INSIGHTS: HIPAA Compliance
HIPAA’s Privacy Rule has been in effect since 2003. Despite more than two decades of enforcement, privacy standard failures remain the most commonly cited category in HHS Office for Civil Rights investigations. This analysis examines what the Privacy Rule’s core standards actually require, how enforcement patterns have evolved, and where the persistent gaps between policy and practice tend to appear in healthcare organisations of every size.
Executive Summary
The HIPAA Privacy Rule establishes national standards for the protection of individually identifiable health information. Its core requirements cover notice of privacy practices, access rights, uses and disclosures, minimum necessary standards, administrative safeguards, and workforce training. Twenty years of HHS enforcement data show that impermissible disclosures, failures to provide access, and inadequate safeguards account for the majority of investigated complaints and resolved enforcement actions. This article examines each core standard, analyses the enforcement record, and identifies the implementation gaps that account for persistent non-compliance across the healthcare sector.
$1.93B
Total OCR Settlements
HHS OCR has collected over $1.93 billion in settlements and civil monetary penalties since the Privacy Rule took effect, through its published enforcement data. The average settlement across all resolved actions reflects the wide variation in penalty levels across the four HITECH culpability tiers.
Source: HHS OCR | Enforcement Highlights
#1
Impermissible Disclosure
Impermissible uses or disclosures of PHI have consistently ranked as the most investigated issue category in HHS OCR’s annual summaries of resolved investigations. This category covers a wide range of conduct from unauthorised sharing with employers to social media disclosures by workforce members.
Source: HHS OCR | OCR Complaint Data
2003
Privacy Rule in Effect
The HIPAA Privacy Rule became effective for most covered entities in April 2003. It has been amended by the HITECH Act (2009), the Omnibus Rule (2013), and the 2024 amendments addressing reproductive health information. Despite its longevity, enforcement actions for basic Privacy Rule violations continue at a steady rate across all covered entity categories.
Source: HHS | HIPAA Privacy Rule
What the Privacy Rule Actually Requires: The Core Standards
The HIPAA Privacy Rule is codified at 45 CFR Parts 160 and 164. Its privacy requirements span approximately 40 regulatory sections covering eight major standard areas. Understanding what each standard actually requires, as distinct from what organisations often implement in its place, is the starting point for addressing persistent compliance gaps.
Expert Insight: The Gap Between Policy and Practice
The most common finding in HIPAA investigations is not that an organisation had no privacy policy. It is that the organisation had a policy that workforce members had not been trained on, or had been trained on at a level of generality that left them unable to apply it to the specific situations they actually encountered. A Notice of Privacy Practices posted in the waiting room satisfies a regulatory requirement. It does not substitute for the workforce training that determines whether PHI is actually handled correctly at the point of care, the billing desk, or the front reception.
Source: HHS OCR | OCR Resolution Agreements and CAPs
Standard 1: Notice of Privacy Practices
The Notice of Privacy Practices (NPP) requirement under 45 CFR 164.520 is one of the most visible Privacy Rule requirements and one of the most frequently misunderstood. The regulation requires covered entities to provide individuals with a notice describing how the entity may use and disclose PHI, the individual’s rights with respect to that information, and the entity’s duties to protect it. For direct treatment providers, the NPP must be provided at the first service delivery and a good-faith effort to obtain written acknowledgement of receipt must be made.
Where organisations commonly fall short is in keeping the NPP current. The Privacy Rule requires that the NPP reflect the entity’s current privacy practices. When policies change, particularly following the 2013 Omnibus Rule’s changes to authorisation requirements and the 2024 amendments addressing reproductive health data, NPPs that were accurate when drafted become inaccurate representations of the organisation’s obligations. HHS OCR has resolved enforcement actions where the NPP in use at the time of investigation described practices that were no longer compliant with the current regulatory framework.
Healthcare organisations that operate across multiple practice locations face an additional complexity: the NPP must apply to the covered healthcare component, and in large health systems with hybrid entity designations, defining the boundaries of that component for NPP purposes requires careful legal review that many organisations have not completed.
Standard 2: Individual Access Rights
The individual right of access under 45 CFR 164.524 has been the subject of sustained OCR enforcement activity through its Right of Access Initiative, launched in 2019. Under this standard, individuals have the right to access and obtain copies of their PHI in a designated record set. The covered entity must provide access within 30 days of the request, in the format requested by the individual if readily producible, and at a fee that does not exceed the labour cost of copying the record.
Requirement
What the Rule Says
Common Violation
Response timeline
30 days; one 30-day extension with written notice
Exceeding 30 days without extension notice
Format of access
Electronic format if maintained electronically and requested
Providing paper when electronic was requested and available
Fee limitation
Labour cost of copying only; no retrieval or handling fees
Charging per-page fees that exceed actual labour cost
Scope of records
All PHI in the designated record set unless an exception applies
Excluding records that are not actually exempt from access
Source: HHS OCR | Right of Access Guidance
OCR’s Right of Access Initiative has resulted in more than 45 enforcement actions since 2019, targeting a range of covered entity types including hospitals, physician practices, and specialty providers. The penalties in these cases have been relatively modest individually, but the volume of actions signals that OCR treats access failures as a systematic enforcement priority rather than an edge case.
Standard 3: Minimum Necessary and Workforce Access Controls
The minimum necessary standard at 45 CFR 164.502(b) requires that covered entities make reasonable efforts to limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose. For workforce members, this means implementing policies that identify the categories of PHI each role may access and the purposes for which that access is permitted.
In practice, the minimum necessary standard is frequently implemented as a policy on paper without the access control infrastructure to enforce it in EHR systems and other PHI repositories. A policy that states “workforce members should access only the PHI relevant to their duties” creates a compliance obligation. It does not satisfy that obligation without corresponding role-based access controls in the technical systems where PHI is maintained. Where EHR systems are configured to allow broad access by default and narrowed only by exception, the minimum necessary standard is difficult to demonstrate compliance with regardless of what the written policy says.
Audit log review is the mechanism through which minimum necessary compliance can be demonstrated and gaps can be identified. OCR investigations frequently include requests for audit log data showing who accessed which records and when. Organisations that have not implemented or are not regularly reviewing audit logs for anomalous access patterns find themselves unable to demonstrate compliance and unable to detect the internal snooping that generates a disproportionate share of privacy complaints.
Standard 4: Administrative Requirements
The administrative requirements under 45 CFR 164.530 are the operational backbone of Privacy Rule compliance. They cover six areas that translate the substantive standards into functional requirements.
Privacy Officer Designation (164.530(a))
Every covered entity and business associate must designate a privacy official responsible for developing and implementing privacy policies. This is a named individual, not a committee or a role title without a named person. OCR investigation requests frequently include asking for the name and contact information of the privacy officer, and an inability to provide this information quickly is a compliance gap signal.
Workforce Training (164.530(b))
Training is required for all workforce members whose work brings them into contact with PHI, before they perform relevant functions and within a reasonable period after material policy changes. Training documentation must be retained for six years. The frequency and depth of training is not specified in the regulation, which is where most organisations under-invest: annual completion of a general HIPAA module satisfies the literal requirement but not the functional one.
Sanctions Policy (164.530(e))
Covered entities must have and apply a sanctions policy for workforce members who fail to comply with privacy policies. The critical requirement is that sanctions are actually applied, not just documented. OCR investigators look at whether sanctions policies exist and whether they were applied consistently in documented violation instances. A policy that exists but has never been invoked, even when violations occurred, is evidence of a non-functional compliance programme.
Complaint Process (164.530(d))
Covered entities must provide a mechanism for individuals to file complaints about privacy practices, designate a contact person or office for receiving complaints, and document all complaints received and their dispositions. Complaint handling documentation is one of the first items OCR requests in an investigation. Organisations that have not documented complaint investigations, including those resolved informally, cannot demonstrate a functioning complaint process.
Industry Trends: How Privacy Enforcement Has Evolved
HIPAA privacy enforcement has shifted in character across the rule’s life. The early enforcement period focused on establishing the compliance baseline and addressing systemic failures at large organisations. The HITECH Act’s 2009 amendments dramatically expanded enforcement authority by introducing the four-tier penalty structure, extending obligations to business associates, and requiring HHS to conduct periodic audits of covered entities and business associates.
Enforcement Focus Areas by Period
2003-2009: Baseline establishment
Resolution agreements, primarily large entities
Early enforcement focused on large-scale systemic failures. Penalties were capped at $100 per violation, $25,000 per violation category per year. Many investigations resolved with technical assistance rather than formal enforcement.
2009-2016: HITECH expansion
Tiered penalties, business associate reach
HITECH dramatically increased maximum penalties and extended direct liability to business associates. Large-scale breach cases produced multi-million dollar settlements. The Omnibus Rule in 2013 finalised business associate requirements and updated the breach notification standard.
2016-2022: Audit programme and targeted enforcement
Phase 2 audits, Right of Access Initiative
OCR’s Phase 2 audit programme reviewed covered entities and business associates against a defined set of standards. The Right of Access Initiative launched in 2019 targeted access failures systematically with relatively small but numerous enforcement actions across diverse entity types.
2022-present: Expanded priority areas
Reproductive health, telehealth, cybersecurity intersection
The 2024 Privacy Rule amendments addressing reproductive health information created new disclosure prohibitions. Telehealth expansion raised questions about third-party tracking technologies and their interaction with the Privacy Rule, addressed in OCR guidance. Cybersecurity incidents increasingly trigger Privacy Rule investigations alongside Security Rule review.
Regulatory Perspective: What OCR Looks at During an Investigation
HHS OCR investigations are complaint-driven for most privacy matters, though the agency also conducts compliance reviews and audits on its own initiative. When a complaint is received, OCR typically requests a defined set of documents that directly reflects the Privacy Rule’s administrative requirements: the entity’s privacy policies and procedures, the NPP, training documentation, the sanctions policy, the complaint log, and documentation relevant to the specific complaint allegation.
What Triggers Escalation from Investigation to Enforcement Action
Not all investigated complaints result in formal enforcement. OCR resolves the majority of investigations through technical assistance or voluntary compliance. Investigations escalate to formal enforcement when: the entity cannot demonstrate that a required element was in place at the time of the complaint (no training documentation, no privacy officer, no sanctions policy); the violation involved wilful neglect; the entity’s response is inadequate or slow; or the same standard was violated in a prior investigation.
The single most consequential factor is whether the organisation can produce documentation demonstrating that its compliance programme was functional at the relevant time. An organisation that can show training records, policy review histories, complaint logs, and a functional sanctions process is in a substantially different position than one that can only show that policies exist on paper.
Source: HHS OCR | OCR Resolution Agreements
What Organisations With Sustained Compliance Do Differently
They treat the NPP as a living document
Organisations with stable compliance records review the NPP at least annually against current regulatory requirements and update it when policies or regulatory obligations change. They maintain version histories that allow them to demonstrate what the NPP said at any given point in time. The NPP is not filed and forgotten after initial implementation.
They connect audit log review to access policy enforcement
Minimum necessary compliance on paper requires minimum necessary enforcement in practice. Regular audit log review that identifies access anomalies, connects them to the workforce member’s role and the records accessed, and triggers investigation when the access is not consistent with job function is how the standard is actually maintained. Organisations that review audit logs only after a complaint has been filed have already failed the minimum necessary standard for the intervening period.
Their training programme evolves with their operations
When a new EHR platform is deployed, when a telehealth programme launches, when staff move between roles with different PHI access levels, or when the regulatory framework changes, training is updated. The organisations with the lowest complaint rates maintain training as a programme that responds to operational changes rather than a calendar obligation that runs independently of what the organisation is actually doing with PHI.
Key Takeaways
The Privacy Rule’s administrative requirements are not supplementary; they are the compliance programme
A covered entity that has a privacy officer, trained its workforce, documented training, applied its sanctions policy consistently, and maintained its complaint log is in a fundamentally different position than one that has only written policies. OCR investigations reveal this distinction very quickly. The administrative requirements under 45 CFR 164.530 are not paperwork surrounding the substantive standards; they are the mechanism by which organisations demonstrate that the substantive standards are being followed.
Access rights enforcement is a sustained OCR priority, not a background concern
The Right of Access Initiative has produced more enforcement actions than any other single-standard enforcement programme in OCR’s history. The violations targeted are not obscure or technical: providing records too slowly, in the wrong format, or at excessive cost. Every covered entity with a request-for-records process should review that process against the access standard’s specific timeline, format, and fee requirements before an access complaint prompts OCR to do so first.
The 2024 reproductive health amendments require immediate NPP and policy review
The 2024 amendments to the Privacy Rule created new prohibitions on using or disclosing PHI related to reproductive health care sought lawfully under applicable state law. The compliance date for these provisions was December 2024. Covered entities that have not reviewed their NPP, disclosure policies, and authorisation forms against the amended requirements since that date are operating with outdated documentation that may not accurately describe their current obligations.
Frequently Asked Questions
What is included in the HIPAA designated record set for purposes of the access right?
The designated record set includes medical and billing records for covered healthcare providers, enrolment and payment records for health plans, and any other records used to make decisions about individuals. It does not include psychotherapy notes, information compiled for civil or criminal proceedings, or certain research records. The access right applies to the designated record set; requests for other categories of records may be denied.
Does HIPAA require covered entities to conduct annual privacy training?
No. The Privacy Rule requires training within a reasonable period of hire and whenever material changes to policies and procedures occur. There is no regulatory requirement for annual retraining, although it is a widely adopted best practice that satisfies the reasonable period standard for ongoing workforce changes. Covered entities that train only once at hire without addressing policy updates may have compliance gaps.
How does the minimum necessary standard apply to requests for PHI from other covered entities?
Requesting covered entities must limit their requests to the minimum necessary for the stated purpose. Responding covered entities may rely on representations from the requesting entity about minimum necessary scope for standard disclosures such as insurance claims. For non-standard requests, the responding entity should make an independent assessment of whether the scope requested is reasonable.
What changed in the 2024 HIPAA Privacy Rule amendments regarding reproductive health?
The 2024 amendments at 45 CFR 164.502(a)(5)(iii) prohibit covered entities from using or disclosing PHI related to reproductive health care to investigate or impose liability on individuals or providers based on seeking, obtaining, providing, or facilitating lawful reproductive health care. Covered entities must obtain attestations from certain requestors before disclosing reproductive health PHI for health oversight, law enforcement, or legal proceedings purposes.
How does HIPAA apply to mental health records?
HIPAA applies to mental health records held by covered entities in the same way it applies to other PHI, with one significant exception: psychotherapy notes receive heightened protection. Psychotherapy notes documented separately from the rest of the medical record require patient authorisation for disclosure in most circumstances and are not included in the designated record set. General mental health information documented in the standard medical record is subject to standard HIPAA rules.
What is the difference between a breach and a security incident under HIPAA?
A security incident is any attempted or successful unauthorised access, use, disclosure, modification, or destruction of information or interference with system operations. A breach is a specific subset: an impermissible use or disclosure of PHI that compromises its security or privacy, unless the covered entity can demonstrate that the probability of compromise is low using the four-factor risk assessment. Not every security incident is a breach requiring notification.
How does HHS OCR prioritise enforcement cases?
HHS OCR investigates all complaints it receives but prioritises based on the nature of the violation, the harm to individuals, the covered entity’s compliance history, and whether the entity self-reported. Cases involving systemic violations affecting large numbers of individuals, wilful neglect, or repeated failures receive priority. OCR has emphasised the right of access, security incidents affecting large volumes of PHI, and reproductive health information in recent enforcement cycles.
Government and Regulatory Sources
Government and Regulatory Sources
- HHS. HIPAA Privacy Rule (45 CFR Parts 160 and 164): full regulatory text and HHS guidance index.
- HHS OCR. Enforcement Highlights and Settlements: annual enforcement data and resolution agreement summaries.
- HHS OCR. Right of Access Guidance: detailed guidance on the patient right to access records.
- HHS OCR. Complaints Received by Calendar Year: annual complaint volume and disposition data.
- HHS OCR. Resolution Agreements and Corrective Action Plans: database of settled enforcement actions with penalty amounts.
Research and Industry Sources
- Health Care Compliance Association (HCCA): professional standards and benchmarking surveys for HIPAA compliance officers.
Related VelSafe Articles
VelSafe
Build a Stronger HIPAA Compliance Programme
HIPAA privacy standards govern how every covered entity handles patient information. Find more compliance resources and practical guidance at VelSafe.
Explore VelSafe Resources