HIPAA privacy standards insights article featured image showing a female healthcare privacy officer holding a compliance audit clipboard in front of a Notice of Privacy Practices wall notice, with a donut chart of top OCR investigation categories in the left panel.

HIPAA Privacy Standards: What They Actually Require and Why Organisations Still Get Them Wrong

INSIGHTS: HIPAA Compliance
HIPAA Privacy Standards: What They Actually Require and Why Organisations Still Get Them Wrong
HIPAA’s Privacy Rule has been in effect since 2003. Despite more than two decades of enforcement, privacy standard failures remain the most commonly cited category in HHS Office for Civil Rights investigations. This analysis examines what the Privacy Rule’s core standards actually require, how enforcement patterns have evolved, and where the persistent gaps between policy and practice tend to appear in healthcare organisations of every size.
Executive Summary
The HIPAA Privacy Rule establishes national standards for the protection of individually identifiable health information. Its core requirements cover notice of privacy practices, access rights, uses and disclosures, minimum necessary standards, administrative safeguards, and workforce training. Twenty years of HHS enforcement data show that impermissible disclosures, failures to provide access, and inadequate safeguards account for the majority of investigated complaints and resolved enforcement actions. This article examines each core standard, analyses the enforcement record, and identifies the implementation gaps that account for persistent non-compliance across the healthcare sector.
$1.93B
Total OCR Settlements
HHS OCR has collected over $1.93 billion in settlements and civil monetary penalties since the Privacy Rule took effect, through its published enforcement data. The average settlement across all resolved actions reflects the wide variation in penalty levels across the four HITECH culpability tiers.
Source: HHS OCR | Enforcement Highlights
#1
Impermissible Disclosure
Impermissible uses or disclosures of PHI have consistently ranked as the most investigated issue category in HHS OCR’s annual summaries of resolved investigations. This category covers a wide range of conduct from unauthorised sharing with employers to social media disclosures by workforce members.
Source: HHS OCR | OCR Complaint Data
2003
Privacy Rule in Effect
The HIPAA Privacy Rule became effective for most covered entities in April 2003. It has been amended by the HITECH Act (2009), the Omnibus Rule (2013), and the 2024 amendments addressing reproductive health information. Despite its longevity, enforcement actions for basic Privacy Rule violations continue at a steady rate across all covered entity categories.
Source: HHS | HIPAA Privacy Rule

What the Privacy Rule Actually Requires: The Core Standards

The HIPAA Privacy Rule is codified at 45 CFR Parts 160 and 164. Its privacy requirements span approximately 40 regulatory sections covering eight major standard areas. Understanding what each standard actually requires, as distinct from what organisations often implement in its place, is the starting point for addressing persistent compliance gaps.

Expert Insight: The Gap Between Policy and Practice
The most common finding in HIPAA investigations is not that an organisation had no privacy policy. It is that the organisation had a policy that workforce members had not been trained on, or had been trained on at a level of generality that left them unable to apply it to the specific situations they actually encountered. A Notice of Privacy Practices posted in the waiting room satisfies a regulatory requirement. It does not substitute for the workforce training that determines whether PHI is actually handled correctly at the point of care, the billing desk, or the front reception.

Standard 1: Notice of Privacy Practices

The Notice of Privacy Practices (NPP) requirement under 45 CFR 164.520 is one of the most visible Privacy Rule requirements and one of the most frequently misunderstood. The regulation requires covered entities to provide individuals with a notice describing how the entity may use and disclose PHI, the individual’s rights with respect to that information, and the entity’s duties to protect it. For direct treatment providers, the NPP must be provided at the first service delivery and a good-faith effort to obtain written acknowledgement of receipt must be made.

Where organisations commonly fall short is in keeping the NPP current. The Privacy Rule requires that the NPP reflect the entity’s current privacy practices. When policies change, particularly following the 2013 Omnibus Rule’s changes to authorisation requirements and the 2024 amendments addressing reproductive health data, NPPs that were accurate when drafted become inaccurate representations of the organisation’s obligations. HHS OCR has resolved enforcement actions where the NPP in use at the time of investigation described practices that were no longer compliant with the current regulatory framework.

Healthcare organisations that operate across multiple practice locations face an additional complexity: the NPP must apply to the covered healthcare component, and in large health systems with hybrid entity designations, defining the boundaries of that component for NPP purposes requires careful legal review that many organisations have not completed.

Standard 2: Individual Access Rights

The individual right of access under 45 CFR 164.524 has been the subject of sustained OCR enforcement activity through its Right of Access Initiative, launched in 2019. Under this standard, individuals have the right to access and obtain copies of their PHI in a designated record set. The covered entity must provide access within 30 days of the request, in the format requested by the individual if readily producible, and at a fee that does not exceed the labour cost of copying the record.

Requirement
What the Rule Says
Common Violation
Response timeline
30 days; one 30-day extension with written notice
Exceeding 30 days without extension notice
Format of access
Electronic format if maintained electronically and requested
Providing paper when electronic was requested and available
Fee limitation
Labour cost of copying only; no retrieval or handling fees
Charging per-page fees that exceed actual labour cost
Scope of records
All PHI in the designated record set unless an exception applies
Excluding records that are not actually exempt from access
Source: HHS OCR | Right of Access Guidance

OCR’s Right of Access Initiative has resulted in more than 45 enforcement actions since 2019, targeting a range of covered entity types including hospitals, physician practices, and specialty providers. The penalties in these cases have been relatively modest individually, but the volume of actions signals that OCR treats access failures as a systematic enforcement priority rather than an edge case.

Standard 3: Minimum Necessary and Workforce Access Controls

The minimum necessary standard at 45 CFR 164.502(b) requires that covered entities make reasonable efforts to limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose. For workforce members, this means implementing policies that identify the categories of PHI each role may access and the purposes for which that access is permitted.

In practice, the minimum necessary standard is frequently implemented as a policy on paper without the access control infrastructure to enforce it in EHR systems and other PHI repositories. A policy that states “workforce members should access only the PHI relevant to their duties” creates a compliance obligation. It does not satisfy that obligation without corresponding role-based access controls in the technical systems where PHI is maintained. Where EHR systems are configured to allow broad access by default and narrowed only by exception, the minimum necessary standard is difficult to demonstrate compliance with regardless of what the written policy says.

Audit log review is the mechanism through which minimum necessary compliance can be demonstrated and gaps can be identified. OCR investigations frequently include requests for audit log data showing who accessed which records and when. Organisations that have not implemented or are not regularly reviewing audit logs for anomalous access patterns find themselves unable to demonstrate compliance and unable to detect the internal snooping that generates a disproportionate share of privacy complaints.

Standard 4: Administrative Requirements

The administrative requirements under 45 CFR 164.530 are the operational backbone of Privacy Rule compliance. They cover six areas that translate the substantive standards into functional requirements.

Privacy Officer Designation (164.530(a))
Every covered entity and business associate must designate a privacy official responsible for developing and implementing privacy policies. This is a named individual, not a committee or a role title without a named person. OCR investigation requests frequently include asking for the name and contact information of the privacy officer, and an inability to provide this information quickly is a compliance gap signal.
Workforce Training (164.530(b))
Training is required for all workforce members whose work brings them into contact with PHI, before they perform relevant functions and within a reasonable period after material policy changes. Training documentation must be retained for six years. The frequency and depth of training is not specified in the regulation, which is where most organisations under-invest: annual completion of a general HIPAA module satisfies the literal requirement but not the functional one.
Sanctions Policy (164.530(e))
Covered entities must have and apply a sanctions policy for workforce members who fail to comply with privacy policies. The critical requirement is that sanctions are actually applied, not just documented. OCR investigators look at whether sanctions policies exist and whether they were applied consistently in documented violation instances. A policy that exists but has never been invoked, even when violations occurred, is evidence of a non-functional compliance programme.
Complaint Process (164.530(d))
Covered entities must provide a mechanism for individuals to file complaints about privacy practices, designate a contact person or office for receiving complaints, and document all complaints received and their dispositions. Complaint handling documentation is one of the first items OCR requests in an investigation. Organisations that have not documented complaint investigations, including those resolved informally, cannot demonstrate a functioning complaint process.

Industry Trends: How Privacy Enforcement Has Evolved

HIPAA privacy enforcement has shifted in character across the rule’s life. The early enforcement period focused on establishing the compliance baseline and addressing systemic failures at large organisations. The HITECH Act’s 2009 amendments dramatically expanded enforcement authority by introducing the four-tier penalty structure, extending obligations to business associates, and requiring HHS to conduct periodic audits of covered entities and business associates.

Enforcement Focus Areas by Period
2003-2009: Baseline establishment Resolution agreements, primarily large entities
Early enforcement focused on large-scale systemic failures. Penalties were capped at $100 per violation, $25,000 per violation category per year. Many investigations resolved with technical assistance rather than formal enforcement.
2009-2016: HITECH expansion Tiered penalties, business associate reach
HITECH dramatically increased maximum penalties and extended direct liability to business associates. Large-scale breach cases produced multi-million dollar settlements. The Omnibus Rule in 2013 finalised business associate requirements and updated the breach notification standard.
2016-2022: Audit programme and targeted enforcement Phase 2 audits, Right of Access Initiative
OCR’s Phase 2 audit programme reviewed covered entities and business associates against a defined set of standards. The Right of Access Initiative launched in 2019 targeted access failures systematically with relatively small but numerous enforcement actions across diverse entity types.
2022-present: Expanded priority areas Reproductive health, telehealth, cybersecurity intersection
The 2024 Privacy Rule amendments addressing reproductive health information created new disclosure prohibitions. Telehealth expansion raised questions about third-party tracking technologies and their interaction with the Privacy Rule, addressed in OCR guidance. Cybersecurity incidents increasingly trigger Privacy Rule investigations alongside Security Rule review.

Regulatory Perspective: What OCR Looks at During an Investigation

HHS OCR investigations are complaint-driven for most privacy matters, though the agency also conducts compliance reviews and audits on its own initiative. When a complaint is received, OCR typically requests a defined set of documents that directly reflects the Privacy Rule’s administrative requirements: the entity’s privacy policies and procedures, the NPP, training documentation, the sanctions policy, the complaint log, and documentation relevant to the specific complaint allegation.

What Triggers Escalation from Investigation to Enforcement Action

Not all investigated complaints result in formal enforcement. OCR resolves the majority of investigations through technical assistance or voluntary compliance. Investigations escalate to formal enforcement when: the entity cannot demonstrate that a required element was in place at the time of the complaint (no training documentation, no privacy officer, no sanctions policy); the violation involved wilful neglect; the entity’s response is inadequate or slow; or the same standard was violated in a prior investigation.

The single most consequential factor is whether the organisation can produce documentation demonstrating that its compliance programme was functional at the relevant time. An organisation that can show training records, policy review histories, complaint logs, and a functional sanctions process is in a substantially different position than one that can only show that policies exist on paper.

Source: HHS OCR | OCR Resolution Agreements

What Organisations With Sustained Compliance Do Differently

They treat the NPP as a living document
Organisations with stable compliance records review the NPP at least annually against current regulatory requirements and update it when policies or regulatory obligations change. They maintain version histories that allow them to demonstrate what the NPP said at any given point in time. The NPP is not filed and forgotten after initial implementation.
They connect audit log review to access policy enforcement
Minimum necessary compliance on paper requires minimum necessary enforcement in practice. Regular audit log review that identifies access anomalies, connects them to the workforce member’s role and the records accessed, and triggers investigation when the access is not consistent with job function is how the standard is actually maintained. Organisations that review audit logs only after a complaint has been filed have already failed the minimum necessary standard for the intervening period.
Their training programme evolves with their operations
When a new EHR platform is deployed, when a telehealth programme launches, when staff move between roles with different PHI access levels, or when the regulatory framework changes, training is updated. The organisations with the lowest complaint rates maintain training as a programme that responds to operational changes rather than a calendar obligation that runs independently of what the organisation is actually doing with PHI.

Key Takeaways

The Privacy Rule’s administrative requirements are not supplementary; they are the compliance programme
A covered entity that has a privacy officer, trained its workforce, documented training, applied its sanctions policy consistently, and maintained its complaint log is in a fundamentally different position than one that has only written policies. OCR investigations reveal this distinction very quickly. The administrative requirements under 45 CFR 164.530 are not paperwork surrounding the substantive standards; they are the mechanism by which organisations demonstrate that the substantive standards are being followed.
Access rights enforcement is a sustained OCR priority, not a background concern
The Right of Access Initiative has produced more enforcement actions than any other single-standard enforcement programme in OCR’s history. The violations targeted are not obscure or technical: providing records too slowly, in the wrong format, or at excessive cost. Every covered entity with a request-for-records process should review that process against the access standard’s specific timeline, format, and fee requirements before an access complaint prompts OCR to do so first.
The 2024 reproductive health amendments require immediate NPP and policy review
The 2024 amendments to the Privacy Rule created new prohibitions on using or disclosing PHI related to reproductive health care sought lawfully under applicable state law. The compliance date for these provisions was December 2024. Covered entities that have not reviewed their NPP, disclosure policies, and authorisation forms against the amended requirements since that date are operating with outdated documentation that may not accurately describe their current obligations.

Frequently Asked Questions

What is included in the HIPAA designated record set for purposes of the access right?
The designated record set includes medical and billing records for covered healthcare providers, enrolment and payment records for health plans, and any other records used to make decisions about individuals. The phrase “used to make decisions” is broader than clinical records alone: case management and utilisation review records may qualify. PHI maintained solely for quality improvement may be excluded but requires fact-specific analysis.

Does HIPAA require covered entities to conduct annual privacy training?
No. The Privacy Rule requires training within a reasonable period of hire and when material changes are made to policies or procedures. It does not specify annual training. Many organisations implement annual training as a programme best practice and because state law, accreditation requirements, or contracting requirements independently impose that expectation. Annual training satisfies the regulatory baseline but should not be mistaken for the full extent of training that a functional privacy programme requires. Role-specific training, onboarding training, and training triggered by policy changes are all part of what the regulation requires and what audits examine.

How does the minimum necessary standard apply to requests for PHI from other covered entities?
Requesting covered entities must limit their requests to the minimum necessary for the stated purpose under 45 CFR 164.502(b)(2). The responding entity may rely on the requestor’s representation of minimum necessity unless it has actual knowledge the request is non-compliant. This reliance provision is significant in practice: the responding entity’s obligation is to produce what is requested, not to independently assess whether the requesting entity actually needs everything it asked for. For routine recurring requests between covered entities, such as referral record transfers or claims audits, standard protocols defining what is routinely included satisfy the minimum necessary determination requirement without requiring individual case-by-case analysis for each transaction, provided the protocol itself reflects minimum necessary principles.

What changed in the 2024 HIPAA Privacy Rule amendments regarding reproductive health?
The 2024 amendments at 45 CFR 164.502(a)(5)(iii) and related provisions prohibit covered entities from using or disclosing PHI to conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for seeking, obtaining, providing, or facilitating lawful reproductive health care. A new required attestation process applies to certain requests for PHI related to reproductive health care. The amendments also require NPP updates to address these new protections. The compliance date was December 23, 2024, with certain attestation requirements phased in from February 16, 2026.

Government and Regulatory Sources

Related VelSafe Articles

Building a Privacy Programme That Holds Up

The HIPAA Privacy Rule’s core standards have not changed in their essentials since 2003. What has changed is the enforcement environment, the complexity of healthcare operations, and the range of technologies through which PHI flows. Organisations that approach privacy compliance as a programme, with a named officer, functioning training, documented complaint handling, applied sanctions, and a current NPP, are in the strongest position regardless of which standard comes under scrutiny. The gap between having written policies and having a working compliance programme is exactly where OCR investigations reveal themselves, and exactly where sustained compliance effort produces the most value. Find more HIPAA and healthcare compliance resources at velsafe.com.

Tags: No tags