HIPAA
Last reviewed: 2026-09-26
HIPAA review starts with the organisation's role and the information handled. A business associate agreement addresses a particular service relationship. Masking identifiers and signing an agreement do not, by themselves, establish that a workflow meets HIPAA requirements.
PHI Mask and your HIPAA review
PHI Mask is HIPAA-compatible. Your file is masked in your browser and never sent to us, so there is no BAA to sign, and without a signed BAA we cannot claim HIPAA compliance.
This describes PHI Mask's browser workflow. Assess the service receiving your masked copy separately, including its purposes, settings, agreements and storage locations.
Determine who handles protected health information
Identify the covered entity, business associates and workforce involved in the task. A business associate can create, receive, maintain or transmit PHI on behalf of a covered entity.
Assess each provider from its actual service and access to PHI. Include the AI service that receives the copy, not only the software used to prepare it.
Separate masking from formal de-identification
HIPAA provides two de-identification methods: Safe Harbor and Expert Determination. Replacing visible names or applying reversible placeholders does not establish that either method has been satisfied.
If the proposed disclosure relies on de-identification, document the method and its requirements. Remaining context, dates and other identifying information matter to that decision.
Include local records in the security review
The Security Rule risk analysis addresses the electronic PHI an organisation creates, receives, maintains or transmits. Assess the relevant browser records and workstations alongside hosted services.
Record access controls, retention and deletion, staff procedures, incident handling and actions for the risks found.