Health Insurance Portability and Accountability Act (HIPAA) Overview (US)

GUIDES: Health Insurance Portability and Accountability Act
HIPAA Overview: What US Employers and Covered Entities Must Know About Health Information Privacy
The Health Insurance Portability and Accountability Act sets federal standards for protecting individually identifiable health information. This guide covers who is covered, what information is protected, what the Privacy and Security Rules require, how to train employees, and what penalties apply when organizations fail to comply.
Legal Disclaimer
This article provides educational information about HIPAA requirements. It is not legal or compliance advice. Organizations should consult qualified legal counsel and HIPAA compliance specialists to ensure their programs meet all applicable federal, state, and local requirements.
$1.9M
Average HIPAA Breach Cost
The average cost of a healthcare data breach in the United States reached $1.9 million per incident in recent reporting cycles, including OCR settlements, corrective action costs, notification expenses, and reputational damage to covered organizations.
$2M+
Max Annual Civil Penalty
HHS Office for Civil Rights can impose civil monetary penalties of up to $2,067,813 per calendar year per violation category. The penalty tier system distinguishes between violations caused by willful neglect and those caused by reasonable ignorance of the standard.
60
Days to Report a Breach
Covered entities must notify affected individuals, HHS, and in some cases the media, within 60 days of discovering a breach of unsecured protected health information. Smaller breaches are logged annually; breaches affecting 500 or more individuals require immediate HHS notification.

What HIPAA Is and Why It Applies to Your Organization

Congress enacted the Health Insurance Portability and Accountability Act in 1996 to address two problems simultaneously: the portability of health coverage when workers changed jobs, and the growing need for national standards governing the electronic exchange and protection of health information. The law’s administrative simplification provisions, codified at 45 CFR Parts 160 and 164, established the framework that organizations operating in healthcare and related sectors must follow today.

HIPAA does not apply universally to all businesses that touch health information. It applies specifically to covered entities and their business associates. Understanding whether your organization is a covered entity, a business associate, or neither is the first and most consequential question in any HIPAA compliance analysis. Getting that question wrong in either direction creates risk: treating non-covered activities as HIPAA-governed wastes compliance resources, while misidentifying a covered function as exempt leaves organizations exposed to OCR enforcement.

Step 1: Determine Whether Your Organization Is a Covered Entity

HIPAA defines three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers that transmit any health information electronically in connection with a standard HIPAA transaction. Each category has its own scope, and many organizations discover that only part of their operations falls within HIPAA’s reach.

Category
Examples
Key Compliance Trigger
Health Plans
Group health plans, HMOs, Medicare, Medicaid, employer-sponsored health plans with 50+ participants
Any plan that provides or pays the cost of medical care and meets the enrollment threshold. Small employer plans administered entirely by the employer may be exempt from certain requirements but not all HIPAA provisions.
Healthcare Clearinghouses
Billing services, repricing companies, community health information systems
Any entity that processes nonstandard health information received from another entity into a standard format, or vice versa. Clearinghouses receive protected health information and translate it, which makes them covered entities by function.
Healthcare Providers
Hospitals, physician practices, dentists, pharmacies, home health agencies, occupational health clinics
Any provider that furnishes health services AND transmits any health information electronically in connection with a HIPAA standard transaction such as claims submission, eligibility inquiries, or referral authorizations. Providers who conduct all transactions on paper are technically not covered, but very few providers operate this way today.

Step 2: Identify Your Business Associates

A business associate is any person or organization that performs functions or activities involving the use or disclosure of protected health information on behalf of a covered entity. Business associates are directly subject to HIPAA’s Security Rule and many Privacy Rule provisions under the HITECH Act amendments. They are not exempt simply because they are vendors rather than healthcare organizations.

Common business associates include cloud storage providers hosting electronic health records, medical billing companies, IT service firms with access to systems containing PHI, law firms handling healthcare litigation, and consultants who analyze patient data. The covered entity must execute a written Business Associate Agreement (BAA) with each business associate before any PHI is shared. A missing BAA is one of the most frequently cited HIPAA violations in OCR investigations.

What a Business Associate Agreement Must Include
Permitted Uses and Disclosures
Specify exactly what PHI the BA may use and for what purposes. Uses not listed in the BAA are not authorized.
Safeguard Obligations
The BA must implement appropriate administrative, physical, and technical safeguards to protect PHI and prevent uses or disclosures not authorized by the agreement.
Breach Reporting
The BA must report any use or disclosure of PHI not permitted by the BAA, including security incidents and breaches, to the covered entity without unreasonable delay.
Termination and Return of PHI
Upon termination, the BA must return or destroy all PHI received from or created on behalf of the covered entity and retain no copies.

Step 3: Understand What Protected Health Information Covers

Protected health information (PHI) is individually identifiable health information that is transmitted or maintained in any form or medium by a covered entity or its business associate. The individually identifiable component is critical: health information becomes PHI when it includes any of 18 specific identifiers that could be used to identify the individual, or when there is a reasonable basis to believe the information could be used to identify the person.

Direct Identifiers
Names
Geographic data smaller than state
Dates (except year) related to individual
Phone numbers
Fax numbers
Email addresses
Social Security numbers
Account and Record Identifiers
Medical record numbers
Health plan beneficiary numbers
Account numbers
Certificate/license numbers
Vehicle identifiers and serial numbers
Device identifiers and serial numbers
Web URLs
Biometric and Other Identifiers
IP addresses
Biometric identifiers (fingerprints, voiceprints)
Full-face photographs
Any other unique identifying number, characteristic, or code

If any of these appear alongside health information, the combined record is PHI.

De-identified health information is not PHI and is not subject to HIPAA’s protections. HHS recognizes two methods for de-identification: the Expert Determination method, where a qualified statistician certifies that the risk of identifying an individual is very small, and the Safe Harbor method, where all 18 identifiers are removed and the covered entity has no actual knowledge that the remaining information could identify an individual. Both methods require documented analysis, not just the deletion of obvious fields like name and date of birth.

Step 4: Apply the Privacy Rule Requirements

The HIPAA Privacy Rule, codified at 45 CFR Part 164 Subpart E, establishes national standards for when covered entities may use or disclose PHI, what rights individuals have over their health information, and what administrative requirements organizations must implement to protect privacy. The Privacy Rule permits certain uses and disclosures without individual authorization and requires others to be authorized in writing by the individual.

Disclosure Type
Authorization Required?
Key Conditions
Treatment, payment, and healthcare operations
No
The most common permitted uses. PHI may be shared for treatment purposes, to process payment claims, and for defined healthcare operations such as quality improvement and training, without individual authorization.
Public health activities
No
Disclosures to public health authorities for disease surveillance, reporting of adverse events, and public health interventions are permitted without authorization under specific conditions.
Marketing and sale of PHI
Yes
Using PHI to market products or services not related to treatment, or selling PHI to third parties, requires explicit written authorization from the individual. HITECH significantly restricted these uses.
Most other disclosures to third parties
Yes
Sharing PHI with employers, life insurers, or any party for purposes unrelated to treatment, payment, or operations requires a signed, HIPAA-compliant authorization from the individual, specifying what is shared, with whom, and for what purpose.
Source: HHS | HIPAA Privacy Rule

The Minimum Necessary standard applies to all uses and disclosures except for treatment purposes. Covered entities must make reasonable efforts to limit PHI used, disclosed, or requested to the minimum necessary to accomplish the intended purpose. A billing department employee who needs a patient’s diagnosis code for a claim does not need access to the patient’s full medical history. Policies, procedures, and access controls must reflect this standard.

Step 5: Implement the Security Rule Safeguards

The HIPAA Security Rule, at 45 CFR Part 164 Subpart C, applies specifically to electronic protected health information (ePHI). It requires covered entities and business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Unlike the Privacy Rule, which governs all forms of PHI, the Security Rule focuses exclusively on electronic information.

Safeguard Type
What It Covers
Required vs. Addressable
Administrative
Security management process, assigned security responsibility, workforce training and management, information access management, security incident procedures, contingency planning, periodic evaluations
Mix of required and addressable specifications. The risk analysis and risk management specifications are required with no flexibility.
Physical
Facility access controls, workstation use policies, workstation security, device and media controls including disposal and re-use procedures for hardware containing ePHI
Mix of required and addressable. Facility access controls and device disposal procedures are areas where OCR frequently finds violations during investigations.
Technical
Access controls, audit controls, integrity controls to prevent improper alteration or destruction of ePHI, transmission security including encryption of ePHI sent over open networks
Access controls and audit controls are required. Encryption is addressable, but OCR’s position is that encryption should be implemented unless a documented alternative equivalent measure is in place.
Source: HHS | HIPAA Security Rule

The distinction between required and addressable specifications does not mean addressable specifications are optional. An addressable specification must either be implemented as written, or the covered entity must document why implementation is not reasonable and appropriate and implement an equivalent alternative measure. “Addressable” means the organization assesses whether the specification applies and how to implement it, not that it may be ignored.

Step 6: Conduct and Document a Risk Analysis

The Security Rule’s risk analysis requirement under 45 CFR 164.308(a)(1) is both the most important administrative safeguard and the most frequently cited deficiency in OCR investigations and resolution agreements. A risk analysis is a thorough and accurate assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI the organization creates, receives, maintains, or transmits.

A compliant risk analysis must identify all sources of ePHI in the organization, identify threats and vulnerabilities to each source, assess the current controls in place, determine the likelihood and impact of each threat being exploited, assign a risk level, and document the entire process. A general statement that systems are secure is not a risk analysis. The output must be a written document that can be produced to OCR during an investigation and that drives the organization’s risk management plan.

Step 7: Train the Workforce

HIPAA requires covered entities to train all workforce members on their privacy and security policies and procedures as necessary and appropriate for them to carry out their functions. Training is not a one-time event at hiring. It must be updated when policies change and must be documented. The training requirement applies to employees, volunteers, trainees, and others under the direct control of the covered entity, whether or not they receive compensation.

Training Element
What It Must Cover and Why
Privacy policies and procedures
Workers must understand what PHI is, when they may access and use it, and when they must obtain authorization or apply the minimum necessary standard. Generic training that does not address the organization’s actual PHI handling practices does not meet the requirement.
Security awareness
The Security Rule requires a security awareness and training program for all workforce members, including periodic security reminders. This must cover malicious software protection, log-in monitoring, and password management at minimum.
Breach recognition and reporting
Workers must know how to recognize a potential breach or impermissible use or disclosure, and must know how and to whom to report it internally. The 60-day notification clock starts from when the covered entity knows or should have known of a breach, so delayed internal reporting compounds violations.
Documentation and records
Training completion must be documented and retained for six years from the date of creation or last effective date, whichever is later. OCR investigations routinely request training records. Organizations that cannot produce them face sanctions regardless of whether training actually occurred.

Step 8: Understand the Breach Notification Rule

The HIPAA Breach Notification Rule at 45 CFR Part 164 Subpart D requires covered entities to notify individuals, HHS, and in some cases the media following a breach of unsecured PHI. A breach is an impermissible use or disclosure that compromises the security or privacy of PHI. The rule presumes that any impermissible use or disclosure is a breach unless the covered entity demonstrates through a four-factor risk assessment that there is a low probability the PHI was compromised.

The four-factor risk assessment examines the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; the identity of the unauthorized person who used or received the PHI; whether PHI was actually acquired or viewed; and the extent to which the risk has been mitigated. If this assessment cannot establish a low probability of compromise, the incident is a breach and notification obligations apply.

HIPAA Penalty Structure

OCR enforces HIPAA through a tiered civil monetary penalty structure that distinguishes violations based on the covered entity’s knowledge and culpability. Criminal penalties under 42 USC 1320d-6 apply when individuals knowingly misuse PHI.

Violation Category
Min Per Violation
Max Per Violation
Annual Cap
Did not know (and could not have known)
$137
$68,928
$2,067,813
Reasonable cause (not willful neglect)
$1,379
$68,928
$2,067,813
Willful neglect, corrected within 30 days
$13,785
$68,928
$2,067,813
Willful neglect, not corrected
$68,928
$2,067,813
$2,067,813

Key Takeaways

Start with Covered Entity Status
Before building any compliance program, confirm whether your organization is a covered entity and in what capacity. Many compliance failures begin with organizations applying HIPAA inconsistently because they never precisely defined the scope of their covered functions. Document the analysis.
The Risk Analysis Is Non-Negotiable
OCR’s enforcement record shows that missing or inadequate risk analyses appear in the majority of resolution agreements. A completed, documented risk analysis is the foundation of every other Security Rule safeguard. If you have not done one, every other security investment rests on an unstable base.
BAAs Must Be in Place Before PHI Flows
Every vendor, consultant, or service provider with access to PHI needs a signed Business Associate Agreement before any PHI is shared. Audit your vendor relationships annually. Technology changes faster than vendor contract reviews, and a cloud migration can create new BA relationships that are not covered by existing agreements.

Frequently Asked Questions

Does HIPAA apply to employers who maintain employee health records?
It depends on the context. HIPAA does not generally apply to employment records, even if they contain medical information, because those records are held by the employer in its capacity as an employer rather than as a covered entity. However, if an employer sponsors a group health plan, the health plan component is a covered entity and the information it holds is subject to HIPAA. The employer must maintain a firewall between health plan information and employment decisions.

What is the difference between a required and an addressable Security Rule specification?
Required specifications must be implemented as stated with no flexibility. Addressable specifications must be assessed by the organization, and if implementation is reasonable and appropriate given the organization’s size, capabilities, and risk environment, they must be implemented. If not reasonable and appropriate, the organization must document why and implement an equivalent alternative. Addressable does not mean optional.

When does the 60-day breach notification clock start?
The clock starts when the covered entity knew or should have known of a breach, not when it completes its investigation. This means delayed internal reporting by workforce members who discover a potential breach extends the organization’s total exposure time even though the external deadline is measured from discovery. Training on immediate internal reporting of suspected breaches is a direct risk management measure.

Are business associates directly liable under HIPAA?
Yes. Under the HITECH Act, business associates are directly liable for compliance with the Security Rule and certain Privacy Rule provisions, including breach notification obligations to the covered entity. OCR can and does bring enforcement actions directly against business associates. The presence of a BAA does not shield a business associate from direct liability for its own HIPAA violations.

Government and Regulatory Sources

Related VelSafe Articles

HIPAA Compliance Is an Ongoing Program, Not a One-Time Project

The covered entities and business associates that avoid OCR enforcement actions share one characteristic: they treat HIPAA compliance as an operational program with annual risk analyses, regular workforce training, audited vendor relationships, and documented policies that are actually followed. Organizations that build their compliance program once and never revisit it accumulate risk with every system change, staff turnover, and technology update. The 60-day notification clock, the risk analysis requirement, and the BAA audit obligation all presuppose a program that runs continuously, not a project completed at implementation and forgotten. Find more health information privacy compliance resources at velsafe.com.

Tags: No tags

Add a Comment

Your email address will not be published. Required fields are marked *