HIPAA-Compliant App Development: A Guide for Indian Teams Building for the US
What HIPAA requires from an Indian development team building for US healthcare clients: business associate agreements, the Security Rule safeguards, offshore access and breach duties.

There is no such thing as HIPAA certification for software, and no government body approves an app as compliant. HIPAA is a set of obligations on organisations. An Indian team building for a US hospital, insurer or health-tech company takes on some of those obligations by contract, and has to design both the product and its own working practices accordingly.
Does HIPAA apply to your project?
HIPAA applies to covered entities, meaning healthcare providers, health plans and clearinghouses, and to their business associates, meaning anyone who creates, receives, maintains or transmits protected health information on their behalf. A fitness or wellness app that sells directly to consumers and has no relationship with a covered entity is generally outside HIPAA, though other US laws apply.
The business associate agreement
Before any PHI is shared, the client and vendor sign a business associate agreement, or BAA. It limits how PHI can be used, requires safeguards, sets breach reporting duties and flows down to subcontractors. You also need BAAs with your own vendors that touch PHI, such as the cloud provider. Major cloud platforms sign BAAs, but only for specific eligible services.
No BAA, no PHI. Until the agreement is signed, build and test with synthetic data only.
Security Rule safeguards in the product
The Security Rule groups requirements into administrative, physical and technical safeguards. The technical ones translate into features.
Working from India
HIPAA itself does not prohibit handling PHI outside the United States, but many clients, state Medicaid contracts and some federal programmes do restrict offshore access. Clarify this in the contract. The safest model is that production PHI never leaves US-hosted systems and the Indian team works on de-identified or synthetic data.
Administrative duties
A business associate needs its own compliance programme: a risk analysis, written policies, a security officer, staff training, incident response and documentation retained for six years. Clients will ask for evidence. Independent reports such as SOC 2 or HITRUST are not required by HIPAA but are commonly requested in procurement.
Breach notification and the proposed rule changes
A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery; BAAs usually set a much shorter period. In January 2025 the US Department of Health and Human Services proposed a major update to the Security Rule that would make encryption and multi-factor authentication explicit requirements and add asset inventories, network segmentation and regular testing. Check the HHS site for whether a final rule has been issued and its compliance dates. Building to the proposed standard is prudent in any case.
- US Department of Health and Human Services: HIPAA Security Rule
- US Department of Health and Human Services: Business Associates
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





