The free checklist

The HIPAA checklist
for building apps for clinics

Every service that touches patient data needs a signed BAA, including the ones Claude wired in

Free, straight to your inbox. No call, no pitch

The video, without the music

The short answer

What HIPAA means for a clinic's app

If you build an app for a US clinic and it touches patient health information (PHI), you are a business associate. You sign a business associate agreement (BAA) with the clinic before you touch any patient data, and every outside service your app sends PHI to (hosting, logs, error tracking, email, AI models) needs a BAA too. Business associates can be fined directly, not just the clinic.

Do I need a BAA as a developer?

Yes, if your work touches PHI. Sign it with the clinic before you see any patient data

Does my hosting or AI provider need a BAA?

Yes, if PHI passes through it. Many providers only offer one on certain plans

Can I use real patient data while building?

Use fake patient data until every BAA is signed

Who gets fined?

The clinic, and business associates directly for their own violations

The Blinkz team · Updated

HIPAA in plain English

What it is, and why it lands on you

What HIPAA is

The US law for health information tied to a person, called PHI, which stands for protected health information

Why it lands on you

Anyone outside the clinic who touches PHI is a business associate and signs a BAA first. That includes you, and every company your app passes PHI to

What Claude can check

Every outside service that stores, receives or sends PHI, with the file and line, and whether that company offers a BAA on your plan. It also flags PHI in logs, URLs, analytics, AI prompts and notification text

What Claude can't check

Whether each BAA has actually been signed. A company offering a BAA is not the same as you having one

From the video
When we built our HIPAA app, we worked on fake patient data until every one of them was signed
The Blinkz team
In the full checklist

What the checklist gives you

The full audit prompt

Ready to copy into Claude. It reads your code and changes nothing

Five things to look for

The leaks that hide in error logs, tracking pixels and reminder texts

What you can ignore

So you don't chase services that never see a patient

The paperwork after the scan

Every BAA to get signed, and the breach plan the code can't do for you

Free, no call

Get the full HIPAA checklist

The prompt to give Claude, what to look for in its answer, what you can ignore, and the BAAs you still have to get signed

Free, straight to your inbox. No call, no pitch

Fine print

What this page is, and isn't

  • This is a technical checklist, not legal advice. For your situation, talk to a lawyer or your client's compliance lead.
  • The Claude prompts only read your code and report back. They don't change anything.
  • The page explains the rules in plain English. The law and the auditor's criteria are the final word, linked below.

Building an app that has to pass a check like this

An engineer checks it, fixes it, tests it and puts their name on it

  • 30 minutes
  • Free
  • No slides, no sales team