There is actually a lot more to HIPAA compliance than what you see on the back end of your application. You have to do Risk Assessments annually, assign a Privacy Officer, have policies & procedures in place, implement employee training, and execute Business Associate Agreements with anyone you share PHI with.
These administrative parts are frequently forgotten when implementing a HIPAA compliance program.
These administrative parts are frequently forgotten when implementing a HIPAA compliance program.
Disclosure: my startup, Accountable, automates this process. http://www.accountablehq.com