What HIPAA Is and Why It Applies to Your Organization
Congress enacted the Health Insurance Portability and Accountability Act in 1996 to address two problems simultaneously: the portability of health coverage when workers changed jobs, and the growing need for national standards governing the electronic exchange and protection of health information. The law’s administrative simplification provisions, codified at 45 CFR Parts 160 and 164, established the framework that organizations operating in healthcare and related sectors must follow today.
HIPAA does not apply universally to all businesses that touch health information. It applies specifically to covered entities and their business associates. Understanding whether your organization is a covered entity, a business associate, or neither is the first and most consequential question in any HIPAA compliance analysis. Getting that question wrong in either direction creates risk: treating non-covered activities as HIPAA-governed wastes compliance resources, while misidentifying a covered function as exempt leaves organizations exposed to OCR enforcement.
Step 1: Determine Whether Your Organization Is a Covered Entity
HIPAA defines three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers that transmit any health information electronically in connection with a standard HIPAA transaction. Each category has its own scope, and many organizations discover that only part of their operations falls within HIPAA’s reach.
Step 2: Identify Your Business Associates
A business associate is any person or organization that performs functions or activities involving the use or disclosure of protected health information on behalf of a covered entity. Business associates are directly subject to HIPAA’s Security Rule and many Privacy Rule provisions under the HITECH Act amendments. They are not exempt simply because they are vendors rather than healthcare organizations.
Common business associates include cloud storage providers hosting electronic health records, medical billing companies, IT service firms with access to systems containing PHI, law firms handling healthcare litigation, and consultants who analyze patient data. The covered entity must execute a written Business Associate Agreement (BAA) with each business associate before any PHI is shared. A missing BAA is one of the most frequently cited HIPAA violations in OCR investigations.
Step 3: Understand What Protected Health Information Covers
Protected health information (PHI) is individually identifiable health information that is transmitted or maintained in any form or medium by a covered entity or its business associate. The individually identifiable component is critical: health information becomes PHI when it includes any of 18 specific identifiers that could be used to identify the individual, or when there is a reasonable basis to believe the information could be used to identify the person.
Geographic data smaller than state
Dates (except year) related to individual
Phone numbers
Fax numbers
Email addresses
Social Security numbers
Health plan beneficiary numbers
Account numbers
Certificate/license numbers
Vehicle identifiers and serial numbers
Device identifiers and serial numbers
Web URLs
Biometric identifiers (fingerprints, voiceprints)
Full-face photographs
Any other unique identifying number, characteristic, or code
If any of these appear alongside health information, the combined record is PHI.
De-identified health information is not PHI and is not subject to HIPAA’s protections. HHS recognizes two methods for de-identification: the Expert Determination method, where a qualified statistician certifies that the risk of identifying an individual is very small, and the Safe Harbor method, where all 18 identifiers are removed and the covered entity has no actual knowledge that the remaining information could identify an individual. Both methods require documented analysis, not just the deletion of obvious fields like name and date of birth.
Step 4: Apply the Privacy Rule Requirements
The HIPAA Privacy Rule, codified at 45 CFR Part 164 Subpart E, establishes national standards for when covered entities may use or disclose PHI, what rights individuals have over their health information, and what administrative requirements organizations must implement to protect privacy. The Privacy Rule permits certain uses and disclosures without individual authorization and requires others to be authorized in writing by the individual.
The Minimum Necessary standard applies to all uses and disclosures except for treatment purposes. Covered entities must make reasonable efforts to limit PHI used, disclosed, or requested to the minimum necessary to accomplish the intended purpose. A billing department employee who needs a patient’s diagnosis code for a claim does not need access to the patient’s full medical history. Policies, procedures, and access controls must reflect this standard.
Step 5: Implement the Security Rule Safeguards
The HIPAA Security Rule, at 45 CFR Part 164 Subpart C, applies specifically to electronic protected health information (ePHI). It requires covered entities and business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Unlike the Privacy Rule, which governs all forms of PHI, the Security Rule focuses exclusively on electronic information.
The distinction between required and addressable specifications does not mean addressable specifications are optional. An addressable specification must either be implemented as written, or the covered entity must document why implementation is not reasonable and appropriate and implement an equivalent alternative measure. “Addressable” means the organization assesses whether the specification applies and how to implement it, not that it may be ignored.
Step 6: Conduct and Document a Risk Analysis
The Security Rule’s risk analysis requirement under 45 CFR 164.308(a)(1) is both the most important administrative safeguard and the most frequently cited deficiency in OCR investigations and resolution agreements. A risk analysis is a thorough and accurate assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI the organization creates, receives, maintains, or transmits.
A compliant risk analysis must identify all sources of ePHI in the organization, identify threats and vulnerabilities to each source, assess the current controls in place, determine the likelihood and impact of each threat being exploited, assign a risk level, and document the entire process. A general statement that systems are secure is not a risk analysis. The output must be a written document that can be produced to OCR during an investigation and that drives the organization’s risk management plan.
Step 7: Train the Workforce
HIPAA requires covered entities to train all workforce members on their privacy and security policies and procedures as necessary and appropriate for them to carry out their functions. Training is not a one-time event at hiring. It must be updated when policies change and must be documented. The training requirement applies to employees, volunteers, trainees, and others under the direct control of the covered entity, whether or not they receive compensation.
Step 8: Understand the Breach Notification Rule
The HIPAA Breach Notification Rule at 45 CFR Part 164 Subpart D requires covered entities to notify individuals, HHS, and in some cases the media following a breach of unsecured PHI. A breach is an impermissible use or disclosure that compromises the security or privacy of PHI. The rule presumes that any impermissible use or disclosure is a breach unless the covered entity demonstrates through a four-factor risk assessment that there is a low probability the PHI was compromised.
The four-factor risk assessment examines the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; the identity of the unauthorized person who used or received the PHI; whether PHI was actually acquired or viewed; and the extent to which the risk has been mitigated. If this assessment cannot establish a low probability of compromise, the incident is a breach and notification obligations apply.
HIPAA Penalty Structure
OCR enforces HIPAA through a tiered civil monetary penalty structure that distinguishes violations based on the covered entity’s knowledge and culpability. Criminal penalties under 42 USC 1320d-6 apply when individuals knowingly misuse PHI.
Key Takeaways
Frequently Asked Questions
Does HIPAA apply to employers who maintain employee health records?
It depends on the context. HIPAA does not generally apply to employment records, even if they contain medical information, because those records are held by the employer in its capacity as an employer rather than as a covered entity. However, if an employer sponsors a group health plan, the health plan component is a covered entity and the information it holds is subject to HIPAA. The employer must maintain a firewall between health plan information and employment decisions.
What is the difference between a required and an addressable Security Rule specification?
Required specifications must be implemented as stated with no flexibility. Addressable specifications must be assessed by the organization, and if implementation is reasonable and appropriate given the organization’s size, capabilities, and risk environment, they must be implemented. If not reasonable and appropriate, the organization must document why and implement an equivalent alternative. Addressable does not mean optional.
When does the 60-day breach notification clock start?
The clock starts when the covered entity knew or should have known of a breach, not when it completes its investigation. This means delayed internal reporting by workforce members who discover a potential breach extends the organization’s total exposure time even though the external deadline is measured from discovery. Training on immediate internal reporting of suspected breaches is a direct risk management measure.
Are business associates directly liable under HIPAA?
Yes. Under the HITECH Act, business associates are directly liable for compliance with the Security Rule and certain Privacy Rule provisions, including breach notification obligations to the covered entity. OCR can and does bring enforcement actions directly against business associates. The presence of a BAA does not shield a business associate from direct liability for its own HIPAA violations.
Government and Regulatory Sources
- HHS – HIPAA for Professionals
- HHS – HIPAA Privacy Rule, 45 CFR Part 164 Subpart E
- HHS – HIPAA Security Rule, 45 CFR Part 164 Subpart C
- HHS – Breach Notification Rule, 45 CFR Part 164 Subpart D
- HHS – Covered Entities and Business Associates
- HHS – HIPAA Enforcement Actions and Settlements
- eCFR – 45 CFR Part 164 (Full Regulatory Text)
Related VelSafe Articles
- Lead in Buildings: Exposure Trends and Compliance Analysis
- HAZWOPER PPE Levels A and B: Use, Care and Inspection
- HAZWOPER: Scope, Application and Training Requirements
HIPAA Compliance Is an Ongoing Program, Not a One-Time Project
The covered entities and business associates that avoid OCR enforcement actions share one characteristic: they treat HIPAA compliance as an operational program with annual risk analyses, regular workforce training, audited vendor relationships, and documented policies that are actually followed. Organizations that build their compliance program once and never revisit it accumulate risk with every system change, staff turnover, and technology update. The 60-day notification clock, the risk analysis requirement, and the BAA audit obligation all presuppose a program that runs continuously, not a project completed at implementation and forgotten. Find more health information privacy compliance resources at velsafe.com.

