What is HIPAA (Health Data Privacy)?

HIPAA (Health Insurance Portability and Accountability Act) is a U.S. law that sets rules for protecting people’s personal health information. Organisations that create, store or transmit protected health information (PHI) must follow privacy, security and breach-notification requirements under HIPAA.

HIPAA is a federal law in the United States that governs how certain types of health information are handled. It applies to 'covered entities' (health plans, healthcare providers who bill electronically, and healthcare clearinghouses) and their 'business associates' (vendors that store, process or transmit PHI on their behalf). Key parts of HIPAA include the Privacy Rule (who may access and share PHI), the Security Rule (technical and organisational safeguards such as encryption, access controls and audit logging), and the Breach Notification Rule (requirements to notify individuals and authorities after unauthorized disclosures). Data that is properly de-identified is not treated as PHI under HIPAA.

Usage example

We plan to run a patient intake survey that asks about medical history and medications. Because the responses include PHI from U.S. residents, we must treat the survey and its responses as HIPAA-regulated data — using secure storage, access controls, and a vendor that will sign a Business Associate Agreement (BAA).

Practical application

For people running surveys and forms, HIPAA matters when questions or answers collect health-related details that can identify a person (names, contact info, diagnoses, treatment details, etc.). Practical steps include: avoid collecting PHI unless necessary; de-identify data when possible; require a signed BAA from any vendor that will handle PHI; ensure encryption in transit and at rest; use role-based access and audit logs; provide participant consent and privacy notices in the participant’s preferred language; and have policies for retention and breach response. If your survey uses machine translation or external APIs, confirm how those services process data and whether they meet HIPAA requirements. Always consult your organisation’s legal or compliance team for specific obligations.

FAQ

When does HIPAA apply to my survey?

HIPAA applies if your survey collects or stores protected health information (PHI) about U.S. individuals and you are a covered entity or a business associate of one. If your survey only collects non-identifying feedback or you are not a covered entity, HIPAA may not apply — but other privacy laws might. Check with your compliance or legal team.

What counts as PHI in a survey?

PHI includes health information tied to an identifiable person — for example: names, contact details, dates (birth, admission), medical conditions, treatment, medications, or identifiers like Social Security numbers. Even free-text answers that reveal identity can be PHI.

Can I use machine translation for responses that contain PHI?

Using machine translation can be permitted only if the translation service and data handling meet HIPAA requirements and you have appropriate agreements (like a BAA) in place. If the translation service routes data through third-party processors that are not covered by a BAA, that can create compliance risk. When in doubt, avoid sending PHI to unapproved translation systems or de-identify text first.

What immediate steps should I take to make a survey HIPAA-compliant?

Limit PHI collection to what's essential, de-identify answers when possible, require a BAA from any vendor handling PHI, enable encryption and access controls, keep audit logs, provide clear consent/privacy notices (in participants’ languages), and have a documented breach response plan. Work with legal/compliance to confirm these measures meet your obligations.