HIPAA Requirements for File Sharing
Understanding what the law actually requires when you share Protected Health Information electronically.
What Counts as PHI
Protected Health Information (PHI) is any individually identifiable health information held or transmitted by a covered entity or business associate. In billing, this includes:
- Patient names, dates of birth, Social Security numbers
- Insurance ID numbers and policy details
- Diagnosis codes (ICD-10) and procedure codes (CPT)
- Explanation of Benefits (EOBs) and remittance advice
- Claims data, billing records, and account numbers
- Any document that links health information to an individual
HIPAA Security Rule Technical Safeguards
The Security Rule (45 CFR Part 164) mandates specific technical safeguards for any system that stores, processes, or transmits electronic PHI (ePHI):
- Encryption & decryption of ePHI at rest
- Access controls with unique user identification
- Audit controls logging all ePHI access
- Transmission security for data in transit
- Integrity controls to prevent unauthorized alteration
- Automatic logoff and session management
Penalties for Violations
The HHS Office for Civil Rights (OCR) enforces HIPAA with a tiered penalty structure:
Annual maximum of $1.5 million per identical provision. State attorneys general can pursue additional penalties. Criminal penalties apply for knowing violations.
Business Associate Agreements
If you're a healthcare billing company or RCM firm, you are a Business Associate under HIPAA. This means:
- You must sign a BAA with every covered entity you serve
- Any subcontractor or vendor handling PHI on your behalf also needs a BAA
- Your file sharing tools are part of this chain -- no BAA means no compliance
- You are directly liable for breaches under the HITECH Act
Common HIPAA Violations in File Sharing
These happen every day in billing offices. Each one is a reportable breach waiting to happen.
Emailing EOBs and Claims with PHI
Standard email is unencrypted in transit and stored indefinitely on mail servers. Sending Explanation of Benefits, claims data, or patient identifiers via email violates the Transmission Security standard.
Consumer Cloud Tools Without BAAs
Google Drive, Dropbox, and WeTransfer are not HIPAA-compliant out of the box. Using them without a signed Business Associate Agreement exposes your organization to breach liability.
No Encryption at Rest
Storing claims files, patient records, or billing data on unencrypted drives or servers violates the Encryption and Decryption implementation specification under the Security Rule.
No Audit Trail of Access
HIPAA requires audit controls that record who accessed PHI, when, and what they did. Sharing files without logging access events is a direct violation of 45 CFR 164.312(b).
What HIPAA-Compliant File Sharing Requires
Any tool you use to share PHI must meet these technical requirements at a minimum.
AES-256 encryption at rest
All PHI must be encrypted when stored, using NIST-approved algorithms.
TLS 1.2+ encryption in transit
Data transmitted over networks must be protected with transport layer security.
Role-based access controls
Only authorized personnel should access PHI, with unique user identification.
Comprehensive audit logging
Every access, modification, and transmission of PHI must be logged and reviewable.
Automatic data destruction
PHI should not persist beyond its required retention period. Disposal must be verifiable.
Business Associate Agreement (BAA)
Any third-party service handling PHI must sign a BAA accepting HIPAA obligations.
How DeadVault Meets These Requirements
A direct mapping of HIPAA Technical Safeguards to DeadVault's architecture.
Encryption & Decryption (164.312(a)(2)(iv))
Encrypt ePHI at rest
AES-256-GCM encryption with per-file keys. Each file gets its own encryption key, wrapped with a master key and stored separately from file data.
Transmission Security (164.312(e)(1))
Protect ePHI in transit
All data transmitted over TLS 1.2+. Secure links for client access with no unencrypted fallback.
Access Controls (164.312(a)(1))
Limit ePHI access to authorized users
Unique secure links per recipient. Optional PIN protection for two-factor file access. No shared credentials.
Audit Controls (164.312(b))
Record ePHI access activity
Complete audit trail with timestamps, IP addresses, and access events. Export-ready logs for compliance reviews and breach investigations.
Integrity Controls (164.312(c)(1))
Protect ePHI from unauthorized alteration
AES-256-GCM provides authenticated encryption, detecting any tampering with file data. Immutable audit logs prevent retroactive changes.
Automatic Logoff / Disposal
Terminate sessions and dispose of ePHI
Cryptographic erasure at deadline: encryption keys are permanently destroyed, rendering file data mathematically unrecoverable. Nothing lingers.
About BAAs and HIPAA Compliance
HIPAA compliance is an organizational process, not a product certification -- there is no such thing as "HIPAA certified." DeadVault's architecture aligns with HIPAA Technical Safeguard requirements. Business Associate Agreements (BAAs) are available on our Enterprise plan for covered entities and business associates that require them as part of their compliance program.
Frequently Asked Questions
Common questions about HIPAA-compliant file sharing for billing and RCM.