What the Privacy Rule Actually Requires: The Core Standards
The HIPAA Privacy Rule is codified at 45 CFR Parts 160 and 164. Its privacy requirements span approximately 40 regulatory sections covering eight major standard areas. Understanding what each standard actually requires, as distinct from what organisations often implement in its place, is the starting point for addressing persistent compliance gaps.
Standard 1: Notice of Privacy Practices
The Notice of Privacy Practices (NPP) requirement under 45 CFR 164.520 is one of the most visible Privacy Rule requirements and one of the most frequently misunderstood. The regulation requires covered entities to provide individuals with a notice describing how the entity may use and disclose PHI, the individual’s rights with respect to that information, and the entity’s duties to protect it. For direct treatment providers, the NPP must be provided at the first service delivery and a good-faith effort to obtain written acknowledgement of receipt must be made.
Where organisations commonly fall short is in keeping the NPP current. The Privacy Rule requires that the NPP reflect the entity’s current privacy practices. When policies change, particularly following the 2013 Omnibus Rule’s changes to authorisation requirements and the 2024 amendments addressing reproductive health data, NPPs that were accurate when drafted become inaccurate representations of the organisation’s obligations. HHS OCR has resolved enforcement actions where the NPP in use at the time of investigation described practices that were no longer compliant with the current regulatory framework.
Healthcare organisations that operate across multiple practice locations face an additional complexity: the NPP must apply to the covered healthcare component, and in large health systems with hybrid entity designations, defining the boundaries of that component for NPP purposes requires careful legal review that many organisations have not completed.
Standard 2: Individual Access Rights
The individual right of access under 45 CFR 164.524 has been the subject of sustained OCR enforcement activity through its Right of Access Initiative, launched in 2019. Under this standard, individuals have the right to access and obtain copies of their PHI in a designated record set. The covered entity must provide access within 30 days of the request, in the format requested by the individual if readily producible, and at a fee that does not exceed the labour cost of copying the record.
OCR’s Right of Access Initiative has resulted in more than 45 enforcement actions since 2019, targeting a range of covered entity types including hospitals, physician practices, and specialty providers. The penalties in these cases have been relatively modest individually, but the volume of actions signals that OCR treats access failures as a systematic enforcement priority rather than an edge case.
Standard 3: Minimum Necessary and Workforce Access Controls
The minimum necessary standard at 45 CFR 164.502(b) requires that covered entities make reasonable efforts to limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose. For workforce members, this means implementing policies that identify the categories of PHI each role may access and the purposes for which that access is permitted.
In practice, the minimum necessary standard is frequently implemented as a policy on paper without the access control infrastructure to enforce it in EHR systems and other PHI repositories. A policy that states “workforce members should access only the PHI relevant to their duties” creates a compliance obligation. It does not satisfy that obligation without corresponding role-based access controls in the technical systems where PHI is maintained. Where EHR systems are configured to allow broad access by default and narrowed only by exception, the minimum necessary standard is difficult to demonstrate compliance with regardless of what the written policy says.
Audit log review is the mechanism through which minimum necessary compliance can be demonstrated and gaps can be identified. OCR investigations frequently include requests for audit log data showing who accessed which records and when. Organisations that have not implemented or are not regularly reviewing audit logs for anomalous access patterns find themselves unable to demonstrate compliance and unable to detect the internal snooping that generates a disproportionate share of privacy complaints.
Standard 4: Administrative Requirements
The administrative requirements under 45 CFR 164.530 are the operational backbone of Privacy Rule compliance. They cover six areas that translate the substantive standards into functional requirements.
Industry Trends: How Privacy Enforcement Has Evolved
HIPAA privacy enforcement has shifted in character across the rule’s life. The early enforcement period focused on establishing the compliance baseline and addressing systemic failures at large organisations. The HITECH Act’s 2009 amendments dramatically expanded enforcement authority by introducing the four-tier penalty structure, extending obligations to business associates, and requiring HHS to conduct periodic audits of covered entities and business associates.
Regulatory Perspective: What OCR Looks at During an Investigation
HHS OCR investigations are complaint-driven for most privacy matters, though the agency also conducts compliance reviews and audits on its own initiative. When a complaint is received, OCR typically requests a defined set of documents that directly reflects the Privacy Rule’s administrative requirements: the entity’s privacy policies and procedures, the NPP, training documentation, the sanctions policy, the complaint log, and documentation relevant to the specific complaint allegation.
Not all investigated complaints result in formal enforcement. OCR resolves the majority of investigations through technical assistance or voluntary compliance. Investigations escalate to formal enforcement when: the entity cannot demonstrate that a required element was in place at the time of the complaint (no training documentation, no privacy officer, no sanctions policy); the violation involved wilful neglect; the entity’s response is inadequate or slow; or the same standard was violated in a prior investigation.
The single most consequential factor is whether the organisation can produce documentation demonstrating that its compliance programme was functional at the relevant time. An organisation that can show training records, policy review histories, complaint logs, and a functional sanctions process is in a substantially different position than one that can only show that policies exist on paper.
What Organisations With Sustained Compliance Do Differently
Key Takeaways
Frequently Asked Questions
What is included in the HIPAA designated record set for purposes of the access right?
The designated record set includes medical and billing records for covered healthcare providers, enrolment and payment records for health plans, and any other records used to make decisions about individuals. The phrase “used to make decisions” is broader than clinical records alone: case management and utilisation review records may qualify. PHI maintained solely for quality improvement may be excluded but requires fact-specific analysis.
Does HIPAA require covered entities to conduct annual privacy training?
No. The Privacy Rule requires training within a reasonable period of hire and when material changes are made to policies or procedures. It does not specify annual training. Many organisations implement annual training as a programme best practice and because state law, accreditation requirements, or contracting requirements independently impose that expectation. Annual training satisfies the regulatory baseline but should not be mistaken for the full extent of training that a functional privacy programme requires. Role-specific training, onboarding training, and training triggered by policy changes are all part of what the regulation requires and what audits examine.
How does the minimum necessary standard apply to requests for PHI from other covered entities?
Requesting covered entities must limit their requests to the minimum necessary for the stated purpose under 45 CFR 164.502(b)(2). The responding entity may rely on the requestor’s representation of minimum necessity unless it has actual knowledge the request is non-compliant. This reliance provision is significant in practice: the responding entity’s obligation is to produce what is requested, not to independently assess whether the requesting entity actually needs everything it asked for. For routine recurring requests between covered entities, such as referral record transfers or claims audits, standard protocols defining what is routinely included satisfy the minimum necessary determination requirement without requiring individual case-by-case analysis for each transaction, provided the protocol itself reflects minimum necessary principles.
What changed in the 2024 HIPAA Privacy Rule amendments regarding reproductive health?
The 2024 amendments at 45 CFR 164.502(a)(5)(iii) and related provisions prohibit covered entities from using or disclosing PHI to conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for seeking, obtaining, providing, or facilitating lawful reproductive health care. A new required attestation process applies to certain requests for PHI related to reproductive health care. The amendments also require NPP updates to address these new protections. The compliance date was December 23, 2024, with certain attestation requirements phased in from February 16, 2026.
Government and Regulatory Sources
- HHS – HIPAA Privacy Rule (45 CFR Parts 160 and 164)
- HHS OCR – HIPAA Enforcement Highlights and Settlement Data
- HHS OCR – Right of Access Guidance
- HHS OCR – Complaints Received by Calendar Year
- HHS OCR – Resolution Agreements and Corrective Action Plans
Related VelSafe Articles
- HIPAA Uses and Disclosures of PHI: Role-Based Training
- HIPAA: The Impact on Clinical Research
- HIPAA Privacy for Medical Device Sales Representatives
Building a Privacy Programme That Holds Up
The HIPAA Privacy Rule’s core standards have not changed in their essentials since 2003. What has changed is the enforcement environment, the complexity of healthcare operations, and the range of technologies through which PHI flows. Organisations that approach privacy compliance as a programme, with a named officer, functioning training, documented complaint handling, applied sanctions, and a current NPP, are in the strongest position regardless of which standard comes under scrutiny. The gap between having written policies and having a working compliance programme is exactly where OCR investigations reveal themselves, and exactly where sustained compliance effort produces the most value. Find more HIPAA and healthcare compliance resources at velsafe.com.


