Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteEvaluate a health data vendor by tracing what information it handles and why, determining whether it accesses protected health information (PHI) on your behalf, and checking any de-identification claim against the method, dataset, recipients, and supporting documentation. A statement such as “HIPAA compliant” or “de-identified” is not enough to establish how a particular vendor or dataset should be treated.
This U.S.-focused guide turns federal guidance from the Department of Health and Human Services (HHS) and the Federal Trade Commission (FTC), reviewed as of October 7, 2026, into a practical diligence process. The right legal answer depends on the parties, data, service, and jurisdictions involved.
Start by mapping the data and the service
Before reviewing a privacy policy or security questionnaire, establish what the vendor actually does with the information. Follow the data from collection to deletion, including operational access that may not be obvious from a product diagram.
Ask the vendor to identify:
- What information it receives, creates, maintains, or transmits, and where that information comes from.
- Whether each dataset is identifiable, PHI, or claimed to be de-identified—and who made that determination.
- Every purpose for which the vendor uses the information, including service delivery, support, analytics, product improvement, or other secondary uses.
- Which employees, subcontractors, and other recipients can access it, and what each recipient is permitted to do.
- How long information is retained, what happens in backups, and how deletion or return is carried out when the service ends.
Draw the flow through ingestion, processing, support access, analytics, subcontractors, exports, backups, and deletion. Compare that flow with the vendor’s privacy notices, sales materials, consent screens, and contract. HHS recommends examining data sources, uses, recipients, purposes, retention, and safeguards, as well as whether actual practices match consumer-facing statements.
#1 Best Overall
Determine whether the vendor is a HIPAA business associate
HIPAA applies to covered entities and business associates as defined by the rules; a vendor’s label for itself does not decide its role. Ask whether your organization is a covered entity, whether the vendor performs a function or service on its behalf involving PHI, and whether the vendor has access to that PHI to do the work.
HHS says selling or providing software to a covered entity, by itself, does not create a business-associate relationship when the vendor has no access to the covered entity’s PHI. The analysis changes if the service requires access—for example, hosting patient information or accessing it during troubleshooting. Covered entities that engage a business associate generally need a written business-associate contract.
Review whether the agreement addresses the permitted uses and disclosures, safeguards, subcontractors, incident reporting, cooperation, return or destruction of information, and limits on secondary use. The appropriate provisions depend on the actual arrangement and applicable law; a signed agreement does not make an inaccurate data-flow description accurate.
Rank #2
Ask what “de-identified” means in this case
For HIPAA, HHS recognizes two methods of de-identification: Safe Harbor and Expert Determination. Ask which method the vendor uses, which dataset and disclosure it covers, and what evidence supports the claim.
| HIPAA method | What the method requires | What to request from the vendor |
|---|---|---|
| Safe Harbor | Removal of the identifiers specified by the rule, together with satisfaction of the actual-knowledge condition. | A description of how identifiers are removed across the dataset, plus an explanation of how the vendor addresses information it actually knows could identify a person when combined with what remains. |
| Expert Determination | A qualified person applies accepted statistical and scientific principles to find that the risk of identification is very small in the anticipated recipient context, and documents the method and result. | The expert’s relevant experience; the dataset and disclosure scope; the anticipated recipient and reasonably available auxiliary information considered; mitigation steps; and documentation of the analysis and result. |
HHS does not set one universal numerical threshold for “very small” risk under Expert Determination. Context matters: a conclusion for one dataset or recipient should not be assumed to cover a different dataset, recipient, or use. An expert may consider recipient capabilities and other reasonably available data, recommend mitigation, and reassess the resulting dataset; the analysis may take several iterations. Treat a generic certificate as a starting point for questions, not proof that every disclosure is covered.
Check free text, rare details, and linkage risk
Do not limit the review to database columns. HHS says Safe Harbor does not distinguish structured fields from free text: a recognizable identifier must be removed wherever it appears. Clinical notes, derived fields, and narrative descriptions can contain identifying details, while rare events, unusual occupations, or combinations of dates and procedures can make a person recognizable.
Ask how the vendor finds identifiers in structured records, free-text notes, and derived data, and what review is used to detect unusual or identifying combinations. Ask whether it suppresses or generalizes details, restricts access, or imposes recipient controls when needed to reduce residual risk.
De-identification does not mean zero risk. HHS states that data handled under either HIPAA method can retain some possibility of linkage to a patient. Ask whether a linkage key or other re-identification means exists, who can access it, and whether it is disclosed. HHS discusses circumstances in which a derived code may be used under Expert Determination if the re-identification key is not disclosed. A data use agreement can add safeguards, but it does not replace the technical and documentation requirements of either HIPAA method.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Review claims, safeguards, and incident handling
Check whether the vendor’s public and contractual statements match its practices. HHS warns against misleading claims such as “HIPAA Certified” and recommends clear, conspicuous disclosures rather than burying important information. Ask for a plain-language account of collection, use, retention, sharing, and deletion, then compare it with the data flow and contract.
Rank #4
For the safeguards relevant to the service, ask how the vendor handles:
- Risk assessment and management.
- Access controls, workforce training, and audit controls.
- Incident response and contingency planning.
- Encryption practices for electronic PHI.
- Subcontractor access and oversight.
These are examples of safeguards identified in HHS guidance on the HIPAA Security Rule for electronic PHI; the questions should be tailored to the service and the parties’ obligations.
Get the incident process in writing. Clarify who detects and reports an incident, what information the vendor must provide, how the parties cooperate, and the notice deadline under the contract. Under HIPAA, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Covered entities have their own notification duties, and regulated parties must document relevant matters. The FTC Health Breach Notification Rule may impose separate duties on certain covered non-HIPAA businesses, including some personal health record vendors and related entities.
Best Value
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notaries Public' confidential information
- GLBA and HIPAA require strict confidentiality policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
Do not assume HIPAA is the only applicable rule
A vendor may handle health information without being a HIPAA covered entity or business associate. HHS identifies FTC Act obligations for companies handling health information, including companies outside HIPAA, and identifies the FTC Health Breach Notification Rule as applying to certain personal health record vendors and related entities. Which rules apply depends on the company, information, service, and circumstances.
State privacy laws, international rules, research requirements, contractual commitments, and sector-specific restrictions may also apply. A federal HIPAA analysis alone cannot resolve those questions. Have qualified counsel review the actual arrangement where the consequences or uncertainty warrant it.
Compare vendors on evidence, not slogans
Use the same questions and evidence requests for each candidate so that differences are visible. The following comparison dimensions synthesize HHS guidance; they are not an official scoring rubric.
| Comparison area | Evidence to compare |
|---|---|
| Legal role and PHI access | Vendor functions, actual access, and whether the proposed relationship requires a business-associate contract. |
| Data use and retention | Data minimization, stated purposes, onward sharing, retention, and deletion practices. |
| De-identification | Method, dataset and recipient scope, documentation, and treatment of residual risk. |
| Unstructured and unusual records | How free text, rare events, and combinations of details are reviewed and mitigated. |
| Security and operations | Safeguards, access logging, incident readiness, and subcontractor controls. |
| Contracts and transparency | Contract protections and consistency between public claims, actual practices, and contractual commitments. |
Prefer answers tied to the specific service and disclosure over broad assurances. If a vendor cannot explain its data flows, identify its role, or substantiate a de-identification claim for the intended recipient and use, treat that uncertainty as a procurement issue to resolve before sharing data.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

