28.3 HIPAA and HITECH in bank services

Key Takeaways

  • Ordinary payment processing does not make every bank a HIPAA business associate.

  • Expanded services involving protected health information require a function-specific coverage analysis.

  • Covered services need the applicable contract, safeguards and incident obligations under HIPAA and HITECH.

Last updated: October 2026

Determine the bank’s actual role

The Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) address health-information privacy, security and related obligations. A bank does not automatically become a HIPAA covered entity because it finances a medical practice or processes a patient’s payment. Covered entities generally include health plans, health care clearinghouses and health care providers conducting specified electronic transactions.

A business associate performs specified functions or services for a covered entity involving protected health information. The bank’s actual service can therefore matter. Maintaining ordinary deposit accounts for a hospital differs from administering a service that receives and processes identifiable patient billing information on the provider’s behalf. Review the function, information and legal definition instead of relying on the customer’s industry or a vendor’s contract label.

Financial payment functions and expanded services

HIPAA has treatment for ordinary financial transactions and activities that directly facilitate payment for health care. Processing checks, card transactions or funds transfers does not automatically establish a business associate relationship. This financial-function boundary does not make every health-data service offered by a bank exempt.

Suppose a bank merely clears a patient’s check payable to a clinic. That differs from a bank service storing diagnoses, treatment details and identifiable billing records to manage the clinic’s accounts receivable. The expanded service requires a business-associate analysis. A lockbox, analytics or payment-support product must be evaluated by what it actually does and the data it handles; the word banking is not a blanket exemption.

The bank may also sponsor an employee health plan that has covered-entity obligations. Keep the plan’s information and permitted employer access separate from ordinary employment records and bank customer information. A human resources file does not automatically become HIPAA protected health information merely because it mentions illness, while information held in a covered plan context can be subject to different rules.

Define protected information and permitted uses

Protected health information (PHI) generally concerns individually identifiable health information held or transmitted by a covered entity or business associate, with regulatory exclusions. Electronic PHI is subject to the Security Rule. Properly deidentified information has distinct treatment, but simply removing a patient’s name may leave identifiable dates, numbers or other information. Use the permitted deidentification standards rather than a casual assumption.

The Privacy Rule addresses uses and disclosures, authorizations, individual rights and the minimum necessary standard where applicable. Minimum necessary has exceptions; do not impose it mechanically on every permitted health transaction. A business associate’s agreement and the applicable rule restrict uses beyond performing the authorized service. A bank cannot use identifiable patient data received for billing support as a general marketing prospect list merely because a vendor contract gives it access.

Bank functionInitial compliance question
Clearing a patient’s ordinary paymentDoes the financial transaction boundary apply?
Hosting identifiable provider billing recordsIs the bank a business associate?
Sponsoring an employee health planWhich plan obligations and access limits apply?
Using patient data for unrelated marketingIs the use authorized under the governing rules?

Agreements and security

Where a business associate relationship exists, a compliant business associate agreement addresses permitted uses, safeguards, reporting, subcontractors, access and other required provisions. A generic confidentiality clause is not automatically sufficient. HITECH and implementing rules make business associates directly accountable for specified obligations; a contract does not remove statutory responsibility.

The Security Rule requires administrative, physical and technical safeguards based on the applicable assessment and standards. Risk analysis, access management, workforce procedures, contingency planning and documentation belong in the review. Do not assume that the bank’s GLBA security program automatically satisfies every health-specific requirement, although controls can support both frameworks. Determine where data are stored, transmitted, accessed and retained, including subcontractors.

Breaches and notification clocks

HIPAA breach analysis considers whether an impermissible use or disclosure is a breach under the regulatory definition and its exceptions or whether the permitted risk assessment demonstrates a low probability of compromise. A business associate must notify the covered entity without unreasonable delay and no later than sixty calendar days after discovery; a contract can require quicker notice. Discovery and imputed knowledge require analysis under the rule.

Covered-entity notices to individuals, HHS and sometimes media depend on the circumstances, including the number affected and applicable timing. Do not replace the HIPAA process with GDPR’s seventy-two-hour authority rule or the bank regulator’s thirty-six-hour notification incident rule. Multiple regimes may apply to one incident, each with a different trigger, recipient and clock.

Work an operational review

Before launching a hospital receivables service, inventory data fields and services, determine covered-entity and business-associate roles, obtain required agreements and map safeguards and incident procedures. Test whether staff can access more patient detail than the role permits and whether subcontractors have appropriate obligations. Train personnel using the actual service, including forbidden secondary uses and escalation of suspected disclosures.

HHS business-associate and cloud guidance and the HIPAA privacy framework provide the official starting points. The exam skill is recognizing the scope boundary and escalating an expanded health-information function rather than assuming every bank is either entirely covered or entirely exempt.

Test Your Knowledge

A bank expands from clearing clinic checks to hosting identifiable patient billing records for the clinic. What should compliance do?

A

Apply GDPR automatically instead.

B

Reassess business-associate status, agreements and safeguards for the new function.

C

Assume all bank functions are exempt.

D

Treat every depositor as a health plan.

Sections you finish are checked off in the contents.