Tag: Nathan Treloar

Amazon Alexa Is Now HIPAA Eligible: What’s Next?

Image result for amazon alexa logoAmazon announced that a version of their virtual assistant technology, Alexa, is now HIPAA-eligible. This means it’s available for applications that are subject to the data privacy and security requirements of HIPAA. The new HIPAA-eligible version of Alexa, specifically the Alexa Skills Kit, is now available to a limited number of developers by invitation only.


Amazon has seen increasing interest in Alexa’s potential to serve as a virtual healthcare assistant. While devices like PCs, tablets, and smartphones have contributed to advances in healthcare, they’ve been problematic for some aspects of patient engagement – particularly among the elderly and others who physically cannot – or will not – use them.

The idea of a smart, always-available, hands-free, voice-powered virtual assistant that can answer questions, deliver medication reminders, facilitate communication with one’s doctor, provide health coaching, and more, has piqued the interest of the healthcare communityAmazon has responded.

What’s different

Until now, Alexa’s use in healthcare has been mostly limited to question answering services – voice appsor “skills” in Alexa parlance, that answer general questions about health conditions, treatments, symptoms, etcAmazon Echo users, for example, can access health benefit information from a skill like Answers by Cigna, or tap into one of many symptom checkers in the Alexa marketplace. The big change is that Alexa can now be used in certain applications that collect and transmit protected health information (PHI).

This opens a whole new world of voice applications beyond basic Q&A, such as remote patient monitoring population health, medication adherence and clinical trial optimization. It seemed inevitable that voice assistants like Alexa and smart speaker-equipped devices like the Amazon Echo would find their way into clinical applications. Amazon’s announcement confirms this.


Organizations must understand the full range of issues surrounding the “what, why and how” of securing, voice-first healthcare applications. HIPAA is just the start. There is no formal certification process for HIPAA, and it applies only in the U.S. Also, many healthcare IT departments use other industry standards or ?have created their own standards for data privacy and security. In their eyes, completely securing a voice application may go well beyond ensuring that a service provider will sign a HIPAA business associate agreement. Issues like user authentication, data privacy in shared spaces, network and device hacking, secure system integration (e.g. with an EHR), should all be addressed.  Continue Reading