AI AUTOMATION • REAL ENGINEERING • YOU OWN IT

Compliance Framework

HIPAA (Health Insurance Portability and Accountability Act)

The US federal law governing how healthcare providers, insurers, and their vendors handle Protected Health Information (PHI).

Who it applies to

US healthcare providers and insurers ('covered entities') directly, and any vendor or software provider handling PHI on their behalf ('business associates') — including software Vajra might build for a healthcare client.

What it requires

  • Administrative, physical, and technical safeguards around PHI — access controls, audit logs, encryption in transit and at rest
  • A signed Business Associate Agreement (BAA) between a covered entity and any vendor that touches PHI
  • Breach notification procedures for any exposure of PHI
  • Minimum-necessary access — systems and staff only see the PHI actually required for their function

How we approach it

For any project touching PHI, we scope the BAA requirement explicitly at the start, design access control around minimum-necessary from day one rather than retrofitting it, and treat audit logging as a core requirement, not an optional add-on. We don't issue HIPAA certification — there isn't a formal one; compliance is an ongoing operational posture we help build the technical half of.

FAQs

Can you build software for a healthcare client if we're not a hospital ourselves?

Yes — HIPAA obligations follow the data (PHI), not the type of company. If your software touches PHI on behalf of a covered entity, you're likely a business associate under HIPAA regardless of your own industry, and the BAA and safeguards apply.

Have a project in mind?

Tell us what you're trying to automate or build — we'll reply with next steps, not a sales pitch.