Hello,
\nI’m not sure if I need to be HIPAA compliant in the following situation:<\/p>\n
There is a clinic in the USA (a covered entity), and I will be providing them with pseudonymized data<\/em>—meaning the data I share does not contain identifiable patient information, and only the clinic can match the pseudonyms to actual individuals using their internal system.<\/p>\n
I will not have access to any Protected Health Information (PHI) myself—only pseudonymized data. In this case, do I still need to sign a Business Associate Agreement (BAA) and comply with all HIPAA requirements?<\/p>","upvoteCount":4,"answerCount":7,"datePublished":"2025-04-21T17:11:04.261Z","author":{"@type":"Person","name":"ssp2102","url":"https://community.spiceworks.com/u/ssp2102"},"suggestedAnswer":[{"@type":"Answer","text":" Hello, There is a clinic in the USA (a covered entity), and I will be providing them with pseudonymized data<\/em>—meaning the data I share does not contain identifiable patient information, and only the clinic can match the pseudonyms to actual individuals using their internal system.<\/p>\n I will not have access to any Protected Health Information (PHI) myself—only pseudonymized data. In this case, do I still need to sign a Business Associate Agreement (BAA) and comply with all HIPAA requirements?<\/p>","upvoteCount":4,"datePublished":"2025-04-21T17:11:04.535Z","url":"https://community.spiceworks.com/t/do-i-need-hipaa-compliance-for-pseudonymized-data/1198217/1","author":{"@type":"Person","name":"ssp2102","url":"https://community.spiceworks.com/u/ssp2102"}},{"@type":"Answer","text":" Short answer should be no, nor will you need to sign a BAA.<\/p>\n However, the longer answer is, confirm with the company and their security team they are happy with this too.<\/p>\n So long as you do not have the client data and the data you do have doesn’t directly get you this data (but it does the client), then this should be ok.<\/p>\n I am no HIPAA/PHI expert though.<\/p>","upvoteCount":3,"datePublished":"2025-04-21T17:41:41.254Z","url":"https://community.spiceworks.com/t/do-i-need-hipaa-compliance-for-pseudonymized-data/1198217/2","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":" You shouldn’t have to, but to cover yourself and them I would say sign one just incase.<\/p>","upvoteCount":2,"datePublished":"2025-04-21T18:20:39.280Z","url":"https://community.spiceworks.com/t/do-i-need-hipaa-compliance-for-pseudonymized-data/1198217/4","author":{"@type":"Person","name":"Greg-Starnes","url":"https://community.spiceworks.com/u/Greg-Starnes"}},{"@type":"Answer","text":"
\nI’m not sure if I need to be HIPAA compliant in the following situation:<\/p>\n