Understanding HIPAA Components: Privacy, Security & Breach Notification

Introduction

HIPAA sets three separate obligations for covered entities and business associates — the Privacy Rule, the Security Rule, and the Breach Notification Rule — and each one carries its own requirements, its own documentation demands, and its own penalty exposure. Understanding all three as a system, not individually, is what separates organizations that pass OCR scrutiny from those that don't.

Most HIPAA violations don't stem from ignorance of the law. They come from misreading which rule applies, assuming "addressable" means optional, or skipping the documented risk analysis because nothing bad has happened yet. OCR doesn't accept those explanations.

This article breaks down what each rule requires and how they interact — including where organizations consistently go wrong and what violations actually cost, based on current HHS enforcement data and the 2025 inflation-adjusted civil penalty schedule.

Key Takeaways:

  • The Privacy Rule governs all PHI in any format; the Security Rule adds separate protections specifically for ePHI
  • Encrypted PHI that is lost or stolen does not trigger breach notification obligations
  • OCR's most frequently cited violation is impermissible PHI use or disclosure — not hacking
  • "Addressable" Security Rule specifications are not optional; non-implementation requires documented justification
  • Workforce training is a formal requirement under both the Privacy Rule and Security Rule

HIPAA's Three Core Rules: Who They Cover and What They Protect

Covered Entities and Business Associates

HIPAA applies to two categories of organizations:

Covered entities — three types:

  • Healthcare providers that transmit health information electronically (physicians, hospitals, pharmacies)
  • Health plans (insurers, employer health plans, Medicare/Medicaid)
  • Healthcare clearinghouses that process nonstandard health information into standard formats

Business associates — any person or entity, outside the covered entity's workforce, that performs functions involving PHI on its behalf. This includes billing companies, IT vendors, cloud storage providers, and EHR platforms. Subcontractors of business associates carry comparable obligations. A written Business Associate Agreement (BAA) is required whenever PHI passes to an outside party.

The 2013 Omnibus Rule extended direct HIPAA liability to business associates — they are no longer simply contractually bound through a covered entity. They face OCR enforcement independently.

What Is Protected Health Information?

PHI is any individually identifiable health information related to an individual's past, present, or future health condition, healthcare, or payment — held or transmitted in any format (electronic, paper, or oral) by a covered entity or business associate.

The Safe Harbor de-identification method requires removal of 18 specific identifier categories. Key examples include:

  • Names and geographic subdivisions smaller than a state
  • Dates directly related to an individual (except year)
  • Phone numbers, fax numbers, and email addresses
  • Social Security numbers and medical record numbers
  • IP addresses and device identifiers
  • Biometric identifiers (fingerprints, voice prints)

Once all 18 categories are removed, the information carries no HIPAA restrictions.

How the Three Rules Divide Responsibility

Rule Applies To Governing Function
Privacy Rule All PHI (any format) What may be done with PHI and by whom
Security Rule Electronic PHI (ePHI) only How ePHI must be technically protected
Breach Notification Rule Unsecured PHI What must happen when protections fail

HIPAA three rules comparison chart Privacy Security Breach Notification overview

All three rules are enforced by the HHS Office for Civil Rights (OCR).


The Privacy Rule: Governing PHI Use, Disclosure, and Patient Rights

Core Principle and Permitted Disclosures

The Privacy Rule establishes a default: covered entities may only use or disclose PHI as the rule explicitly permits — or with the individual's written authorization. Every use or disclosure must also satisfy the minimum necessary standard, meaning PHI shared should be limited to what's actually needed for the intended purpose.

Three categories of use are permitted without patient authorization under 45 CFR 164.506:

  • Treatment: sharing records between a referring physician and specialist
  • Payment: submitting a claim to an insurer
  • Healthcare operations: quality assessment, staff training, business management

Written authorization is required for marketing uses, the sale of PHI, and most other purposes. If a marketing communication involves financial remuneration to the covered entity, the authorization must explicitly disclose that fact.

Patient Rights Under the Privacy Rule

Patients hold six enforceable rights:

  1. Right to access — receive a copy of their PHI within 30 days (one 30-day extension permitted with written notice)
  2. Right to amendment — request corrections to inaccurate or incomplete records
  3. Right to an accounting — obtain a record of certain disclosures made without authorization
  4. Right to request restrictions — ask that certain uses or disclosures be limited
  5. Right to confidential communications — request PHI be sent to an alternative address or by alternative means
  6. Right to a Notice of Privacy Practices — receive a plain-language document describing how their PHI may be used

Administrative Obligations

Covered entities must meet four organizational requirements:

  • Designate a privacy officer responsible for policy development and compliance
  • Provide a Notice of Privacy Practices (NPP) to patients
  • Train all workforce members on privacy policies (documented completion required)
  • Retain required policies, communications, and actions for six years from creation or last effective date

The 2013 Omnibus Rule introduced two significant changes:

  • PHI protection now extends 50 years after an individual's death
  • The breach harm standard was replaced with a presumption of breach — covered entities must now demonstrate a low probability of compromise to avoid notification, rather than proving harm occurred

The Security Rule: Safeguarding Electronic PHI Through Layered Controls

The Security Rule applies exclusively to ePHI — PHI stored, processed, or transmitted electronically. It complements the Privacy Rule without replacing it. Covered entities must ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit.

Administrative Safeguards (45 CFR 164.308)

Administrative safeguards are the policies and workforce practices governing how an organization approaches ePHI security. Key required specifications include:

  • Risk analysis — a documented, accurate assessment of potential risks and vulnerabilities to ePHI. This is explicitly Required, not Addressable — and its absence is one of OCR's most frequently cited findings
  • Risk management — implementing security measures sufficient to reduce identified risks
  • Sanction policy — formal consequences for workforce members who violate security policies
  • Assigned security responsibility — designating a HIPAA security officer
  • Incident response and reporting — procedures for identifying and responding to security incidents

Physical Safeguards (45 CFR 164.310)

Physical safeguards control the environment where ePHI is stored or accessed:

  • Facility access controls restricting who can enter areas containing ePHI systems
  • Workstation use policies (screens must not be visible to unauthorized individuals)
  • Device and media controls governing how hardware is introduced, moved, reused, and disposed of — including required specifications for disposal and media reuse

Technical Safeguards (45 CFR 164.312)

Technology-based controls protecting ePHI from unauthorized access. Required specifications include:

  • Unique user identification — every user gets a distinct ID; shared logins are not compliant
  • Emergency access procedure — a documented process for accessing ePHI during emergencies
  • Audit controls — logging who accessed what and when (required at the standard level)
  • Person or entity authentication — verifying that users are who they claim to be

Addressable specifications include automatic logoff, encryption/decryption, and transmission security. The Security Rule does not mandate specific technologies — choices must be appropriate to the entity's size, complexity, and risk profile under 45 CFR 164.306(b).

Required vs. Addressable: A Critical Distinction

Under 45 CFR 164.306(d), "addressable" defines how to comply — not whether to comply. Each addressable specification follows one of three paths:

  • Implement it — if reasonable and appropriate for the entity's environment
  • Document an equivalent alternative — if the specification doesn't fit, implement a comparable measure and record the rationale
  • Never skip without documentation — an undocumented gap is a violation, regardless of intent

HIPAA Security Rule required versus addressable specifications decision flow diagram

NIST SP 800-66 Rev. 2 identifies the full breakdown: 14 Required and 22 Addressable implementation specifications, plus six required standards without separate specifications — producing a commonly referenced total of 20 Required and 22 Addressable when those standards are counted.


The Breach Notification Rule: Obligations When PHI Is Compromised

What Constitutes a Breach

A breach is the unauthorized acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule. Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate — through documented risk assessment — a low probability that PHI was compromised.

Unsecured PHI is PHI that has not been rendered unusable or indecipherable through encryption or destruction. Properly encrypted PHI that is lost or stolen does not trigger breach notification obligations. This makes encryption one of the most practical risk-management tools available.

The Four-Factor Risk Assessment

When a potential breach occurs, covered entities must conduct a documented assessment of four factors:

  1. The nature and extent of PHI involved, including identifier types and re-identification likelihood
  2. Who accessed or could have accessed the PHI, and whether they were authorized
  3. Whether the PHI was actually acquired or viewed
  4. The extent to which the risk has been mitigated since the incident

Four-factor HIPAA breach risk assessment process flow infographic

Only if this analysis demonstrates a low probability of compromise can the entity treat the incident as not a reportable breach. Otherwise, notification is required.

Notification Timeline and Requirements

Recipient Trigger Deadline
Affected individuals Any breach of unsecured PHI Within 60 days of discovery
HHS Secretary Breach affecting 500+ individuals Contemporaneously with individual notice
HHS Secretary Breach affecting fewer than 500 individuals No later than 60 days after calendar year end
Media (prominent outlets) Breach affecting 500+ residents of a state or jurisdiction Within 60 days of discovery

A valid notification must include: a description of what happened and when, the types of PHI involved, protective steps individuals should take, and what the entity is doing to investigate and prevent recurrence.

Business Associate Obligations

These timelines apply even when the breach originates outside your organization. When a business associate discovers a breach, it must notify the covered entity without unreasonable delay and no later than 60 days after discovery. The covered entity remains ultimately responsible for notification to individuals and HHS, even when the breach originated with the business associate. BAA provisions should explicitly define discovery timelines, notification contacts, and incident documentation requirements — gaps in those terms become your liability.


How the Three Rules Work Together in a Compliance Program

The three rules are interdependent. The Privacy Rule defines what PHI is and who may access it. The Security Rule defines how ePHI must be protected. The Breach Notification Rule defines the response when those protections fail. A gap in one typically produces violations in the others — for example, no encryption means a lost device triggers both a Security Rule failure and a Breach Notification obligation.

What a Functional Compliance Program Looks Like

A compliant program requires all of the following — not a subset:

  • Written privacy and security policies mapped to each rule
  • Designated privacy officer and security officer
  • Annual workforce training with documented completion records
  • Periodic, documented risk assessments (required, not optional)
  • BAAs with all vendors and subcontractors who touch PHI
  • An incident response plan covering breach identification, risk assessment, and notification procedures

HIPAA compliance program six required components checklist infographic

For medical device manufacturers with connected devices or software that interacts with hospital systems, HIPAA obligations intersect with ISO 13485 and FDA 21 CFR Part 820 requirements — meaning the same workforce training records that satisfy OCR also serve FDA and registrar audits.

QMS Learning's Medical Device & Life Sciences pathway (pilot cohort opening Q3 2026) addresses this overlap directly. It includes a dedicated HIPAA Privacy & Security course covering the Privacy Rule, Security Rule, breach notification, and BAA obligations alongside ISO 13485, FDA 21 CFR Part 820, and ISO 14971. The Manager Dashboard exports timestamped training records and competency data as an Audit-Evidence Package accepted for both OCR investigations and ISO 13485 audits.

One compliance gap organizations frequently create: reading the Security Rule's technology neutrality as leniency. OCR expects covered entities to document why they chose specific safeguards through a formal risk analysis. Controls implemented by assumption — without documented justification — leave a retroactively difficult gap when OCR investigates.


HIPAA Violations and Penalties: What Non-Compliance Actually Costs

Civil Penalty Tiers

OCR enforces a four-tier civil penalty structure. The following amounts reflect the 2025 inflation-adjusted schedule, applicable to penalties assessed on or after January 28, 2026:

Tier Condition Per Violation Annual Cap (Identical Violations)
1 Did not know and could not have known $145–$73,011 $2,190,294
2 Reasonable cause, not willful neglect $1,461–$73,011 $2,190,294
3 Willful neglect, corrected within 30 days $14,602–$73,011 $2,190,294
4 Willful neglect, not corrected $73,011–$2,190,294 $2,190,294

OCR also imposes Corrective Action Plans (CAPs) alongside financial penalties. CAPs carry their own operational burden: multi-year oversight, implementation reports, required training, and reportable-event obligations.

Two recent resolutions illustrate the range. Anthem's 2018 settlement — $16 million for a breach affecting nearly 79 million people — included a two-year CAP requiring enterprise risk analysis, system-activity review, and documented workforce training. A 2025 resolution with Elgon, Inc. following a ransomware incident affecting 31,248 individuals resulted in an $80,000 payment and a three-year CAP with identical structural requirements.

Most Commonly Cited Violations

OCR enforcement data from April 2003 through October 2024 identifies the five most frequently investigated issues:

  1. Impermissible uses and disclosures of PHI
  2. Lack of PHI safeguards
  3. Lack of patient access to records
  4. Lack of ePHI administrative safeguards
  5. Uses and disclosures exceeding the minimum necessary standard

OCR top five most cited HIPAA violations ranked bar chart infographic

OCR's 2023 breach report found that hacking and IT incidents — not employee negligence — represented approximately 81% of large breach reports, affecting 96% of individuals whose information was exposed in reportable breaches. Minimum-necessary and workforce training violations tend to drive complaint-based investigations rather than large-scale breach reports.

The absence of documented, role-specific training records transforms a potential Tier 1 issue into evidence of willful neglect.

Criminal Penalties

Civil penalties address negligence. Intentional violations cross into criminal territory, where the Department of Justice — not OCR — prosecutes under 42 U.S.C. § 1320d-6:

  • Knowing violation — up to $50,000 fine and 1 year imprisonment
  • Violation under false pretenses — up to $100,000 fine and 5 years imprisonment
  • Violation for commercial advantage, personal gain, or malicious harm — up to $250,000 fine and 10 years imprisonment

Frequently Asked Questions

What are the components of HIPAA?

HIPAA has five titles, but its operational compliance obligations are defined by five Administrative Simplification rules: the Privacy Rule, Security Rule, Breach Notification Rule, Transactions and Code Sets Rule, and Enforcement Rule. The first three are the rules most directly relevant to day-to-day compliance for covered entities and business associates.

What is the difference between the HIPAA Privacy Rule and the Security Rule?

The Privacy Rule governs all forms of PHI — electronic, paper, and oral — and defines who can use or disclose it and under what conditions. The Security Rule applies only to electronic PHI and specifies the administrative, physical, and technical safeguards required to protect it. Satisfying the Security Rule does not automatically satisfy the Privacy Rule — both apply independently to ePHI.

Who is considered a covered entity under HIPAA?

Covered entities are healthcare providers that transmit health information electronically, health plans, and healthcare clearinghouses. Business associates — third parties that handle PHI on behalf of a covered entity — are also directly bound by HIPAA under the 2013 Omnibus Rule, not just through contractual obligation.

What qualifies as a HIPAA breach, and when must it be reported?

A breach is the unauthorized acquisition, access, use, or disclosure of unsecured PHI. Covered entities must notify affected individuals and HHS within 60 days of discovering the breach. Breaches affecting 500 or more residents of a state or jurisdiction also require notification to prominent local media within the same 60-day window.

What are the penalties for violating HIPAA?

Civil penalties range from $145 per violation for unknowing violations up to $2,190,294 per violation for uncorrected willful neglect. Criminal penalties apply for intentional violations and can include imprisonment; OCR also commonly pairs financial penalties with corrective action plans that carry years of monitored compliance obligations.

What is protected health information (PHI) and what does it include?

PHI is individually identifiable health information tied to a person's past, present, or future condition, care, or payment — held or transmitted in any format by a covered entity or business associate. It encompasses 18 specific identifiers, including name, address, date of birth, Social Security number, medical record numbers, IP addresses, and biometric data.