2 links tagged with all of: hipaa + compliance + healthcare
Click any tag below to further narrow down your results
Links
This article explains how healthcare organizations can get a HIPAA-compliant Business Associate Agreement with OpenAI to process protected health information via the API. Email baa@openai.com with your company details and use case; most requests are approved within a few business days. If your request is denied, you can seek reconsideration through your sales contact.
- Emailing baa@openai.com with company details and use case gets most BAA requests approved within a few business days.
- Denied requests can only be reconsidered if you already have an OpenAI sales rep or account director to escalate through.
- Nearly all API services are covered under the BAA (exceptions listed in the platform docs), and no enterprise agreement is required to get one.
The article provides official guidance on how the Health Insurance Portability and Accountability Act (HIPAA) applies to online tracking technologies. It emphasizes the importance of protecting patient privacy and ensuring compliance when using digital tools for tracking purposes. The content is aimed at professionals navigating these regulations.
- Tracking tech on healthcare websites/apps (cookies, web beacons, pixels) can transmit PHI to third parties like Google or Meta, triggering HIPAA obligations even without login credentials
- Covered entities must have a valid HIPAA authorization or a Business Associate Agreement with tracking vendors before allowing them access to PHI, not just a general privacy policy disclosure
- IP addresses combined with visits to health-related pages can count as PHI, so even "de-identified" or aggregate analytics tools carry compliance risk
- Organizations face liability exposure if third-party trackers disclose PHI without proper safeguards, making an audit of existing tracking tools and vendor contracts a practical necessity