HIPAA Compliance for Ecommerce Companies: A Practical Guide for SMBs
Ecommerce companies that collect, store, or transmit protected health information (PHI) - such as prescription orders, health product purchases, or patient account data - must comply with HIPAA. Compliance requires a risk assessment, technical safeguards, BAAs with vendors, and documented policies. Penalties range from $100 to $50,000 per violation.
Does a general ecommerce store selling vitamins or supplements need to comply with HIPAA?
Not automatically. Selling over-the-counter supplements does not by itself trigger HIPAA. However, if your store collects health questionnaires, stores customer diagnoses, integrates with health apps, or processes prescriptions, you may be handling PHI. The determining factor is whether the data you store qualifies as individually identifiable health information linked to a health condition or treatment.
What is a Business Associate Agreement and does my ecommerce vendor need to sign one?
A Business Associate Agreement (BAA) is a legally binding contract required by HIPAA whenever a vendor handles PHI on your behalf. If your ecommerce platform, CRM, email service provider, cloud host, or payment processor touches PHI - even indirectly - they must sign a BAA. Vendors that refuse to sign a BAA should be replaced with compliant alternatives before go-live.
Can Shopify or WooCommerce be used for a HIPAA-compliant ecommerce store?
Shopify does not sign BAAs and is not designed for HIPAA compliance as of 2024. WooCommerce, hosted on a HIPAA-eligible infrastructure such as AWS or Google Cloud with a signed BAA, can be configured to meet technical safeguard requirements, but requires significant custom development and security hardening. Neither platform is HIPAA-compliant out of the box.
How often does a HIPAA risk assessment need to be performed?
The HIPAA Security Rule requires a risk analysis to be conducted on an ongoing basis - HHS OCR guidance states this means at least annually and whenever there are significant changes to your systems, workforce, or operations. This includes launching a new product line, migrating to a new platform, or onboarding a new third-party vendor that touches ePHI.
What are the penalties for an ecommerce company that violates HIPAA?
Civil penalties range from $100 per violation (for unknowing violations) to $50,000 per violation (for willful neglect not corrected), with an annual cap of $1.9 million per violation category. Criminal penalties for intentional violations can include fines up to $250,000 and up to 10 years in prison. HHS OCR has increased enforcement activity against non-healthcare businesses that handle PHI.
Does HIPAA apply to ecommerce companies that only store data outside the United States?
Yes. HIPAA applies based on where the covered entity or business associate operates and where the individual whose PHI is at issue is located - not where data is stored. An ecommerce company serving U.S. customers cannot avoid HIPAA obligations by storing data on servers located in another country.
How long does it take for an SMB ecommerce company to become HIPAA compliant?
Most SMB ecommerce companies with 20 to 150 employees require 3 to 6 months to achieve baseline HIPAA compliance when using a structured compliance platform. Factors that extend this timeline include legacy systems that require retrofitting, a large number of third-party vendors requiring BAAs, and organizations with no prior compliance documentation.