HIPAA · OCR · PRIVACY AND SECURITY RULES

Your PHI left the clinical system. The rules followed it out.

The copies in analytics, training sets and inference logs are PHI too - and in scope, on the same eighteen standards as everything else.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
The risk analysis is what OCR asks for first
18 safeguards Risk analysis 60-day clock BAAs ePHI

Our promise

“A policy is paper. The risk analysis is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

HIPAA, in three chapters

The Rules

The Health Insurance Portability and Accountability Act of 1996 is enforced by the Office for Civil Rights. The Privacy Rule governs use and disclosure, the Security Rule sets eighteen safeguard standards for electronic PHI, and the Breach Notification Rule runs a sixty-day clock.

The Gap

Most programmes were scoped around the clinical system, and PHI has not stayed in it. Analytics warehouses, model training sets, support tickets, prompts, inference logs and export files all hold copies - and none appear on the flow diagram drawn when the EHR went in.

The Office

OCR asks for the risk analysis first, and it is the deficiency it cites most often. We build the inventory from the systems inwards, test the eighteen standards where they are meant to bite, and hand you a finding trail that is dated, owned and evidenced rather than merely asserted.

What is PHI?

Health data that names a person.

Eighteen identifiers, from a name to a date to a device ID - they need only be linked to health information.

Who owes these rules № 01
  • Providers, health plans and clearinghouses
  • Business associates, in their own right
  • Subcontractors, at every link below them
  • Cloud, analytics and model vendors holding PHI
HIPAA · iDharma · Presented for review
When the duties bite № 02
  • Before PHI is shared - the BAA comes first
  • On discovery, when the sixty days start running
  • Whenever the estate changes shape materially
  • At every review the risk analysis is meant to get
HIPAA · iDharma · Presented for review
Whose duty is it

The duty is yours. So is theirs.

You

The covered entity at the top

A provider, a health plan or a clearinghouse handling PHI directly. The Privacy Rule, the Security Rule and the Breach Notification Rule all land in full - and choosing a business associate does not move any of them. You stay answerable for having chosen it, and for how it performs long after you have.

Your vendor

The people who hold it for you

A business associate creates, receives, maintains or transmits PHI on your behalf. It owes you a signed agreement - and since the Omnibus Rule it owes the Security Rule and the Breach Notification Rule directly, in its own right, rather than through your contract with it, whatever that contract says.

The catch

The chain does not end at one contract

A subcontractor handling PHI for a business associate carries direct liability too, and owes a BAA of its own. Liability follows the data down the supply chain rather than stopping where the paperwork does - which is why the inventory matters more than the contract file does, and why it always will do.

What most teams assume

“Our vendor signed a BAA, so that is covered.”

What the rule says

Liability follows the data, not the contract.

It is the first thing we have to correct.

  • Who it is for
  • Providers & health plans
  • Digital health & EHR
  • Clinical AI teams
  • Billing & RCM
  • Cloud & analytics vendors
Why this matters
A heavy leather-bound volume pulled forward from a shelf of matching volumes under a low light, pale paper tabs and a ribbon marking half a dozen pages part-way through it.
01 Civil penalties are graded by culpability, in four tiers - and the widest step in the schedule is willful neglect corrected inside thirty days against willful neglect that was not.
02

The Security Rule risk analysis is the most commonly cited deficiency - usually because it was done once and never revisited.

03

Penalties are assessed per violation, so one bad control repeated right across a large estate is not a single finding at all. It is arithmetic.

04

Three criminal offences sit above all of it, prosecuted by the Department of Justice on referral. Intent is what separates them.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Identifiable health data -

Eighteen identifiers, and they are broad. A name, a date, a postcode, a device ID or a biometric - once any of them is linked to health information, the record is PHI in any form it is held.

Your capacity -

This is the question that decides scope. HIPAA binds covered entities, business associates and their subcontractors. Health data held on your own account is a different regime, not no regime.

Risk analysis -

This is the one OCR asks for first. It is the most commonly cited deficiency in enforcement, and every safeguard decision underneath it is undocumented without one.

The calendar

Four clocks, and the first one starts early.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Assess

    On discovery

    The four-factor assessment starts the day the breach is known, or would have been with reasonable care.

  2. Tell the individuals

    Within 60 days

    Sixty days from discovery, not from the day the investigation closes. It does not pause while you decide.

  3. Tell HHS and media

    500 individuals

    At or above the threshold, both go without unreasonable delay. Below it, HHS gets an annual log instead of that.

  4. Revisit the analysis

    Continuously

    A risk analysis run at go-live and never revisited does not describe the estate you have today, or defend it now.

The trap

Teams start the sixty days when somebody opens a ticket. The rule starts them on discovery - the first day the breach was known, or would have been known with reasonable diligence. The clock can already be running before anyone has noticed.

Requirement & coverage

What the rules say, what we ship

The Security Rule’s 18 standards, grouped by family, and the Privacy and Breach duties beside them.

Risk analysis Administrative
Where ePHI is created, received, maintained and transmitted; the threats to it; the measures in place; and the likelihood, impact and remediation priority of each risk. The first document an investigation asks for.
Risk management Administrative
The remediation the analysis called for, prioritised, owned and dated - plus the sanction policy and the review of information system activity that sit in the same standard.
Assigned responsibility Administrative
A named security official and a named privacy officer, both designated in writing rather than assumed, and both reachable by someone outside the organisation.
Workforce security Administrative
Authorisation, supervision and clearance - and the termination procedure, which is the limb that lapses first and the one an access review finds.
Information access management Administrative
Access authorisation, establishment and modification applied per role rather than per request, so a leaver or a mover changes one thing and not twelve.
Awareness and training Administrative
Security reminders, malware protection, log-in monitoring and password management - with attendance records, because the training you cannot evidence did not happen.
Security incident procedures Administrative
Response to and reporting of security incidents, with the route and the decision-maker defined before one happens rather than named during one.
Contingency plan Administrative
Data backup, disaster recovery, emergency mode operation, testing, and a criticality analysis of which applications and data actually have to come back first.
Evaluation Administrative
Periodic technical and non-technical evaluation of whether the safeguards still fit the estate - the standard that turns a one-off programme into a live one.
Physical safeguards Four standards
Facility access controls, workstation use, workstation security, and device and media controls - including disposal, re-use and what happens before a device moves.
Technical safeguards Five standards
Access control, audit controls, integrity, person or entity authentication, and transmission security - with the encryption decision documented either way.
Privacy and breach duties The other two rules
Minimum necessary, individual rights, the notice of privacy practices and the workforce sanctions behind them - plus the breach path from discovery to notification.
The engagement

Health data, independently reviewed

From the EHR to the model training set.

  1. Intake

    Where PHI is created, received, maintained and transmitted.

  2. Test

    The eighteen standards against the estate, and the BAAs behind them.

  3. Sign off and evidence

    You see the draft first. Then the analysis, policies and drills - dated.

Request a HIPAA review
An auditor in a dark green trouser suit and cream blouse, with shoulder-length auburn hair, standing against a warm pale wall and pointing into the open space alongside.
The analysis is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their HIPAA review

The analysis, done right

The risk analysis OCR asks for first, scoped to the estate you have rather than to a questionnaire.

Evidence, not attestation

Every safeguard tested where it is meant to bite, and every finding dated, owned and tracked.

The whole chain covered

Business associates and their subcontractors, with agreement status and current risk.

PHI in the AI estate

Training sets, prompts and inference logs read as PHI, because that is what they hold.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

HIPAA review report

The full review: what PHI you hold, on what footing, under which rule - and where each obligation is evidenced or is not. Findings land on the Security Rule’s own eighteen standards plus the Privacy and Breach duties, ranked by consequence to patients rather than by ease of fixing, with the business associate chain stated separately.

Analysis

Security Rule risk analysis

Threats and vulnerabilities to the confidentiality, integrity and availability of ePHI, with likelihood, impact and a remediation plan attached.

Workbook

PHI inventory and flow map

Every system that creates, receives, maintains or transmits PHI, traced to a flow map - analytics, training sets and inference logs included.

Evidence

Safeguards evidence pack

The eighteen standards tested where they are meant to bite - access control, encryption decisions, audit logging and the integrity controls.

Runbook

Breach runbook and drill

Discovery to notification with the four-factor assessment written down: who decides, who drafts to OCR, and when the media threshold trips.

Register

Business associate register

Every associate and subcontractor with agreement status, risk position and review date - the oversight both rules require and few keep current.

Documents

Policy template pack

The Privacy Rule set, the Security Rule set and the breach and compliance set - mapped across to SOC 2 and ISO 27001 so one set answers both.

Format & fee

Real numbers, upfront.

Scope
Set by the rules
Inputs
Your systems and your BAAs
Re-review
Every twelve months - $10,500 against your known baseline

The rules fixed the standards, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
HIPAA · Named engagement $12,500 flat
  • The Security Rule risk analysis
  • PHI inventory and flow map
  • Breach runbook and one drill
  • 31 policy templates, tailored
Show your hand

Four things you have to be able to produce

HIPAA is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The analysis,
current

A risk analysis that describes the estate you have now. It is the most commonly cited deficiency in enforcement, and it is the first thing an investigation asks to see.

The map,
complete

Every system that creates, receives, maintains or transmits PHI - the analytics tables, training sets, prompts and inference logs included, because they hold it too.

The BAA,
signed

A BAA with every party that touches PHI on your behalf, and one at every link below them. No compliant agreement means the sharing itself was not lawful.

The clock,
rehearsed

The path from discovery to notification, with the four-factor assessment written before you need it. Sixty days is not long once the first week goes on deciding.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

What counts as PHI, which side of the line you are on, and where AI touches scope. Answered straight.

Request this review
What counts as protected health information?

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form - electronic, paper or spoken. It turns on eighteen identifiers, from names and dates to biometric identifiers, once they are linked to health information.

What is the difference between a covered entity and a business associate?

Covered entities are healthcare providers, health plans and clearinghouses that handle PHI directly. Business associates are third parties performing services involving PHI on their behalf - and since the Omnibus Rule of 2013 they carry direct HIPAA liability of their own.

What does the Security Rule risk analysis have to cover?

Where ePHI is created, received, maintained and transmitted; the threats to it; the measures currently in place; and the likelihood, impact and remediation priority of each risk. It is the single most commonly cited deficiency in enforcement - usually because it was done once and never revisited.

Where does AI touch HIPAA scope?

In three places, and they matter more here because the identifiers are so broad. PHI copied into a training set is maintained PHI. A prompt carrying patient detail is PHI in transmission, and the model vendor receiving it is a business associate. Inference logs kept for debugging are a copy of both.

What does an iDharma HIPAA review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the Security Rule risk analysis, the PHI inventory and flow map, the safeguards evidence pack, the breach runbook and drill, the business associate register and the policy template pack.

Get started

Request your HIPAA review

Tell us where PHI lives and we come back with a scoping call in one business day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your clinical and security teams, and we tell you which extracts we need before you commit.

  1. Which systems create, receive, maintain or transmit PHI
  2. Whether you are a covered entity, an associate, or both
  3. Your current risk analysis, if one exists
  4. The business associate list, with agreement status
  5. Whether PHI has reached analytics or model pipelines

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a HIPAA review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The HIPAA rules and HHS guidance
  • The Office for Civil Rights, on enforcement
Enacted
1996
Omnibus Rule
2013

What it means

  • General information about what the rules require — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • No penalty amount appears on this page. OCR adjusts the civil money penalty figures for inflation every year, and the current schedule is published by HHS — go there rather than to a page like this one for a number.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us