{"id":22861,"date":"2026-05-15T12:46:52","date_gmt":"2026-05-15T12:46:52","guid":{"rendered":"https:\/\/engineerbabu.com\/blog\/?p=22861"},"modified":"2026-09-02T04:10:22","modified_gmt":"2026-09-02T04:10:22","slug":"build-a-hipaa-compliant-app-in-the-usa","status":"publish","type":"post","link":"https:\/\/engineerbabu.com\/blog\/build-a-hipaa-compliant-app-in-the-usa\/","title":{"rendered":"How to Build a HIPAA Compliant App in the USA: The Builder&#8217;s Guide (2026)"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Nobody fails a HIPAA audit. There is no examiner who shows up, reviews your code, and stamps your app approved.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What actually happens is quieter. A phone goes missing, a storage bucket gets misconfigured, and nine weeks later the Office for Civil Rights asks for your risk analysis. If you cannot produce one, that is the finding.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is where most founders get caught. They treat compliance as a checklist for the week before launch. In practice, the choices that let you build a HIPAA compliant app in the USA get made before the first sprint.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The stakes are not theoretical. Healthcare breaches averaged $6.64 million in 2026. That is the costliest of any industry for the thirteenth year running, per<\/span><a href=\"https:\/\/www.hipaajournal.com\/2026-cost-data-breach-study-ibm\/\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">IBM&#8217;s Cost of a Data Breach Report 2026<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So here is what it really takes to build a HIPAA compliant app in the USA, decision by decision.<\/span><\/p>\n<h2><b>What HIPAA Actually Requires From Your Product<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">HIPAA is not a technical specification. Three rules shape everything you do to build a HIPAA compliant app in the USA.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>The Privacy Rule<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This governs who may see protected health information and why. In product terms, it means consent capture, patient access and export, and a record of every disclosure you make.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>The Security Rule<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This is the one your engineers live inside. It splits safeguards into administrative, physical, and technical categories.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Some specifications are labeled &#8220;required&#8221; and some &#8220;addressable.&#8221; Addressable does not mean optional. It means you implement the control or document a reasonable alternative that achieves the same result.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>The Breach Notification Rule<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This sets your clock. Breaches affecting 500 or more people require notice to individuals, HHS, and the media within 60 days. Smaller incidents get logged and reported annually.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>PHI vs. Health Data<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">A step counter is not regulated. PHI is identifiable health information that you create, receive, or store on behalf of a covered entity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are 18 identifiers, and the ones teams forget are IP addresses, device IDs, full-face photos, and appointment dates. If your logs capture those alongside a diagnosis, your logs now hold PHI.<\/span><\/p>\n<h2><b>First, Decide What You Are: Covered Entity or Business Associate<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Your role is the first thing to settle before you build a HIPAA compliant app in the USA. Most digital health startups are business associates. You handle PHI on behalf of a clinic, hospital, payer, or lab, which means their compliance obligations flow down to you through a contract.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Covered entities are providers, health plans, and clearinghouses that bill for care directly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Get this wrong and every downstream decision drifts. Your role determines who signs a<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/what-is-hipaa-baa-healthcare-apps-usa\/\"> <span style=\"font-weight: 400;\">business associate agreement<\/span><\/a><span style=\"font-weight: 400;\"> with you, what you must report, and how fast.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Direct-to-consumer wellness apps sometimes sit outside HIPAA entirely. They still fall under the FTC Health Breach Notification Rule, so &#8220;not HIPAA&#8221; never means &#8220;unregulated.&#8221;<\/span><\/p>\n<h2><b>How to Build a HIPAA Compliant App in the USA: Step by Step<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The order here matters. Steps taken out of sequence create rework that costs real money.<\/span><\/p>\n<h3><b>Step 1: Map Every Place PHI Touches Your System<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The first real task when you build a HIPAA compliant app in the USA is drawing the data flow. Every field, every hop, every log line.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">List where PHI enters, where it rests, which services read it, and where it leaves. Include the unglamorous paths: error monitoring, analytics events, push notification payloads, customer support tools, CSV exports, and database backups.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Most compliance failures I have seen came from a path nobody drew. Sentry captured a stack trace with a patient name. A push notification showed a lab result on a lock screen.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Finish this map first. It becomes the reference for every safeguard you build next.<\/span><\/p>\n<h3><b>Step 2: Lock Down Infrastructure and Vendors That Will Sign a BAA<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Every vendor that touches PHI needs a signed BAA before launch. That covers your cloud provider, database host, email service, SMS gateway, and error tracker. This is the least negotiable part of how you build a HIPAA compliant app in the USA.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AWS, Google Cloud, and Azure all offer BAAs, but only across a defined list of eligible services. Using a non-eligible service inside your PHI boundary voids the protection.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check the same for your storage layer, since<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/hipaa-compliant-cloud-storage-healthcare-apps\/\"> <span style=\"font-weight: 400;\">HIPAA compliant cloud storage<\/span><\/a><span style=\"font-weight: 400;\"> has specific configuration requirements. If PHI will ever reach a model, confirm<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/llms-under-baa\/\"> <span style=\"font-weight: 400;\">which LLMs are available under a BAA<\/span><\/a><span style=\"font-weight: 400;\"> first.<\/span><\/p>\n<h3><b>Step 3: Build Access Control Around Minimum Necessary<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Role-based access is the baseline, not the finish line. The standard is minimum necessary, meaning each user sees only the PHI their job requires.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Practically, that means unique user IDs with no shared logins, mandatory multi-factor authentication, automatic session timeouts, and emergency access procedures for clinical situations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Build row-level or record-level authorization, not just screen-level. A nurse in one facility should not be able to change a URL parameter and pull a chart from another.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Then add automatic account deprovisioning. Orphaned accounts from departed staff show up in OCR findings constantly.<\/span><\/p>\n<h3><b>Step 4: Encrypt in Transit, at Rest, and on the Device<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Encryption is technically addressable, but skipping it is indefensible when you build a HIPAA compliant app in the USA. Encrypted PHI also qualifies for breach notification safe harbor, which is the single most valuable protection you can buy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Use TLS 1.2 or higher for transport with certificate pinning on mobile clients. Encrypt at rest with AES-256 and manage keys in a dedicated KMS, rotated on a schedule.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On-device storage deserves its own attention during<\/span><a href=\"https:\/\/engineerbabu.com\/services\/mobile-app-development\"> <span style=\"font-weight: 400;\">mobile app development<\/span><\/a><span style=\"font-weight: 400;\">. Use iOS Keychain and Android Keystore, block screenshots on PHI screens, and never cache PHI in plaintext.<\/span><\/p>\n<h3><b>Step 5: Design Your APIs So They Cannot Overshare<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Your API layer is where PHI leaks quietly. A generic endpoint that returns a full patient object gives every client more data than it needs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Scope responses to the caller&#8217;s role. Use short-lived tokens, enforce rate limits, and reject requests that ask for wider date ranges or larger record sets than the workflow justifies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Careful<\/span><a href=\"https:\/\/engineerbabu.com\/services\/api-development\"> <span style=\"font-weight: 400;\">API development<\/span><\/a><span style=\"font-weight: 400;\"> also means versioning without breaking authorization logic. If you exchange clinical data with providers, plan for<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/fhir-r4-integration-for-healthcare-startups\/\"> <span style=\"font-weight: 400;\">FHIR R4 integration<\/span><\/a><span style=\"font-weight: 400;\"> early, because retrofitting standards later is painful.<\/span><\/p>\n<h3><b>Step 6: Make Audit Logging a Real Feature<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The Security Rule requires you to record and examine activity in systems holding PHI. That means logging every create, read, update, delete, export, and failed login.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Each entry needs a user ID, timestamp, action, record identifier, and source IP. Store logs in append-only storage, separate from the application database, and retain them for six years.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Then make them queryable. When an investigator asks who viewed a specific record last March, a grep across raw files will not save you.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Add anomaly alerts for bulk exports and after-hours access patterns.<\/span><\/p>\n<h3><b>Step 7: Run the Risk Analysis and Write the Policies<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Teams that build a HIPAA compliant app in the USA skip this step constantly, and it is the one OCR asks about first. A security risk analysis is a documented review of every threat to PHI in your environment, with your chosen mitigations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Repeat it annually and after any material architecture change. Pair it with written policies covering incident response, sanctions, workforce training, contingency planning, and device management.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Then test adversarially. Run a third-party penetration test, attempt privilege escalation, and rehearse a breach notification in a tabletop exercise before you need it.<\/span><\/p>\n<h2><b>The Safeguards Teams Consistently Underbuild<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">These are the gaps that appear again and again when teams build a HIPAA compliant app in the USA on a compressed timeline.<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Safeguard<\/b><\/td>\n<td><b>What regulators expect<\/b><\/td>\n<td><b>The shortcut that fails<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Audit controls<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Queryable, tamper-resistant PHI access logs<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Application logs with 30-day retention<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Backup and recovery<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Encrypted, tested restores with an RTO<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Automated snapshots nobody has restored<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Workforce training<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Documented, role-specific, repeated annually<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A slide deck sent once at onboarding<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Device management<\/span><\/td>\n<td><span style=\"font-weight: 400;\">MDM, remote wipe, full-disk encryption<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Trusting staff to secure personal laptops<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Vendor oversight<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Signed BAAs plus periodic review<\/span><\/td>\n<td><span style=\"font-weight: 400;\">A BAA signed in 2023 and never revisited<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">De-identification<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Safe Harbor or expert determination<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Deleting names and calling it anonymous<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><b>Where AI Fits Without Breaking Compliance<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">AI features are the newest way to leak PHI when you build a HIPAA compliant app in the USA. A summarization call to an endpoint without a BAA is an impermissible disclosure, even if the output never reaches a user.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Keep the PHI boundary explicit. Route model calls through your own backend, log every prompt and response as PHI, and de-identify inputs wherever the feature still works without identifiers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Responsible<\/span><a href=\"https:\/\/engineerbabu.com\/services\/ai-development\"> <span style=\"font-weight: 400;\">AI development<\/span><\/a><span style=\"font-weight: 400;\"> in healthcare also means human review on anything clinical. If you train custom models, treat<\/span><a href=\"https:\/\/engineerbabu.com\/technologies\/machine-learning-development-services\"> <span style=\"font-weight: 400;\">ML development<\/span><\/a><span style=\"font-weight: 400;\"> datasets as PHI until formally de-identified.<\/span><\/p>\n<h2><b>Beyond HIPAA: What Buyers Will Actually Ask For<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">HIPAA is the legal floor. Buyers checking whether you can build a HIPAA compliant app in the USA rarely stop there.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Expect a security questionnaire, and expect SOC 2 Type II to come up in the first serious enterprise conversation. Health systems increasingly ask about HITRUST too, which is heavier and more expensive.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If enterprise sales is your plan, read up on<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/hitrust-vs-soc-2-type-ii-for-digital-health\/\"> <span style=\"font-weight: 400;\">HITRUST vs. SOC 2 Type II<\/span><\/a><span style=\"font-weight: 400;\"> before you commit budget to either. Sequencing matters more than badge collecting.<\/span><\/p>\n<h2><b>What It Costs to Build a HIPAA Compliant App in the USA<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The cost to build a HIPAA compliant app in the USA is not a line item you can strip out. Compliance adds 15% to 25% over a comparable build.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A HIPAA-ready MVP with one integration and a clean audit trail generally runs $60,000 to $120,000. A full platform with EHR connectivity, multi-role access, and clinical workflows lands between $150,000 and $400,000.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Then there is the recurring side. Penetration testing runs $8,000 to $25,000 a year. A SOC 2 Type II audit adds $20,000 to $50,000. Compliance automation tooling costs another $6,000 to $18,000 annually.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Scoping a narrow<\/span><a href=\"https:\/\/engineerbabu.com\/services\/mvp-development\"> <span style=\"font-weight: 400;\">MVP development<\/span><\/a><span style=\"font-weight: 400;\"> cycle first keeps the compliance surface small while you validate demand. It is also worth knowing the<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/hidden-costs-in-healthcare-app-development\/\"> <span style=\"font-weight: 400;\">hidden costs in healthcare app development<\/span><\/a><span style=\"font-weight: 400;\"> before you sign a fixed-bid contract.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Timeline runs 4 to 7 months for an MVP. BAA negotiations and risk analysis add weeks that founders rarely budget for.<\/span><\/p>\n<h2><b>Mistakes That Turn Into Breach Reports<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Each of these has shown up in real enforcement actions against teams who build a HIPAA compliant app in the USA.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>PHI in third-party analytics.<\/b><span style=\"font-weight: 400;\"> Marketing pixels on authenticated pages have triggered multiple OCR enforcement actions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Test data pulled from production.<\/b><span style=\"font-weight: 400;\"> Real patient records in a staging environment are a reportable breach waiting to happen.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>No BAA with a subprocessor.<\/b><span style=\"font-weight: 400;\"> Your vendor&#8217;s vendor is still inside your boundary.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Logs that capture request bodies.<\/b><span style=\"font-weight: 400;\"> Debug logging is the most common accidental PHI store.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Treating compliance as one-time.<\/b><span style=\"font-weight: 400;\"> Risk analysis is annual, training is annual, and BAAs need review.<\/span><\/li>\n<\/ul>\n<h2><b>Choosing a Partner Who Has Shipped in Regulated Markets<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A team that has never handled PHI will quote low, then bill you for rework. Ask for proof they have helped someone build a HIPAA compliant app in the USA, and ask who owns the risk analysis.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Two questions cut through most sales calls. First, show me your audit log schema. Second, walk me through your last breach tabletop exercise.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When you compare<\/span><a href=\"https:\/\/engineerbabu.com\/blog\/mobile-app-development-companies-in-the-usa\/\"> <span style=\"font-weight: 400;\">mobile app development companies in the USA<\/span><\/a><span style=\"font-weight: 400;\">, weight regulated-industry depth heavily. The same discipline that makes a<\/span><a href=\"https:\/\/engineerbabu.com\/industries\/fintech\/app-development-company\"> <span style=\"font-weight: 400;\">fintech app development company<\/span><\/a><span style=\"font-weight: 400;\"> reliable is what you need here.<\/span><\/p>\n<h2><b>Final Thoughts<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The teams that build a HIPAA compliant app in the USA successfully treat compliance as an architecture constraint, not a launch task.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Map your PHI first. Sign your BAAs before integration work starts. Encrypt everything, log everything, and document the reasoning behind each decision.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Do that, and compliance stops being the thing that delays your launch. It becomes the reason a health system is willing to sign.<\/span><\/p>\n<h2><b>About EngineerBabu<\/b><\/h2>\n<p><a href=\"http:\/\/engineerbabu.com\"><span style=\"font-weight: 400;\">EngineerBabu<\/span><\/a><span style=\"font-weight: 400;\"> is a technology development company building products across healthtech, fintech, and AI, from MVPs to scaled, production-ready platforms.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It holds a CMMI Level 5 rating, has worked with 4 unicorn clients, and has supported 200+ VC-funded products. The company is backed by Vijay Shekhar Sharma.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Founded by Mayank Pratap (Co-founder) \u00b7 <\/span><a href=\"mailto:mayank@engineerbabu.com\"><span style=\"font-weight: 400;\">mayank@engineerbabu.com<\/span><\/a><\/p>\n<h2><b>FAQs<\/b><\/h2>\n<ul>\n<li aria-level=\"1\">\n<h3><b>How long does it take to build a HIPAA compliant app in the USA?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Most teams need 4 to 7 months to build a HIPAA compliant app in the USA at MVP scope. Add 2 to 4 weeks for BAA negotiations, plus time for the initial risk analysis.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>How much does it cost to build a HIPAA compliant app in the USA?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Expect $60,000 to $120,000 for a compliant MVP and $150,000 to $400,000 for a full clinical platform. Compliance work adds roughly 15% to 25% over a non-regulated build.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>Is there an official HIPAA certification for apps?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">No. HHS does not certify software. Third-party assessments and SOC 2 or HITRUST reports demonstrate diligence, but compliance remains your ongoing obligation.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>Do I need a BAA if my app never displays PHI to users?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Yes. Storing, transmitting, or processing PHI triggers the requirement, even when no human ever views it. Encrypted backups and log storage both count.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>What happens if we launch before compliance is finished?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">You carry full liability from day one. Nothing about the duty to build a HIPAA compliant app in the USA is deferred by a soft launch. Penalties scale by culpability tier.<\/span><\/p>\n<ul>\n<li aria-level=\"1\">\n<h3><b>Can we use AI features and still stay compliant?<\/b><\/h3>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Yes, provided the model provider signs a BAA and you keep PHI inside that boundary. De-identify inputs where the feature still works without identifiers.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nobody fails a HIPAA audit. There is no examiner who shows up, reviews your code, and stamps your app approved. What actually happens is quieter. A phone goes missing, a storage bucket gets misconfigured, and nine weeks later the Office for Civil Rights asks for your risk analysis. If you cannot produce one, that is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":22862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1246],"tags":[],"class_list":["post-22861","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-healthtech"],"_links":{"self":[{"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/posts\/22861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/comments?post=22861"}],"version-history":[{"count":3,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/posts\/22861\/revisions"}],"predecessor-version":[{"id":24222,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/posts\/22861\/revisions\/24222"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/media\/22862"}],"wp:attachment":[{"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/media?parent=22861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/categories?post=22861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/engineerbabu.com\/blog\/wp-json\/wp\/v2\/tags?post=22861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}