The Compliance Knowledge Gap in Healthcare Technology

Table of Contents

Protecting PHI requires more than secure software. It requires understanding the responsibility that comes with having access to healthcare information.

Healthcare technology is advancing rapidly. We are seeing more AI, automation, analytics, revenue cycle platforms, documentation tools, integrations, and applications designed to make healthcare more efficient.

That innovation is needed.

But there is a knowledge gap I continue to see when technology companies enter healthcare:

Understanding the technology is not the same as understanding the responsibility of protecting protected health information (PHI).

If your company is going to create, receive, maintain, transmit, display, analyze, or otherwise interact with PHI on behalf of a healthcare organization, HIPAA and healthcare compliance cannot be something your team learns after implementation.

They have to be part of the foundation.

PHI Is More Than What Appears in the Medical Record

When people hear “PHI,” they often think of a patient’s medical chart.

But PHI can travel much further than the EHR.

It may appear in a claim, eligibility response, denial, patient demographic file, screenshot, support ticket, screen recording, email, exported report, system log, training example, testing environment, or data set being analyzed by another application.

That is why everyone who may encounter healthcare information needs to understand what PHI is and how it must be handled.

The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity, and availability of electronic PHI through administrative, physical, and technical safeguards.

Those are not simply IT responsibilities.

They are organizational responsibilities.

Access Is Not the Same as Authorization

Technology makes access easy.

Compliance asks whether that access is appropriate.

A developer may technically be capable of opening a production environment.

A support representative may be able to see an entire patient record while troubleshooting.

An administrator may be able to export thousands of records.

That does not automatically mean they should.

HIPAA requires appropriate access management, including policies and procedures designed to authorize access to electronic PHI based on the user’s role. The Privacy Rule’s minimum necessary principle also generally requires reasonable efforts to limit access, use, and disclosure to what is needed for the intended purpose.

That distinction matters enormously in technology.

“They needed access to the system” is not the same as “they needed access to all of the PHI inside the system.”

The Small Things Are Often Where Exposure Happens

Healthcare technology companies should be thinking beyond cyberattacks and massive data breaches.

Sometimes PHI exposure begins with ordinary workflow.

A support employee asks a client to send a screenshot containing patient information through an inappropriate channel.

A developer uses production data for testing.

A team downloads a patient report onto a personal device.

Someone shares credentials because it is faster.

A screen containing patient information is recorded during a training session.

PHI is pasted into an AI application without understanding where the information goes or whether the tool is approved for that use.

A subcontractor is given access without anyone evaluating the HIPAA implications.

None of these scenarios requires a sophisticated hacker.

They require a gap in compliance understanding.

Signing a BAA Does Not Create Compliance

The Business Associate Agreement is important, but I think this is another area where technology companies can misunderstand healthcare compliance.

A BAA is not a certificate saying, “We are HIPAA compliant.”

When a technology company functions as a business associate, it can have direct obligations under HIPAA. HHS also makes clear that business associates may be directly liable for certain HIPAA violations, including failures to appropriately safeguard electronic PHI.

And the responsibility may continue downstream.

If a business associate uses a subcontractor that creates, receives, maintains, or transmits PHI on its behalf, appropriate business associate arrangements may also be required with that subcontractor.

That means healthcare technology companies need to understand not only their own systems, but their entire PHI ecosystem.

Where does the information go?

Who can access it?

What vendors touch it?

Where is it stored?

How is access terminated?

How is activity monitored?

What happens when something goes wrong?

Your Workforce Needs to Understand Healthcare Compliance

You can build sophisticated security controls and still create significant risk if the people operating the technology do not understand why those controls exist.

Developers, engineers, implementation specialists, account managers, customer support teams, analysts, executives, and contractors who may encounter PHI need appropriate education.

Not just a once-a-year training where everyone clicks “next.”

They need to understand how HIPAA applies to their actual job.

What can I access?

What should I access?

Can I download this?

Can I email this?

Can I take this screenshot?

Can I put this information into another application?

Can I share this with a coworker?

What should I do if I accidentally receive information I should not have?

Who do I contact if I believe PHI may have been exposed?

HHS specifically identifies workforce security, security awareness and training, access management, audit controls, authentication, and transmission security among the safeguards required to protect ePHI.

Compliance has to become part of how the organization thinks.

Healthcare Data Is Different

Technology companies are accustomed to collecting data.

Healthcare companies are entrusted with information about people’s lives.

Diagnoses.

Procedures.

Medications.

Mental health information.

Insurance coverage.

Financial information.

Addresses.

Dates of birth.

Medical histories.

Sometimes information people have shared with almost no one other than their healthcare professional.

That deserves a different level of care.

Healthcare organizations should absolutely embrace technology, and technology companies should continue building solutions for healthcare.

But entering this industry comes with an obligation to learn it.

Learn HIPAA.

Understand PHI.

Understand minimum necessary access.

Understand your business associate responsibilities.

Understand where patient information travels throughout your technology stack.

Train your people to recognize risk before an incident occurs.

Because when a healthcare organization gives a technology company access to PHI, it is not simply providing access to data.

It is extending the trust its patients placed in that organization.

And protecting that trust should be treated with the same importance as building the technology itself.

Table of Contents

Share on:
Scroll to Top