• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Q&A: HIPAA and Health Apps

August 14, 2019/in Blog, HIPAA

Rachel V. Rose, JD, MBA, presented the webinar “HIPAA and Health Apps” recently and a recording can now be found on our YouTube Channel. Rachel returned to answer many commonly asked questions on our blog.

How has HIPAA evolved to address mobile technology?

HIPAA was signed into law in August 1996. Subsequently, the Privacy Rule and Security Rule were implemented. In 2009, the HITECH Act passed and with it came an increased focus on security of protected health information (PHI) and breach notification. Finally, on January 25, 2013, the Final Omnibus Rule was published (78 Fed. Reg. 5566 (Jan. 25, 2013)). In general, the U.S. Department of Health and Human Services – Office for Civil Rights has primary jurisdiction over HIPAA enforcement for covered entities, business associates and subcontractors. Other agencies such as the Federal Trade Commission (FTC) and the Food and Drug Administration (FDA) also play a role.

In terms of mobile technology and health apps in particular, HHS recently published FAQs – a series of five questions and answers that target a covered entity’s liability when transferring a patient’s data to an app. Additionally, over the past couple of years, the FDA has released guidance on mobile medical apps – specifically those medical apps the FDA will regulate and those that it won’t, which depends on the app’s function.

What is covered under ePHI?

ePHI, which is also known as electronic protected health information, is protected health information that is produced, saved, transferred or received in an electronic form. This can include USB drives, CD-ROMS, email, apps and VoIP technology. The management of ePHI is covered under the Security Rule.

What steps can companies take to ensure compliance?

One can think of compliance as an inverted triangle – start with a broad base at the top and narrow the focus into different departments and the relevant technical, administrative and physical safeguards set forth in the Security Rule. The top should include forming an enterprise risk management team and conducting an annual, comprehensive risk analysis that every team member reads. From there, understanding the ingress and egress of protected health information, the vulnerabilities and compliance solutions identified in the risk analysis can be addressed.

Are there any National Institute for Standards and Technology (NIST) publications that address privacy, security and mobile apps?

Yes. Two key NIST special publications are SP 800-124, Rev. 1, Managing the Security of Mobile Devices in the Enterprise and SP 800-53, Rev. 5, Security and Privacy Controls for Info Systems and Organizations. Both of these publications provide useful frameworks for achieving compliance to ensure that the confidentiality, integrity and availability of the data is maintained, even on an app.

Rachel V. Rose – Attorney at Law, PLLC (Houston, Texas) – represents clients on healthcare, cybersecurity, securities and qui tam matters. She also teaches bioethics at Baylor College of Medicine. She has been consecutively named by Houstonia Magazine as a Top Lawyer (Healthcare) and to the National Women Trial Lawyer’s Top 25. She can be reached at rvrose@rvrose.com.

Be sure to look up a recording of this webinar on YouTube and be on the lookout for Rachel on our radio program 1st Talk Compliance in September 2019. Take a look at our brand-new book: HIPAA Privacy and Security, and our online compliance training courses such as What is HIPAA?, and HIPAA Business Associate Agreements Under HITECH. And check out Rachel’s other blog Recent HHS Guidance Underscores the Importance of HIPAA Compliance. Come hear Rachel Rose speak live at the HIPAA Privacy and Security Summit, November 14, 2019 at Delaware Law School.

Tags: cyber security, healthcare apps, Security
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2019/08/QA-Rachel-Rose-HIPAA-Health-Apps.jpg 500 800 Catherine Short https://1sthcc.com/wp-content/uploads/2026/07/1stHCC_Logo_HORZ_LRG.png Catherine Short2019-08-14 17:25:522025-04-15 12:47:06Q&A: HIPAA and Health Apps
You might also like
Healthcare Cybersecurity
Business Associates under HIPAA: Compliance Requirements, Liability Considerations, and the Anatomy of a Breach
Data Analytics Podcast Securing Your Data Analytics Program
Top Challenges Healthcare Compliance Be Aware of the Top Challenges of Healthcare Compliance
Surviving an OCR Audit – Lessons Learned
Recent Developments in Health Information Privacy: HIPAA Right of Access

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • The OIG Exclusions List: First Line of Employment Defense
  • Navigating the HIPAA Security Landscape: A Comprehensive Guide to Security Risk Assessments
  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only