HIPAA in UX Research: Health Data as Hazardous Material
HIPAA in UX research treats health data as toxic: collect only what you need and de-identify fast. When interviewing patients or handling medical logs, treat every note as PHI. The footgun is dropping raw transcripts into consumer apps without a signed BAA.
WHY IT EXISTS: UX researchers in health tech routinely collect stories, behaviors, and frustrations from patients and clinicians. Those sessions inevitably capture Protected Health Information, from medication names and diagnoses to dates of treatment and biometric data. HIPAA was created to prevent this sensitive information from leaking through careless storage, sharing, or vendor management. In research, the risk is not malice but friction: a transcript pasted into a shared doc, a highlight reel stored on a laptop, or a survey tool without a Business Associate Agreement can all become breaches.
THE MENTAL MODEL: Think of PHI as radioactive dust. You can study it safely inside a sealed lab, but the moment you carry it out in your pocket or leave it on an open desk, you contaminate everything around you. HIPAA compliance is the containment suit. It does not mean you cannot do research; it means you never let the dust touch unsecured channels, unvetted tools, or unauthorized teammates.
HOW IT WORKS: Compliance starts with classification. If your participant is a patient, or if your product processes health data, assume the research artifact is PHI until you strip all eighteen identifiers defined by the Safe Harbor method. That includes names, dates beyond year, geographic data smaller than state, and unique numbers like medical record IDs. Next, execute a Business Associate Agreement with any vendor that will touch the data, from transcription services to cloud storage providers. Use encryption at rest and in transit. De-identify data as early in the pipeline as possible, ideally before synthesis. Obtain consent that explicitly covers research use, separate from clinical care consent. Finally, limit access to the minimum team members who need the raw material.
WHEN TO USE IT: Apply these rules when you are conducting usability testing for an EHR, interviewing patients about a chronic disease app, or analyzing usage logs from a telehealth platform where user accounts link to real identities. If your organization is a covered entity or business associate, the rules follow the data.
WHEN NOT TO USE IT: You do not need HIPAA compliance for general consumer wellness apps that lack clinical integration, such as a step tracker without physician connectivity, provided you never access medical records. Fully de-identified data sets that cannot reasonably be re-identified also fall outside the scope, though the bar for de-identification is strict.
ONE CANONICAL EXAMPLE: A health system redesigns its patient portal and recruits Type 2 diabetes patients for hour-long interviews. Researchers record video, capture screens showing glucose readings, and take notes about medication frustrations. Before analysis, the team scrubs dates and replaces names with participant codes. They move files from the recording device into HIPAA-compliant storage with a BAA, route transcripts through an approved vendor, and keep clips out of public Slack channels. Synthesis happens on de-identified transcripts only. The researchers never see medical record numbers, and no one emails raw files to stakeholders.
Get five bites like this every day.
Tezvyn delivers a daily feed of 60-second tech bites with quizzes to lock in what you learn.