HIPAA privacy and security
Financial and capital markets firms are sitting at an under-mapped intersection: HIPAA applies wherever they handle protected health information, including through employee benefit plans, fintech health-linked products, and certain data-sharing arrangements with covered entities. The U.S. Department of Health and Human Services Office for Civil Rights and the U.S. Federal Trade Commission have both taken enforcement positions that reach financial sector actors holding health data, and the 2024 HIPAA Security Rule proposed update from HHS would impose materially stricter technical safeguard requirements than the 2003 baseline most firms quietly inherited. Compliance teams are reviewing business associate agreements and third-party data vendor contracts now, not after a breach.
Watch
- HHS proposed HIPAA Security Rule update: new technical safeguard minimums pending finalization
- FTC health breach notification enforcement: penalties extending to non-HIPAA-covered data holders
- Business associate agreement gaps in fintech and embedded finance product structures
- State-level health data privacy laws (Washington My Health MY Data Act) layering onto federal baseline
Recent material activity in Financial & Capital Markets
Active monitoring in place across Financial & Capital Markets. Material developments related to hipaa privacy and security will appear here as they are published.