This document delineates the requirements for HIPAA compliance in web applications with access to electronic personal health information (ePHI) and examines the adequacy of PatientBank’s (PB) security practices. The requirements will be presented in four distinct sections: Administrative Safeguards, Physical Safeguards, Technical Safeguards and Documentation Requirements.