: What They Ask Us Most

Before color palettes or fonts, dental and medical practice clients ask about HIPAA-compliant forms, ADA lawsuits, and why reviews aren't converting. Here's what we tell them.

Read More
A smartphone with a shopping cart depicting the concept of online shopping in a colorful studio setup.CRM • Ecommerce

GoHighLevel vs HubSpot Ecommerce: Which CRM Wins?

GoHighLevel charges one flat rate no matter how many contacts you add. HubSpot charges by seat and contact tier. Here's how that plays out for an online store.

Read More
A male teacher explains math equations on a whiteboard during an online class.Education Marketing • Local SEO

How Education Businesses Compete Online

Coursera spends tens of millions a quarter chasing scale, and Kumon runs thousands of centers worldwide. Here's where a smaller education business can still out-trust both of them online.

Read More
Close-up of a laptop showing a social media marketing strategy in an office setting.Home Services • Content Strategy

Home Service Content Strategy: What Actually Books Jobs

AI Overviews now answer most local searches before a homeowner clicks anything. Here's what that means for a home service content strategy built on blog posts and hope.

Read More
Close-up view of industrial metal balconies and pipes against a clear sky.Manufacturing • Apps & SaaS

What a Manufacturing Digital Platform Build Actually Needs

Manufacturers are under pressure to give buyers self-service pricing and ordering, but a platform built like a retail site will fail against a decade-old ERP. Here's what actually needs planning first.

Read More
Colorful map of Australia featuring toy ships and pins for navigation.SEO • Digital Marketing

SEO Agency Red Flags Australian Businesses Should Know

One in three Australian small businesses end up in a dispute with their digital marketing provider. Here's what to listen for before you sign.

Read More

Subscribe to our newsletter

Offers, insights and updates — a couple of times a month, never more.