Stay informed
Receive monthly updates on trends, products and growth insights in your inbox.

Get weekly updates on markets, new features, and exclusive investment insights delivered straight to your inbox.
The first step to understanding HIPAA is to unpack what PHI is. Under US law, protected health information (PHI) encompasses any data related to an individual’s health status, as well as the provision of healthcare or healthcare payments. This information, created and collected by a Covered Entity (such as a hospital or care facility), can be linked to a specific individual.
In other words, PHI is considered “protected health information” only when it can identify an individual. If all identifiers are stripped from health data, it ceases to be PHI. For example, an email address is only considered PHI when it's associated with a health-related product order, medical record numbers or dates related to the health of individuals, such as the date of hospital discharge. An email address alone isn’t PHI.
Furthermore, processing PHI isn’t a consideration for all health-related transactions. For instance, B2B transactions between medical equipment manufacturers and hospitals don’t require safe PHI processing, as there is no individually identifiable patient data as a part of that kind of transaction.
However, a B2B2C transaction could require processing PHI, as in the example of a doctor’s office ordering a glucose monitor from the device manufacturer (a seemingly B2B transaction) but having it shipped directly to the patient’s home address and including the patient's email for shipment tracking purposes. The association of the health “product” (the glucose monitor) and the patient’s email and home shipping address is considered PHI, and thus processing a transaction like this would require a HIPAA-compliant commerce platform.

For covered entities and their business associates that process PHI, ensuring robust data security and data-processing practices is paramount. The risk of not doing so is immense: If a stolen credit card sells for US$2 on the black market, PHI can sell for as much as US$363, according to the Infosec Institute. Scammers use PHI to commit insurance and medical fraud, resulting in high costs for individuals and healthcare systems.
Moreover, failure to comply with the provisions of the HIPAA Privacy, Security or Breach Notification rules can also mean steep financial penalties for Covered Entities, even if a violation was unintentional.
HIPAA (Health Insurance Portability and Accountability Act) is a federal law in the United States that governs the handling and security of protected health information (PHI). Overall speaking, HIPAA applies to the following parties:
Covered entities and business associates must sign a business associate agreement (BAA) when sharing PHI to ensure compliance with HIPAA regulations. The BAA is a contract that governs the secure processing of PHI, specifies the business associate’s role and requires it to comply with HIPAA rules.
While there’s no formal HIPAA certification, organizations must implement safeguards to process PHI according to their role and risk level, including third-party security risk assessments, adoption of industry standards and established frameworks, direct alignment with the guidance set by the US Department of Health & Human Services, technical, administrative and physical controls, as well as continuous internal training.
When customers know their personal health information is protected, they feel more secure and are more likely to engage in online healthcare transactions. In short, adhering to HIPAA fosters patient trust while reducing the risk of data breaches, having a direct (and positive) impact on the growth of your healthcare eCommerce business.
For instance, when PHI is safely processed, healthcare businesses can create a heap of digital solutions that make health and wellness services easier, faster and more convenient for patients. Here are some examples of digital solutions for healthcare that require PHI processing:
Many healthcare companies are relying on HIPAA-compliant digital commerce platforms to scale health and well-being products and services across the US to serve patients online. For instance, the eyecare leading company Bausch & Lomb is seeking to create an experience that would allow eyecare providers to sell Rx (prescription-required) contact lenses, a process that requires safe PHI processing.
By digitizing its biggest, most complex use case first — B2B2C — which is used when consumers need a prescription from an eye care professional (ECP) to purchase a product, the company required a digital commerce platform that could securely ingest PHI and be fully HIPAA-compliant: commercetools.
While there are technologies serving the healthcare industry that provide HIPAA-ready ERP and related services, such as Adobe Commerce and SAP, these legacy all-in-one platforms aren’t fit for purpose. While they might address secure PHI processing, these platforms typically lack the flexibility to translate complex use cases into intuitive buying experiences.
This is because the monolithic platform bundles all the commerce components (backend, frontend, and everything in between) into a single system, a notoriously inflexible setup that slows businesses down.
This inflexibility means many healthcare companies operating across multiple business models end up with disparate, siloed systems, further adding to their already complex interoperability landscape. As a result, they struggle to release features that meet customer needs and can’t efficiently automate complex, manual and time-consuming sales and ordering processes.
Because of these constraints, many healthcare companies decided to invest in homegrown solutions in order to fully customize patient experiences. In practice, however, business goals quickly outpace the capabilities of in-house built technologies. Moreover, when you build your own system, it’s your job to implement security measures and ensure compliance with regulations. Homegrown solutions might struggle to stay compliant due to the complexity of these regulations, which, in turn, might make your company more vulnerable to cyberattacks.
Modern commerce is a modular, component-based design that provides businesses with the flexibility and freedom to “compose” tailor-made shopping experiences by selecting and integrating the best components for their unique needs.
When coupled with robust security and compliance measures, modern infrastructure is best suited to meet the healthcare industry’s needs, as it can support sophisticated customer experiences while upholding the highest data security standards.
HIPAA compliance is part of Sphere, the commercetools enterprise commerce platform. commercetools’ HIPAA compliance is affirmed by:
commercetools empowers healthcare, medtech and life sciences organizations to digitize commerce with unparalleled flexibility while ensuring regulatory compliance, including HIPAA, and security for sensitive and protected health data at scale.
Data access logs play a critical role in HIPAA compliance by providing a detailed record of who has accessed PHI, when they accessed it and what actions they performed. Key requirements include:
The commercetools also provides Audit Log Premium to track changes for detailed logging of all system activity. By having an audit trail for changes across your commerce operations, you can support compliance audits and security investigations.
For companies operating in France that engage in healthcare commerce, the HDS (Hébergeur de Données de Santé) certification is required to process PHI in the country. In addition, data security and protection, such as the GDPR (General Data Protection Regulation) in the European Union and other relevant standards like TISAX are crucial for healthcare companies to up their security game in digital commerce.
As an IT-managed service provider, commercetools holds the HDS certification for the scope of personal health data management, which is required under the French Public Health Code for handling personal health information. In addition, commercetools’ commitment to securely managing data helps you meet regulatory and policy objectives through multiple certifications, including TISAX, ISO 27001, and more. Check our Trust Center for more information.
Interested in learning more? Get additional information on how to start your HIPAA-compliant eCommerce with commercetools in our docs.
Receive monthly updates on trends, products and growth insights in your inbox.