When individually identifiable health information is submitted by a customer, patient, or any other sort of healthcare user through an eCommerce platform, this information should be handled with extra care by the business owner, ensuring its security and maintaining the privacy of the individual. HIPAA compliance requirements contain two very important rules on the safeguard of ePHI, namely HIPAA Security Rule and HIPAA Privacy Rule.
The Security Rule contains a long list of safeguards that should be followed on an administrative, physical, and technical level, ensuring the safe storage, transmission, and general handling of ePHI. Information that is considered ePHI can be personal data such as demographics or card payment information, but most importantly medical health records, and one’s social security number.
For every transaction through eCommerce, especially when done on a platform related to healthcare, some of the aforementioned ePHI will have to be provided by the end-user, in full confidence of its secure handling. If such information falls in the wrong hands by accident or via hacking of the site or HIPAA-compliant data storage, it can lead to loss of privacy, and potentially dignity of individuals, malfunction of societal operations, disturbance of ongoing research, severe fines, and potentially reputation and business loss.