If even one of your customers is from the healthcare vertical and you are handling any of their Patient Health Information (PHI), you are exposed to risk. You are considered a Business Associate and share the same regulatory compliance requirements as your customer and will be penalized for non compliance or data breach. Typically your customer will require that you sign a BA Agreement with them. To be safe, if you don’t have a BA Agreement in place, you should make it clear to your customer that without one, you cannot be held liable for potential breaches or non-compliance. Also be careful as PHI extends beyond obvious sources and can be found in within other verticals that deal with this type of information. For example, education facilities that track immunization records of their students or local government that maintains PHI, like healthcare records for an inmate within their judiciary system.
Speak to an expert