HIPAA: Complete Healthcare Privacy and Security Guide
The Health Insurance Portability and Accountability Act (HIPAA) is the foundational US law governing the privacy and security of protected health information (PHI). Since its enactment in 1996 and the subsequent Privacy Rule (2003) and Security Rule (2005), HIPAA has defined how healthcare providers, health plans, and their business associates must handle patient data. With OCR enforcement actions exceeding $16 million for single violations and the average healthcare data breach costing over $10 million, HIPAA is one of the highest-stakes compliance frameworks in any regulated sector.
What HIPAA Is and Who Issues It
HIPAA was enacted on August 21, 1996 by Congress. The Department of Health and Human Services (HHS) is responsible for promulgating the implementing regulations and enforcing HIPAA through its Office for Civil Rights (OCR). OCR has authority to investigate complaints, conduct compliance reviews, and impose civil monetary penalties for HIPAA violations. The Department of Justice handles criminal HIPAA violations.
The 2013 Omnibus Rule made the most significant changes to HIPAA since its original implementation, incorporating changes required by the HITECH Act (2009). The Omnibus Rule directly extended HIPAA obligations to business associates, strengthened breach notification requirements, expanded patient rights, and increased civil monetary penalties.
HHS issued a Notice of Proposed Rulemaking (NPRM) in January 2025 to update the Security Rule for the first time since 2005. The proposed update would make previously addressable implementation specifications fully required, add new requirements for multifactor authentication, network segmentation, and vulnerability management, and impose more specific incident response obligations. Organizations should monitor the rulemaking process as the final rule will materially change Security Rule compliance obligations.
Who Must Comply
HIPAA applies to two categories of regulated entities:
Covered Entities (CEs) are the three types of organizations directly covered by HIPAA:
- Healthcare providers who transmit any health information electronically in connection with covered transactions (virtually all healthcare providers — hospitals, clinics, physicians, dentists, pharmacies, nursing homes)
- Health plans, including health insurance companies, HMOs, company health plans, and government programs like Medicare and Medicaid
- Healthcare clearinghouses that process nonstandard health information into standard formats
Business Associates (BAs) are persons or entities that perform functions or activities on behalf of a covered entity that require access to PHI. The HITECH Act extended direct HIPAA liability to business associates. This is the category most directly relevant to technology companies. BAs include:
- Cloud service providers hosting ePHI (Amazon Web Services, Google Cloud, Microsoft Azure offering BAA-covered services)
- Electronic health record (EHR) vendors
- Medical billing services
- Healthcare analytics and data companies
- IT support companies with PHI access
- Consultants and contractors with PHI access
- Health information exchanges
Subcontractors of business associates are also subject to HIPAA as "downstream" business associates. Technology companies in the healthcare ecosystem should carefully determine whether they qualify as a business associate — the threshold is lower than many assume.
The Three Primary Rules Explained in Depth
The Privacy Rule
The Privacy Rule (45 CFR Parts 160 and 164) establishes national standards for how PHI may be used and disclosed. PHI is individually identifiable health information held or transmitted by a covered entity or business associate. PHI includes names, addresses, birth dates, Social Security numbers, and any other information that could identify a person in combination with health information.
Key Privacy Rule requirements:
- Minimum Necessary Standard: Covered entities must make reasonable efforts to limit PHI disclosure to the minimum necessary to accomplish the intended purpose. This applies to all uses, disclosures, and requests for PHI.
- Permitted Uses and Disclosures: PHI can be used or disclosed without patient authorization for treatment, payment, and healthcare operations (TPO). Other uses require written patient authorization.
- Required Disclosures: Covered entities must disclose PHI when patients request access to their own information, or when HHS requires access for investigations.
- Patient Rights: Patients have rights to access their own PHI, request amendments to their records, receive an accounting of disclosures, request confidential communications, and request restrictions on certain uses and disclosures.
- Notice of Privacy Practices (NPP): Covered entities must provide patients with a written NPP describing their privacy practices, and must make good-faith efforts to obtain patient acknowledgment.
The HHS 2024 rulemaking also proposed strengthening protections for reproductive health information PHI, restricting its disclosure for certain law enforcement purposes — a response to legal changes affecting reproductive health following the Dobbs Supreme Court decision.
The Security Rule
The Security Rule (45 CFR Parts 160 and 164) establishes standards for protecting electronic PHI (ePHI) — health information that is created, maintained, received, or transmitted electronically. The Security Rule requires covered entities and business associates to ensure confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit.
The Security Rule organizes safeguards into three categories:
Administrative Safeguards
Administrative safeguards are the policies, procedures, and processes for managing the implementation and maintenance of security measures:
- Risk Analysis: Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI. This is the single most foundational Security Rule requirement — OCR investigates risk analysis adequacy in virtually every enforcement action.
- Risk Management: Implement security measures to reduce risks and vulnerabilities to a reasonable and appropriate level
- Workforce Training: Provide security training to all workforce members
- Access Management: Implement procedures for authorizing access to ePHI
- Contingency Planning: Establish policies for responding to emergencies that damage systems containing ePHI
- Evaluation: Perform periodic technical and non-technical evaluations of the security program
Physical Safeguards
Physical safeguards control physical access to ePHI:
- Facility Access Controls: Limit physical access to electronic information systems and the facilities where they are housed
- Workstation Use: Specify the proper functions and physical attributes of workstations accessing ePHI
- Workstation Security: Implement physical safeguards for workstations that access ePHI
- Device and Media Controls: Govern the receipt, removal, and reuse of hardware and electronic media containing ePHI
Technical Safeguards
Technical safeguards are the technology and policies governing access and protection of ePHI:
- Access Controls: Technical mechanisms to allow only authorized persons to access ePHI, including unique user identifiers and automatic logoff
- Audit Controls: Hardware, software, and procedural mechanisms to record and examine activity in systems that contain ePHI
- Integrity Controls: Policies to protect ePHI from improper alteration or destruction; mechanisms to authenticate ePHI
- Transmission Security: Technical security measures to guard against unauthorized access to ePHI transmitted over electronic communications networks, including encryption
Implementation specifications within the Security Rule are classified as either "required" (must be implemented) or "addressable" (must be implemented if reasonable and appropriate, or an equivalent alternative must be documented). The proposed 2025 Security Rule NPRM would eliminate the addressable category, making all specifications required — a significant shift for many organizations.
The Breach Notification Rule
The Breach Notification Rule (45 CFR Part 164, Subpart D) requires covered entities and business associates to provide notification following a breach of unsecured PHI. Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption or destruction.
Upon discovery of a breach:
- Individual notification: Covered entities must notify affected individuals within 60 days of discovery. Notification must include a description of what happened, types of PHI involved, steps individuals can take to protect themselves, steps the covered entity is taking, and contact information.
- Media notification: If a breach affects over 500 residents of a state or jurisdiction, covered entities must provide media notification within 60 days
- HHS notification: Covered entities must notify HHS. For breaches affecting 500 or more individuals, notification must be within 60 days. For smaller breaches, covered entities may aggregate and report annually
- Business Associate notification: Business associates must notify covered entities within 60 days of discovering a breach
The breach risk assessment — determining whether an impermissible use or disclosure is a breach requiring notification — involves four factors: the nature and extent of PHI involved, who accessed or could access the PHI, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated.
Business Associate Agreements
All business associates must execute a HIPAA-compliant Business Associate Agreement (BAA) with covered entities before accessing PHI. BAAs must include provisions requiring the business associate to:
- Only use or disclose PHI as permitted by the agreement or required by law
- Use appropriate safeguards and comply with the Security Rule for ePHI
- Report breaches and security incidents to the covered entity
- Ensure subcontractors that access PHI execute equivalent agreements
- Return or destroy PHI upon contract termination where feasible
BAAs are contracts — their specific provisions matter. Health tech companies should review BAA templates carefully to ensure they accurately reflect the scope of PHI access and the safeguards in place. A poorly drafted BAA can create unexpected liability or exclude critical uses of data.
Audit and Assessment Process
HIPAA does not require organizations to obtain a formal third-party certification. Instead, compliance is demonstrated through documentation and evidence of ongoing program implementation:
| Activity | Recommended Frequency | Purpose |
|---|---|---|
| Risk analysis | Annual or upon material changes | Foundation of the Security Rule program |
| Risk management review | Annual | Track remediation of identified risks |
| Policy and procedure review | Annual | Keep documentation current |
| Workforce training | Annual (at minimum) | Demonstrate ongoing training program |
| HIPAA audit (internal or external) | Annual | Identify compliance gaps |
OCR enforcement is complaint-driven and investigation-based rather than structured around scheduled audits. However, OCR has conducted periodic random audit programs (most recently the 2016-2017 Phase 2 audit program) and has announced plans for future audit cycles. OCR investigations routinely result in Resolution Agreements with multi-million dollar settlement amounts where systemic compliance failures are found.
Costs and Timeline
| Organization Type | Typical Timeline | Estimated Cost Range |
|---|---|---|
| Small medical practice | 3–4 months | $20,000–$50,000 |
| Health tech startup | 4–6 months | $50,000–$100,000 |
| Mid-sized covered entity | 6–9 months | $100,000–$200,000 |
| Large health system or health plan | 6–9 months | $150,000–$250,000 |
The cost of non-compliance is far higher — OCR civil monetary penalties range from $100 to $50,000 per violation (per category, per calendar year) depending on culpability, with maximum annual penalties per violation category of $1.9 million (2023 adjusted figure). Criminal penalties for knowing HIPAA violations can reach $250,000 and 10 years imprisonment.
Comparison with Related Frameworks
- HITRUST CSF: 85% overlap. HITRUST is the most widely adopted comprehensive security certification in US healthcare, incorporating HIPAA requirements into a broader framework with independent assessment. See the HITRUST guide.
- SOC 2: About 50% overlap, particularly in the Security and Availability trust service criteria. Technology companies serving healthcare clients often pursue both HIPAA compliance and SOC 2 certification, as SOC 2 demonstrates broader security maturity beyond HIPAA's specific requirements.
- ISO 27001: About 55% overlap in information security controls. ISO 27001's risk management approach aligns well with HIPAA's risk analysis requirement, and many controls overlap.
- HITECH Act: HITECH directly extended and strengthened HIPAA. The two frameworks are inseparable in practice. See the HITECH guide.
- GDPR Health: US organizations serving EU patients must comply with both HIPAA and GDPR. The two frameworks share patient rights principles but differ significantly in requirements. See the GDPR Health guide.
How Automation Helps
HIPAA compliance is documentation-intensive, requiring ongoing evidence of risk analysis, training completion, policy maintenance, and incident management. Compliance automation delivers measurable value:
- Automated evidence collection demonstrates ongoing Security Rule compliance with access controls, audit logging, and encryption configurations
- Risk assessment workflows formalize the annual risk analysis process with documentation meeting OCR's analytical standards
- Policy management platforms maintain current versions of privacy and security policies with review tracking
- Training modules deliver and document required annual HIPAA training for all workforce members
- Vendor risk workflows track BAA status and Business Associate security assessments
LowerPlane supports HIPAA compliance programs alongside HITRUST, SOC 2, and 50-plus additional frameworks. At $4,000 per year starting price with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane enables health tech companies to maintain continuous HIPAA compliance without the manual burden of standalone programs. For health technology companies building HIPAA-compliant platforms, see /for/healthtech. Compare automation platforms at /compare/best-compliance-automation-platforms.
Frequently Asked Questions
What is the difference between a covered entity and a business associate?
A covered entity is a healthcare provider, health plan, or healthcare clearinghouse that transmits PHI electronically in connection with covered healthcare transactions. A business associate is any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform functions or activities. The key distinction is whether the organization is providing healthcare (covered entity) or supporting another organization's healthcare functions (business associate). Many technology companies that might not immediately think of themselves as healthcare companies are business associates when they host or process PHI — including cloud providers, analytics companies, and any SaaS platform whose customers upload health data.
What must a HIPAA risk analysis cover?
OCR has issued detailed guidance on risk analysis requirements. A compliant risk analysis must: identify the scope of all ePHI the organization creates, receives, maintains, or transmits; identify all threats and vulnerabilities to that ePHI; assess the likelihood that each threat-vulnerability combination could be exploited; assess the potential impact of such an exploit; and determine the current level of risk based on likelihood and impact. The analysis must be thorough, documented in writing, and updated when significant changes occur to the environment. OCR has found inadequate risk analysis to be the most frequently cited HIPAA violation.
When is encryption of ePHI required under HIPAA?
Under the current Security Rule, encryption is an addressable implementation specification — meaning organizations must implement it or document why it is not reasonable and appropriate and implement an equivalent alternative. In practice, the widespread availability of encryption technology means OCR views failure to encrypt as requiring a very strong documented justification. The proposed 2025 Security Rule update would make encryption of ePHI in transit and at rest a required specification, eliminating ambiguity. Health tech companies should treat encryption as effectively required under both current and proposed rules.
What does the proposed 2025 HIPAA Security Rule update change?
HHS published an NPRM in January 2025 proposing the most significant Security Rule update since 2005. Key proposed changes include: eliminating the distinction between required and addressable implementation specifications; adding specific requirements for multifactor authentication, network segmentation, and vulnerability management; requiring more specific incident response planning; mandating technology asset inventories; imposing 24-hour and 72-hour notification requirements for certain security incidents; and adding enhanced encryption requirements. The final rule will be issued after the public comment period and any revisions. Organizations should begin assessing the impact of proposed requirements on their current programs.
How does HIPAA interact with state health privacy laws?
HIPAA establishes a federal floor of patient privacy and security protections. State laws that provide greater protections for health information are not preempted by HIPAA — both apply simultaneously. Many states have enacted health privacy laws that exceed HIPAA's requirements in specific areas, such as mental health records (many states have stronger protections), HIV/AIDS information, substance abuse treatment records (also governed by 42 CFR Part 2 at the federal level), and genetic information. Organizations operating in multiple states must identify and comply with the most protective applicable law for each situation, which may vary by data type, patient population, and state of service delivery.