homeopathy.software

HIPAA for homeopaths — a practical guide

referenceBy Editorial Board· Published

Whether HIPAA applies to a homeopath turns on role, not job title. The U.S. Health Insurance Portability and Accountability Act binds three classes of covered entity defined at 45 CFR 160.103 — health plans, health-care clearinghouses, and health-care providers who transmit health information electronically in connection with a HIPAA standard transaction such as claims, eligibility, or remittance. A cash-only practitioner who never bills electronically and never files a standard transaction sits outside HIPAA's reach. The moment a practice submits an electronic claim, or works under a covered clinic, it is in scope.

The three rules a clinic must satisfy

RuleCitationWhat it requires
Privacy Rule45 CFR 164 Subparts A & ELimits use and disclosure of protected health information (PHI); grants patients access, amendment, and accounting rights
Security Rule45 CFR 164 Subparts A & CAdministrative, physical, and technical safeguards for electronic PHI — access control, audit controls, encryption, integrity
Breach Notification Rule45 CFR 164 Subparts A & DNotice to affected individuals, HHS, and (at scale) media within 60 days of discovering a breach

The Security Rule is where software choices bite. Its technical-safeguards section at 45 CFR 164.312 names access control, audit controls, integrity, person-or-entity authentication, and transmission security. Encryption is an "addressable" specification: a clinic must implement it or document why an equivalent measure is reasonable.

Business associate agreements are non-optional

When a clinic lets a vendor create, receive, maintain, or transmit PHI on its behalf, that vendor is a business associate, and 45 CFR 164.308(b) and 164.504(e) require a written business associate agreement (BAA) before any PHI changes hands. A cloud case-management host, a transcription provider, and an AI processor that touches case notes are all business associates. The clinic stays liable; the BAA pushes contractual obligations down the chain.

"HIPAA-ready" on a vendor page describes vendor capability, not the clinic's legal posture. Compliance is achieved only when a signed BAA, a documented risk analysis, and workforce policies are all in place. When a platform advertises TLS 1.3 in transit, AES-256 at rest, signed BAAs with AI subprocessors, and zero-retention processing for covered AI data — as Similia does in its public security documentation — treat those as inputs to your own risk analysis, not a substitute for it.

Verification checklist

  • Confirm covered-entity status against 45 CFR 160.103. Electronic billing usually means in scope.
  • Obtain a signed BAA from every vendor that touches PHI, including AI subprocessors and any transcription, hosting, or analytics layer.
  • Verify encryption in transit and at rest, and that audit logs and access controls exist per 45 CFR 164.312.
  • Document a Security Rule risk analysis and a breach-response plan keyed to the 60-day notification clock.
  • Check data export and deletion paths so the practice, not the vendor, controls the record.

HIPAA exposure turns on specific facts. Verify your obligations and any vendor's representations with the vendor directly and with your own counsel before storing a case on a new platform.

References

U.S. Department of Health and Human Services (2013) HIPAA Administrative Simplification, 45 CFR Part 160, §160.103 (definitions of covered entity and business associate), https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160.

U.S. Department of Health and Human Services (2013) Standards for Privacy of Individually Identifiable Health Information (Privacy Rule), 45 CFR Part 164 Subparts A and E, including §164.504(e), https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164.

U.S. Department of Health and Human Services (2013) Security Standards for the Protection of Electronic Protected Health Information (Security Rule), 45 CFR Part 164 Subparts A and C, §§164.308(b), 164.312, https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C.

U.S. Department of Health and Human Services (2013) Notification in the Case of Breach of Unsecured Protected Health Information, 45 CFR Part 164 Subpart D, https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D.

Similia (2026) "Is my patient data secure?", Similia Help Centre, https://similia.crisp.help/en/article/is-my-patient-data-secure-sxmdfd/, fetched 2026-04-22.

Verdict

Ready to act on this?