HIPAA, and the health data that left the clinical system.
HIPAA establishes national standards for protecting protected health information. Whether you are a covered entity, a business associate or a subcontractor, the Privacy Rule, the Security Rule and the Breach Notification Rule all apply and the evidence has to exist. We scope where PHI actually lives, including the copies in analytics and model pipelines, and tell you what has to change.
What is HIPAA?
A federal law of 1996 establishing national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. It is enforced by the Office for Civil Rights within the Department of Health and Human Services, and it reaches covered entities, business associates and their subcontractors alike.
- Privacy Rule Use and disclosure Controls how protected health information may be used and shared, and establishes the rights an individual holds over it.
- Security Rule Electronic PHI Administrative, physical and technical safeguards for ePHI — eighteen standards in total.
- Alongside SOC 2 and ISO 27001 Substantial control overlap, which means shared evidence if the programmes are scoped together. HIPAA, unlike those two, is not voluntary.
Who needs to comply?
Six populations. The third is the one that surprises people: since the Omnibus Rule, liability follows the data down the supply chain rather than stopping at the first contract.
- Covered entities Healthcare providers, health plans and clearinghouses that transmit health information electronically.
- Business associates Third parties that create, receive, maintain or transmit PHI on behalf of a covered entity.
- Subcontractors Entities handling PHI on behalf of a business associate. They carry direct liability too.
- Healthcare providers Hospitals, clinics, physicians, dentists, pharmacies, nursing homes and home health agencies.
- Health plans Health insurers, HMOs, employer health plans and government health programmes.
- Healthcare technology vendors EHR vendors, cloud storage, analytics, billing services, IT support and consultants.
The question that decides the size of the engagement is where PHI actually is, not where it is supposed to be. Analytics warehouses, model training sets, support tickets, inference logs and export files all count, and none of them appear on the data flow diagram anyone drew when the EHR went in.
How iDharma supports HIPAA compliance
Six workstreams across the Privacy Rule, the Security Rule and the Breach Notification Rule. The first is where the engagement is decided: everything downstream depends on knowing where PHI is.
PHI inventory and data mapping
Every system that creates, receives, maintains or transmits protected health information, traced to a data flow map — including the analytics tables, model training sets, prompts and inference logs that hold copies nobody intended to keep.
Safeguards implementation
The administrative, physical and technical safeguards documented where they are meant to bite: access controls, encryption decisions, audit logging and integrity controls across the ePHI estate.
Risk analysis and management
The risk analysis the Security Rule actually mandates: threats and vulnerabilities to the confidentiality, integrity and availability of ePHI, with likelihood, impact and a remediation plan attached. This is the first document OCR asks for.
Policy and procedure set
The required policies and procedures with version control, approval and a review cycle — covering both rules, and the workforce training that has to sit behind them.
Breach response and the 60-day clock
The path from discovery to notification, with the four-factor harm assessment written down before you need it: who decides, who drafts to OCR, who tells the individuals, and when the media threshold trips.
Business associate management
Every business associate and subcontractor with BAA status, risk assessment and ongoing monitoring — the third-party oversight both rules require and almost nobody keeps current.
Every activity is dated, owned and evidenced. That trail is what an OCR investigation runs on: the question is rarely whether you had a policy, but whether you can show the risk analysis was done, reviewed and acted on before the complaint arrived.
Complete HIPAA requirements coverage
The assessment tests against every requirement across the four rules that carry obligations. Nothing in scope is left to a follow-up engagement.
- Privacy Rule PHI use and disclosure, individual rights, the minimum necessary standard and the notice.
- 8 of 8 by the assessment
- Security Rule The eighteen administrative, physical and technical safeguard standards.
- 18 of 18 by the assessment
- Breach Notification Discovery, the harm assessment, notification and the documentation behind it.
- 4 of 4 by the assessment
- Enforcement Investigation readiness, penalties, corrective action and audit response.
- 4 of 4 by the assessment
Scoped for healthcare compliance from the ground up
OCR audit readiness
The evidence pack an investigation or compliance review asks for, assembled before it is requested.
60-day breach clock
The notification path with named owners and decision points, rehearsed rather than written.
BAA coverage
Business associates and subcontractors tracked with agreement status and current risk position.
AI in healthcare
HIPAA read together with AI governance, for clinical models trained on or prompted with PHI.
Key HIPAA rules
Five rules, and what each one actually asks for. The last of them is why a vendor contract is no longer where your liability ends.
Privacy Rule
Controls the use and disclosure of protected health information, and establishes individual rights over it.
- The minimum necessary standard
- Individual rights: access, amendment, accounting
- Notice of privacy practices
- A designated privacy officer
- Workforce training and sanctions
Security Rule
National standards protecting electronic protected health information.
- Administrative safeguards: 9 standards
- Physical safeguards: 4 standards
- Technical safeguards: 5 standards
- Organisational requirements
- Documented policies and procedures
Breach Notification Rule
Requires notification to individuals, to HHS and sometimes to the media when PHI is breached.
- Breach discovery and harm assessment
- Individual notification within 60 days
- HHS notification, annual or immediate
- Media notification above 500 individuals
- Documentation and mitigation
Enforcement Rule
Procedures for investigations, hearings and the imposition of civil money penalties.
- OCR compliance investigations
- The civil money penalty tiers
- Criminal prosecution referrals
- Corrective action plans
- Resolution agreements
Omnibus Rule
Gave business associates direct liability, widened breach notification and implemented the HITECH Act.
- Business associate direct liability
- Subcontractor BAA requirements
- Strengthened enforcement
- Expanded individual rights
- Genetic information protections
Security Rule safeguards breakdown
Eighteen standards across three families: nine administrative, four physical and five technical. The chip on each card names its family, so the count in the coverage ledger and the list here stay readable against each other.
Security management process
Risk analysis, risk management, a sanction policy and review of information system activity.
Assigned security responsibility
A designated security official, named, who is responsible for HIPAA security.
Workforce security
Authorisation, supervision, clearance procedures and — the one that lapses — termination procedures.
Information access management
Access authorisation, establishment and modification, applied per role rather than per request.
Security awareness and training
Security reminders, protection from malicious software, log-in monitoring and password management.
Security incident procedures
Response to and reporting of security incidents, with the route defined before one happens.
Contingency plan
Data backup, disaster recovery, emergency mode operation, testing, and criticality analysis of applications and data.
Evaluation
Periodic technical and non-technical evaluation of how well the security measures still fit.
Business associate contracts
Written contracts carrying satisfactory assurances that PHI will be safeguarded.
Facility access controls
Contingency operations, a facility security plan, access control and validation, and maintenance records.
Workstation use
Policies covering the functions performed at a workstation and how it should be used.
Workstation security
Physical safeguards restricting workstation access to authorised users.
Device and media controls
Disposal, media re-use, accountability, and data backup and storage before a device moves.
Access control
Unique user identification, emergency access procedure, automatic logoff, and encryption and decryption.
Audit controls
Hardware, software and procedural mechanisms that record and examine access to ePHI.
Integrity
Policies ensuring ePHI is not improperly altered or destroyed, and a way to detect it if it is.
Person or entity authentication
Procedures verifying that a person or entity seeking access to ePHI is who they claim to be.
Transmission security
Integrity controls and encryption for ePHI moving across a network.
24-week implementation roadmap
A practical path to HIPAA compliance with clear milestones. The weeks are indicative — the variable is how much of the PHI estate turns out to exist once you go looking.
-
Weeks 1-4
Foundation and gap analysis
Name the owners, then find out what you actually hold.
- Designate the privacy and security officers
- Run an initial HIPAA gap assessment
- Build the PHI inventory and data flow maps
- Review the existing policies and procedures
-
Weeks 5-10
Risk analysis and planning
The document OCR asks for first, done properly rather than quickly.
- Complete a full risk analysis
- Identify threats and vulnerabilities to ePHI
- Prioritise remediation by risk
- Build the security management plan
-
Weeks 11-20
Safeguards implementation
Where the eighteen standards stop being a list and start being controls.
- Implement the administrative safeguards
- Deploy the physical security controls
- Configure the technical safeguards
- Put business associate agreements in place
-
Weeks 21-24
Training and validation
The stage that turns a control set into something a workforce actually follows.
- Run workforce privacy and security training
- Test the incident response procedure
- Validate the technical controls
- Document the compliance evidence
HIPAA penalties and enforcement
Civil money penalties are assessed per violation and scale with culpability. The jump between tier three and tier four is the whole argument for correcting a known problem inside thirty days.
| Tier | Culpability | Per violation | Annual maximum |
|---|---|---|---|
| Tier 1 | Did not know, and reasonable diligence would not have revealed it | $100 to $50,000 | $25,000 |
| Tier 2 | Reasonable cause, not willful neglect | $1,000 to $50,000 | $100,000 |
| Tier 3 | Willful neglect, corrected within 30 days | $10,000 to $50,000 | $250,000 |
| Tier 4 | Willful neglect, not corrected within 30 days | $50,000 | $1,500,000 |
These figures are the tier structure, not a current-year table. OCR adjusts the amounts for inflation annually, so check the published figures before relying on any number here. Penalties are assessed per violation, and multiple violations of different requirements can exceed the annual maximum shown for any one of them.
Criminal penalties
Three offences, prosecuted by the Department of Justice rather than pursued by OCR. What separates the tiers is intent.
Up to $50,000 and 1 year
Knowingly obtaining or disclosing protected health information.
- Knowledge of the act is enough
- No intent to profit required
- Imprisonment up to one year
Up to $100,000 and 5 years
Obtaining protected health information under false pretences.
- Deception is the aggravating element
- Applies to individuals as well as entities
- Imprisonment up to five years
Up to $250,000 and 10 years
Obtaining or disclosing PHI intending to sell it, or for commercial advantage, personal gain or malicious harm.
- Intent to sell, transfer or use
- Commercial advantage or malicious harm
- Imprisonment up to ten years
Criminal prosecutions are handled by the Department of Justice; OCR refers them. In practice most organisations meet HIPAA through the civil route, and the criminal tiers matter mainly as the reason workforce sanctions policies have to have teeth.
HIPAA policy template library
Ready-to-use HIPAA policy templates covering the Privacy Rule, the Security Rule and Breach Notification, mapped across to SOC 2 and ISO 27001 so one document set answers more than one auditor.
Privacy Rule policies
- Notice of Privacy Practices
- Minimum Necessary Policy
- Individual Rights Policy
- Privacy Officer Designation
- PHI Use and Disclosure Policy
- Accounting of Disclosures
- Amendment Request Process
Security Rule policies
- Security Management Process
- Access Control Policy
- Audit Controls Policy
- Encryption and Decryption Standard
- Incident Response Plan
- Contingency Plan
- Workforce Security Policy
Breach and compliance
- Breach Notification Policy
- Breach Risk Assessment
- Business Associate Agreement
- Sanctions Policy
- Training and Awareness Programme
- Compliance Monitoring
- Risk Assessment Policy
Frequently asked questions
Scope, what counts as PHI, the breach clock, and the two questions that decide how much of your estate is in the assessment.
Who enforces HIPAA?
The Office for Civil Rights within the Department of Health and Human Services. OCR conducts compliance reviews, investigates complaints, runs audits and imposes civil money penalties. Criminal enforcement is handled by the Department of Justice on referral.
What is protected health information?
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form — electronic, paper or spoken. It turns on eighteen identifiers including names, dates, contact details, medical record numbers, health plan numbers and biometric identifiers, once they are linked to health information. Electronic PHI carries the additional Security Rule obligations on top.
What is the difference between a covered entity and a business associate?
Covered entities are healthcare providers, health plans and clearinghouses that handle PHI directly. Business associates are third parties performing services involving PHI on their behalf — EHR vendors, billing companies, consultants. Since the Omnibus Rule in 2013 business associates carry direct HIPAA liability and must themselves comply with the Security Rule and the Breach Notification Rule.
Do we need a business associate agreement?
Yes. A covered entity must have a signed BAA with each business associate before any PHI is shared, and a business associate must have one with each of its subcontractors. The agreement has to include specific provisions on safeguarding, breach notification, return or destruction of PHI, and liability. No compliant BAA means no lawful sharing.
What triggers the Breach Notification Rule?
Acquisition, access, use or disclosure of PHI that compromises its security or privacy. You run a four-factor risk assessment; unless an exclusion applies and the assessment shows a low probability that PHI was compromised, notification is required within 60 days to the individuals affected and to HHS, and to the media where 500 or more individuals in a state or jurisdiction are involved.
What does the Security Rule risk analysis have to cover?
Where ePHI is created, received, maintained and transmitted; the threats to it, human, natural and environmental; the security measures currently in place; the likelihood and impact of each threat; and the resulting risk levels with remediation priorities. It has to be documented and kept current. It is the single most commonly cited deficiency in OCR enforcement, usually because it was done once and never revisited.
Do we have to encrypt all PHI?
Encryption is addressable rather than required, which is not the same as optional. If you do not encrypt, you must document why, and what equivalent alternative measure is in place instead. Encrypting to a NIST-validated standard with proper key management is strongly worth doing regardless, because breached data that was properly encrypted does not trigger the notification duty.
What workforce training is required?
Training on your privacy and security policies is required; the frequency and format are not specified. Annual training for the whole workforce, including volunteers, trainees and contractors, with extra depth for elevated PHI access, is the defensible position. Cover both rules, breach notification, sanctions, individual rights, minimum necessary and business associate obligations — and keep attendance records, because the training you cannot evidence did not happen.
How does HIPAA apply to cloud and SaaS vendors?
A provider that stores, processes or transmits ePHI is a business associate and must sign a BAA. The covered entity stays responsible for confirming the vendor has appropriate safeguards; a provider attestation does not transfer your obligations. Review the vendor's security practice, certifications and incident response before engaging, and document the responsibility split.
Where does AI touch HIPAA scope?
In the same three places it touches every data regime, and they matter more here because the identifiers are so broad. PHI copied into a training set or feature store is maintained PHI. A prompt containing patient detail is PHI in transmission, and the model vendor receiving it is a business associate. Inference logs retained for debugging are a copy of both. Each pulls its host system into scope, which is why the PHI inventory is the first workstream on this page.
How does HIPAA relate to state privacy laws?
HIPAA is a federal floor. A state law that gives greater privacy protection or stronger individual rights applies on top, and several states impose shorter breach notification timelines. You comply with both. Unlike SOC 2, which is voluntary and market-driven, HIPAA is mandatory for anyone within its scope.
What does an iDharma HIPAA assessment cover, and how long does it take?
It is scoped before you are charged. The variables are the size of the PHI estate, whether a current risk analysis exists, and whether PHI has reached analytics or model pipelines. A programme typically runs six to nine months end to end; the gap assessment that tells you which of those apply is much shorter. We tell you the shape after a short scoping call.
Ready to achieve HIPAA compliance?
Start with a gap assessment and a real risk analysis — where PHI actually lives, which of the eighteen safeguards are evidenced, and what the 60-day clock would find if it started tomorrow.
This page is guidance on how we scope an assessment, not legal advice. HHS and OCR publish the rules, the enforcement figures and their own guidance; where a scoping call turns on the wording or on a current penalty amount, go to them rather than to this page.