menu
close_24px

HIPAA

HIPAA is the Health Insurance Portability and Accountability Act of 1996. Its Privacy Rule and Security Rule set the U.S. standard for protecting health information, called protected health information, or PHI, and its electronic form, ePHI.

Most people picture HIPAA as a hospital problem. For a growing share of covered entities, it's a mobile app problem instead. Patient portals, telehealth, prescription management, and remote monitoring now run through a phone before they touch anything else.

Who HIPAA actually covers

HIPAA doesn't cover every organization that touches health data. It applies to covered entities, healthcare providers, health plans, and healthcare clearinghouses, and to their business associates, anyone who handles PHI on a covered entity's behalf.

That distinction matters more than it sounds like it should.

A direct-to-consumer fitness or wellness app that collects health-adjacent data, but has no connection to a doctor, hospital, or insurer, usually isn't a HIPAA covered entity at all. It may still owe users protection under the FTC's Health Breach Notification Rule or state privacy law, just not HIPAA specifically. Confusing the two is one of the most common mistakes in this space.

The Privacy Rule and the Security Rule

These do different jobs.
The Privacy Rule governs how PHI can be used and disclosed, and gives individuals rights over their own records: access, amendment, and an accounting of who's seen them.

The Security Rule is narrower and more technical.
It applies specifically to ePHI and requires administrative, physical, and technical safeguards, access controls, audit logs, encryption, and integrity controls that catch data being altered or destroyed without detection.

Penalties, and a number that needs context

Civil penalties currently range from $145 to $2,190,294 per violation, adjusted for inflation each year, most recently on January 28, 2026.

That top figure gets repeated as if it applies broadly. It doesn't, in practice.

Since 2019, the OCR has applied its own enforcement discretion to cap annual penalties for the three lesser tiers, unknowing, reasonable cause, and corrected willful neglect, at $25,000, $100,000, and $250,000, respectively. Only the worst tier, willful neglect left uncorrected, can reach the full statutory cap.

Why it matters for mobile

A health app on a phone creates HIPAA exposure that a desktop system usually doesn't:

  • Local storage on a device the organization doesn't control.
  • A lock screen instead of a managed workstation.
  • Background network calls to third-party analytics or crash-reporting SDKs that were never vetted for what data they actually see.

None of that is hypothetical. It's the same territory Security Rule audits already probe: access control, encryption at rest, audit logging, and whether ePHI leaves the app in ways nobody signed off on.

Where Appknox fits

Appknox tests mobile apps for the technical safeguards the Security Rule actually requires:

  • Whether ePHI is encrypted at rest and in transit,
  • Whether access controls hold up under real testing, and
  • Whether a third-party SDK is quietly exposing data the app's own privacy policy doesn't disclose.

Findings map to HIPAA automatically, alongside Appknox's other compliance mappings. So a covered entity's compliance team gets evidence tied to a specific requirement rather than a generic scan report.

See Appknox's compliance frameworks: Compliance at Appknox


Check out the full testing methodology: Appknox Automated Vulnerability Assessment.

Frequently asked questions

What does HIPAA stand for?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996, the U.S. law governing how protected health information is used, disclosed, and secured.

Does HIPAA apply to every health app?

No. It applies to covered entities, providers, health plans, clearinghouses, and their business associates. A consumer health or wellness app with no connection to a covered entity usually isn't HIPAA-covered, though it may still owe users protection under rules like the FTC's Health Breach Notification Rule.

What's the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs how PHI can be used and disclosed, and gives individuals rights over their records. The Security Rule is narrower, covering only electronic PHI, and requires specific technical, physical, and administrative safeguards.

How much can a HIPAA violation cost?

Civil penalties range from $145 to $2,190,294 per violation as of the 2026 inflation adjustment. In practice, OCR caps annual penalties for all but the worst violation tier well below that maximum.

Does Appknox test for HIPAA compliance?

Appknox tests mobile apps for the technical safeguards HIPAA's Security Rule requires: encryption, access control, and third-party data exposure, and maps findings to HIPAA automatically.

Related: What is GDPR? | What is DORA? | Appknox Automated Vulnerability Assessment

By Aadarsh Anand, Security Researcher, Appknox Security Research Team

Appknox is an enterprise mobile application security testing platform. This page was written by Appknox's security research team based on direct experience testing mobile health apps for HIPAA-covered entities and their business associates.

This page was drafted with AI assistance and reviewed and verified by the Appknox security research team.