HIPAA readiness for Adobe Experience Manager as a Cloud Service hipaa-readiness-for-adobe-experience-manager-as-a-cloud-service
- HIPAA and Adobe Products and Services in the Adobe Trust Center
- Adobe’s Privacy Center
For Adobe Experience Manager (AEM) as a Cloud Service, Adobe is providing documentation to help you understand HIPAA readiness. It can help you become compliant with these regulations.
Health Insurance Portability and Accountability Act (HIPAA) health-insurance-portability-and-accountability-act-hipaa
The Health Insurance Portability and Accountability Act (HIPAA) the-health-insurance-portability-and-accountability-act-hipaa
The HIPAA Privacy, Security, and Breach Notification Rules establish important protections for individually identifiable health information known as Protected Health Information (PHI).
Under HIPAA, a covered entity is a healthcare provider, health plan, or a healthcare clearinghouse. A business associate is an entity that provides services to a covered entity that involves access to PHI. The HIPAA Privacy and Security Rules require that a covered entity obtain written assurances from a business associate in the form of a Business Associate Agreement (BAA) requiring the business associate to safeguard the privacy and security of the Covered Entity’s PHI.
Providing PHI to Adobe providing-phi-to-adobe
Adobe acts as a Business Associate for its HIPAA-ready Services, listed under HIPAA readiness of services in AEM as a Cloud Service.
Customers that license any Adobe HIPAA-ready Service to process PHI must have the correct license and a signed BAA with Adobe.
HIPAA Shared Responsibilities hipaa-shared-responsibilities
Adobe HIPAA-ready Services rely on a shared responsibility security model, requiring the customer and Adobe each to bear distinct responsibilities for maintaining the security of PHI. Under this shared security model, Adobe relies on the customer to use and configure the HIPAA-ready Services consistent with HIPAA.
For more information on executing an Adobe BAA for HIPAA-ready Services, please contact your Adobe sales representative or customer success manager.
For more information, see HIPAA and Adobe Products and Services in the Adobe Trust Center.
HIPAA terminology hipaa-terminology
The following table describes how AEM services are categorized for HIPAA usage.
HIPAA readiness of services in AEM as a Cloud Service hipaa-readiness-of-services-in-aem-as-a-cloud-service
The following table describes which AEM services are HIPAA-ready and which services may be used alongside them. HIPAA-ready services require the purchase of Extended Security for Healthcare, as described under Additional Requirements.
[1] Can be added to an Extended Security Program when no PHI is introduced.
[1] Can be added to an Extended Security Program when no PHI is introduced.
[1] Can be added to an Extended Security Program when no PHI is introduced.
[1] Can be added to an Extended Security Program when no PHI is introduced.
[1] Can be added to an Extended Security Program when no PHI is introduced.
[1] Can be added to an Extended Security Program when no PHI is introduced.
Additional Requirements additional-requirements
Services listed as HIPAA-ready require the purchase of Extended Security for Healthcare.
When Extended Security for Healthcare is purchased, there is the requirement that:
- the products selected for that program are HIPAA-ready (as listed in the table),
- Extended Security for Healthcare has been purchased for each product; this ensures sufficient Cloud Manager Credits,
- Extended Security for Healthcare is applied at the time of program creation.
If the requirements are fulfilled, Extended Security for Healthcare can be applied upon AEM program creation; see Setup for details.
Environments environments
HIPAA-ready does not apply to RDE (Rapid Development Environment), Dev, or Stage environments, as PHI is not allowed on these environments.
This means that you must:
- use dummy data for development and testing purposes
- only process PHI from production environments
The following table shows where the environment types can be supported as HIPAA-ready.
Setup setup
When you Create Production Programs, the Security tab provides the options to activate HIPAA protection.