Is LastPass HIPAA Compliant

LastPass is one of the better-known password management tools on the market today. Lately, however, it’s become known for being involved in two recent hacking data breaches that may have compromised some customer information.

Because LastPass encrypts passwords on customers’ equipment, it appears that no password data was affected by either breach. But is LastPass HIPAA compliant?

What Makes a Software Tool HIPAA Compliant?

When it comes to software, there are specific indications of the tool’s HIPAA compliance. Software HIPAA compliance boils down to two things. Does the software have safeguards to keep patient data private and secure? Does the software provider sign business associate agreements?

When the answer to both of these questions is “yes,” the tool is likely HIPAA compliant. If the answer to either is “no,” the software tool is not HIPAA compliant.

What Are HIPAA Safeguards?

HIPAA safeguards are measures that a healthcare organization puts into place to protect the confidentiality, integrity, and availability of protected health information (PHI). HIPAA categorizes safeguards into three groups – administrative, physical, and technical. 

Administrative safeguards are written policies and procedures that dictate PHI’s proper uses and disclosures.

Physical safeguards, such as locks and alarm systems, protect an organization’s physical location.

Technical safeguards are measures that protect electronic PHI (ePHI).

While administrative and physical safeguards are essential, technical safeguards are generally the determining factor of a software provider’s HIPAA compliance. Technical safeguards should include encryption, user authentication, access controls, and audit controls.

Make Sure You’re HIPAA Compliant

Using a HIPAA compliant password manager is one piece of compliance.

We can help with the whole picture!