HIPAA Requirements: Complete Compliance Guide

Introduction

HIPAA compliance is a framework of interlocking federal rules — the Privacy Rule, Security Rule, Breach Notification Rule, and Omnibus Rule — governing how organizations create, receive, maintain, or transmit protected health information (PHI).

Staying compliant means running an operational program that holds up when OCR asks for evidence — not completing a checklist once and filing it away.

Healthcare averaged $9.77 million per breach in 2024 — the highest of any industry for the 14th consecutive year. In that same year, OCR completed 1,370 complaint investigations and obtained 22 monetary resolutions totaling nearly $10 million. Penalties range from hundreds to millions of dollars per violation category, and criminal prosecution is on the table for knowing violations.

This guide covers who must comply, what each rule requires, how to build a defensible program, and what the 2025 proposed Security Rule amendments mean for your organization.


Key Takeaways

  • HIPAA applies to covered entities and business associates — vendors, cloud providers, and technology partners face the same penalty exposure as healthcare organizations.
  • Compliance rests on four rules: Privacy, Security, Breach Notification, and Omnibus — each with distinct, non-overlapping requirements.
  • The Security Rule's risk analysis is a living, ongoing obligation that requires continuous monitoring and documentation updates.
  • OCR reviews documented evidence of operational controls during investigations — a written program with no proof of implementation will not hold up.
  • The 2025 proposed Security Rule amendments would mandate encryption and MFA — organizations should meet those requirements now, before finalization.

Who Must Comply With HIPAA

Covered Entities

A covered entity is a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with a HIPAA-covered transaction (45 CFR 160.103). The test is functional — it turns on whether the organization transmits health information electronically in covered transactions.

Size does not create an exemption. A small physician practice that submits electronic claims is a covered entity; a large research hospital that doesn't transmit in covered transactions would not be.

Covered entities include:

  • Hospitals, physician practices, clinics, and pharmacies
  • Health insurers, HMOs, and employer-sponsored health plans
  • Healthcare clearinghouses that process health information

Business Associates

A business associate is any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a covered function or service. The definition is broader than most organizations expect.

Business associates include:

  • Cloud service providers storing or processing ePHI (even when they cannot decrypt the data)
  • Billing companies, coding vendors, and revenue cycle management firms
  • IT vendors, managed service providers, and SaaS platforms with PHI access
  • Legal counsel and consultants handling PHI in the course of their engagement

Since the 2013 Omnibus Rule, business associates face the same direct penalty exposure as covered entities. A Business Associate Agreement (BAA) is legally required before any PHI is shared: without one, the disclosure itself is a violation.


HIPAA covered entities and business associates liability structure comparison infographic

The Four HIPAA Rules: What Each One Requires

All four rules apply simultaneously to covered entities. Three of the four — Privacy, Security, and Breach Notification — apply directly to business associates.

The Privacy Rule

The Privacy Rule establishes what constitutes PHI, who can access it, and under what conditions it can be used or disclosed. PHI includes health information combined with any of 18 specific identifiers (names, dates, geographic data, contact information, account numbers, device identifiers, biometric data, and others) as defined under 45 CFR 164.514.

Key requirements:

  • Permitted uses without patient authorization: treatment, payment, and healthcare operations
  • Minimum Necessary standard (45 CFR 164.502(b)): access must be limited to the minimum PHI needed for each specific purpose — with exceptions for treatment and disclosures to the individual
  • Patient rights: access their PHI, request amendments, and receive an accounting of disclosures

The Security Rule

The Security Rule applies specifically to electronic PHI (ePHI) and requires covered entities and business associates to implement administrative, physical, and technical safeguards ensuring confidentiality, integrity, and availability of ePHI.

The Security Rule is intentionally scalable. A small practice and a large health system face the same standards, but implement controls proportionally to their size, resources, and risk profile. The three safeguard categories are covered in detail in the next section.

The Breach Notification Rule

When unsecured PHI is breached, covered entities must notify:

  • Affected individuals: without unreasonable delay, no later than 60 calendar days after discovery
  • HHS Secretary: within 60 days; large breaches (500+ individuals) require simultaneous media notification
  • Business associates: must notify the covered entity without unreasonable delay, no later than 60 days from discovery

The encryption safe harbor is worth understanding clearly. PHI that was properly encrypted at the time of a breach — and whose encryption keys were not also compromised — is considered unusable, unreadable, or indecipherable, and that breach does not trigger notification requirements. This is one of the strongest practical arguments for treating encryption as mandatory, not optional.

The Omnibus Rule

The 2013 Omnibus Rule (78 FR 5566) made two structural changes that remain in effect today:

  1. Extended direct HIPAA liability to business associates and their subcontractors — subcontractors handling PHI are now directly liable, not just contractually obligated through a BAA
  2. Strengthened patient rights, including the right to receive electronic copies of ePHI held in electronic designated record sets

The Omnibus Rule closed the liability gap that had allowed downstream vendors to operate under softer requirements — subcontractors that previously faced only contractual exposure now carry the same direct enforcement liability as the covered entity itself.


HIPAA Security Rule Safeguards: Administrative, Physical, and Technical

The three safeguard categories are not independent checklists — they work together to create layered protection for ePHI. Some implementation specifications within each category are required (must be implemented); others are addressable (must be implemented unless the entity documents a reasonable and appropriate alternative). The 2025 proposed amendments would eliminate the addressable designation for key controls.

Administrative Safeguards

Administrative safeguards govern how your organization manages the selection, development, and maintenance of security measures. Core requirements include:

  • **Risk analysis and risk management** (45 CFR 164.308(a)(1)): a formal, documented risk analysis identifying threats and vulnerabilities to ePHI — this must be ongoing, not a one-time assessment
  • Security Officer designation: a named individual responsible for policies and procedures
  • Workforce training: documented security awareness and training programs for all workforce members
  • Security incident response: documented procedures for identifying, responding to, and reporting security incidents
  • Contingency planning: backup, disaster recovery, and emergency access procedures

HIPAA Security Rule three safeguard categories administrative physical and technical overview

OCR enforcement consistently cites incomplete or outdated risk analyses as a Security Rule violation. The 2025 Health Fitness Corporation settlement ($227,816) involved failing to conduct an accurate risk analysis until January 2024 — a direct example of what happens when organizations treat risk analysis as a one-time exercise.

Physical Safeguards

Physical safeguards govern access to the physical locations and devices where ePHI resides:

  • Facility access controls: policies limiting physical access to systems containing ePHI
  • Workstation use and security: policies defining appropriate use and physical protection of workstations
  • Device and media controls: procedures governing how electronic media containing ePHI is received, moved, reused, and — critically — disposed of

Media disposal without proper data sanitization is a recurring enforcement trigger. In 2013, Affinity Health Plan paid $1.2 million after returning leased photocopiers with ePHI on hard drives — no erasure, no disposal policy.

Where physical controls manage what people can touch, technical safeguards govern what systems can do — and who is allowed to do it.

Technical Safeguards

Technical safeguards are the technology-based controls protecting ePHI and restricting access to authorized users only. The five required areas under 45 CFR 164.312:

Control Area What It Requires
Access controls Unique user IDs, automatic logoff, encryption/decryption capabilities
Audit controls Recording and examining activity in systems containing ePHI
Integrity controls Preventing improper alteration or destruction of ePHI
Authentication Verifying that users are who they claim to be before granting access
Transmission security Protecting ePHI transmitted over electronic networks

Audit logging is mandatory infrastructure — not an optional reporting feature. OCR regularly cites absent or incomplete audit logging as a Security Rule violation. The Cascade Eye and Skin Centers 2024 settlement ($250,000) included failure to implement procedures for regular review of information system activity — a direct audit controls gap.


Building a HIPAA Compliance Program That Holds Up Under Audit

A written program is not compliance. OCR's standard is whether you can produce evidence that your program is operational when they ask. Six requirements define an audit-ready program:

Risk Assessment and Self-Audits

A Security Risk Assessment is required, but it is not the only audit HIPAA demands. Covered entities must also audit Privacy Rule compliance and document identified gaps. HHS OCR offers a free Security Risk Assessment tool that organizations can use to structure their assessment. One important point: cost alone is not a valid basis for refusing to implement a required safeguard.

Policies, Procedures, and Documentation

HIPAA requires written policies and procedures for every safeguard category. Documentation must be retained for at least six years from creation or the date last in effect (45 CFR 164.530(j)(2) and 164.316(b)(2)(i)).

Documentation is the evidentiary record OCR reviews. Organizations with operational controls but outdated or incomplete documentation fail investigations. Update your documentation on the same schedule you update your controls.

Workforce Training

All workforce members must be trained on privacy and security policies and procedures, with documented evidence that training occurred. Organizations must also maintain sanction policies (164.530(e) and 164.308(a)(1)(ii)(C)) and apply them consistently when violations occur.

One distinction auditors expose quickly: completing training is not the same as developing capability. Teams that pass modules but freeze when a real compliance issue surfaces are common — and OCR investigations reveal the gap fast. For medical device and life sciences teams juggling overlapping HIPAA, ISO 13485, and FDA 21 CFR Part 820 obligations, QMS Learning's Medical Device & Life Sciences pathway combines role-specific training with an AI compliance workbench scoped to all three standards.

Business Associate Management

Business associate agreements carry three hard requirements that auditors verify:

  • Executed before any PHI is shared (no grace period, no after-the-fact corrections)
  • Written to impose substantive technical and contractual safeguards, not just shift liability
  • Reviewed regularly as business relationships and data flows change

Covered entities remain responsible for PHI in a business associate's environment. That responsibility requires controls governing what business associates can access and log — a BAA alone does not satisfy it.

Incident Management and Breach Response

Incident response procedures must be tested, not just written. The distinction matters for penalty exposure: OCR treats a breach from an otherwise operational program differently than one resulting from willful neglect or a program that existed on paper only. If your response procedures haven't been exercised, you cannot credibly demonstrate they work — and OCR will draw that conclusion for you.


HIPAA Penalties, Enforcement, and 2025 Security Rule Updates

HIPAA Penalty Structure

Civil penalties are tiered by culpability. The 2026 inflation-adjusted figures (effective January 28, 2026):

Violation Category Minimum Per Violation Annual Cap
No knowledge $145 $2,190,294
Reasonable cause $1,461 $2,190,294
Willful neglect, corrected $14,602 $2,190,294
Willful neglect, not corrected $73,011 $2,190,294

HIPAA civil penalty four-tier structure by culpability level and annual cap amounts

Multi-year noncompliance multiplies annual cap exposure across each year violations occurred. Criminal penalties under 42 U.S.C. § 1320d-6 apply to knowing violations; the Department of Justice prosecutes covered entities and individuals directly under corporate criminal liability principles.

2025 Proposed Security Rule Amendments

HHS published the most significant proposed overhaul of the Security Rule in January 2025 (90 FR 898, docket HHS-OCR-2024-0020). As of publication, this remains a proposed rule — the comment period closed March 7, 2025, and no final rule has been issued. Given OCR's enforcement posture, organizations should treat these proposed requirements as the operative compliance standard.

The central change: eliminating the required/addressable distinction. Proposed mandatory requirements include:

  • Encryption of ePHI at rest and in transit
  • Multi-factor authentication (MFA)
  • Network segmentation
  • Annual technology asset inventory and network map
  • Documented incident response and disaster recovery plans with 72-hour restoration capability
  • Annual written verification from business associates that technical safeguards are deployed

OCR Enforcement Posture

In 2024, OCR resolved 28,228 complaints and completed 1,370 complaint investigations, securing 22 monetary resolutions totaling $9,944,612. OCR's audit program targets covered entities and business associates proactively — a breach is not required to trigger a compliance review.

Recent settlements show where organizations fall short:

  • Solara Medical Supplies — $3 million (2024) for risk analysis failures, phishing vulnerabilities, and breach notification deficiencies
  • Banner Health — $1.25 million (2023) for gaps in risk analysis, audit controls, authentication, and transmission security

OCR doesn't ask whether a compliance program exists. It asks whether it works.


Frequently Asked Questions

What are the three major rules or parts of HIPAA?

HIPAA is most accurately described as having four rules: Privacy, Security, Breach Notification, and Omnibus. Some summaries reference three primary rules because the Omnibus Rule amended and extended the others rather than creating a fully independent framework. All four apply simultaneously to covered entities.

What is not required by HIPAA?

HIPAA does not apply to de-identified data with all 18 identifiers properly removed under 45 CFR 164.514. Encryption is not explicitly required under the current rule, though the 2025 proposed amendments would change this. HIPAA also does not mandate specific technologies or apply to organizations that never handle PHI.

Who is required to comply with HIPAA?

Covered entities — healthcare providers transmitting health information electronically, health plans, and clearinghouses — and business associates that handle PHI on their behalf. Since the 2013 Omnibus Rule, both categories face the same direct penalty exposure.

What are the penalties for HIPAA violations?

Civil penalties range from $145 to $73,011 per violation under 2026-adjusted figures, split across four tiers based on culpability. Multi-year noncompliance multiplies exposure beyond the annual per-category caps. Criminal penalties under 42 U.S.C. § 1320d-6 apply to knowing violations and carry potential imprisonment.

What is the difference between the HIPAA Privacy Rule and the Security Rule?

The Privacy Rule governs all forms of PHI — electronic, paper, and oral — and establishes patient rights and permitted uses and disclosures. The Security Rule applies only to electronic PHI (ePHI) and specifies the administrative, physical, and technical safeguards organizations must implement to protect it.

What does HIPAA require for workforce training?

All workforce members must be trained on privacy and security policies and procedures, with documented evidence that training occurred. Training must be updated when policies change. Organizations must also maintain and apply sanctions against workforce members who violate policies.