HIPAA · PRIVACY RULE · SECURITY RULE · BREACH NOTIFICATION

HIPAA, and the health data that left the clinical system.

HIPAA establishes national standards for protecting protected health information. Whether you are a covered entity, a business associate or a subcontractor, the Privacy Rule, the Security Rule and the Breach Notification Rule all apply and the evidence has to exist. We scope where PHI actually lives, including the copies in analytics and model pipelines, and tell you what has to change.


A printed controls audit summary on a dark desk, showing control coverage, open findings and evidence status Illustrative materials
The risk analysis is the document OCR asks for first
Protected health information 18 safeguards 60-day breach clock Business associate agreements OCR investigations

What is HIPAA?

A federal law of 1996 establishing national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. It is enforced by the Office for Civil Rights within the Department of Health and Human Services, and it reaches covered entities, business associates and their subcontractors alike.

  • Privacy Rule Use and disclosure Controls how protected health information may be used and shared, and establishes the rights an individual holds over it.
  • Security Rule Electronic PHI Administrative, physical and technical safeguards for ePHI — eighteen standards in total.
  • Alongside SOC 2 and ISO 27001 Substantial control overlap, which means shared evidence if the programmes are scoped together. HIPAA, unlike those two, is not voluntary.

Who needs to comply?

Six populations. The third is the one that surprises people: since the Omnibus Rule, liability follows the data down the supply chain rather than stopping at the first contract.

  • Covered entities Healthcare providers, health plans and clearinghouses that transmit health information electronically.
  • Business associates Third parties that create, receive, maintain or transmit PHI on behalf of a covered entity.
  • Subcontractors Entities handling PHI on behalf of a business associate. They carry direct liability too.
  • Healthcare providers Hospitals, clinics, physicians, dentists, pharmacies, nursing homes and home health agencies.
  • Health plans Health insurers, HMOs, employer health plans and government health programmes.
  • Healthcare technology vendors EHR vendors, cloud storage, analytics, billing services, IT support and consultants.

The question that decides the size of the engagement is where PHI actually is, not where it is supposed to be. Analytics warehouses, model training sets, support tickets, inference logs and export files all count, and none of them appear on the data flow diagram anyone drew when the EHR went in.

How we help

How iDharma supports HIPAA compliance

Six workstreams across the Privacy Rule, the Security Rule and the Breach Notification Rule. The first is where the engagement is decided: everything downstream depends on knowing where PHI is.

Privacy Rule

PHI inventory and data mapping

Every system that creates, receives, maintains or transmits protected health information, traced to a data flow map — including the analytics tables, model training sets, prompts and inference logs that hold copies nobody intended to keep.

Security Rule

Safeguards implementation

The administrative, physical and technical safeguards documented where they are meant to bite: access controls, encryption decisions, audit logging and integrity controls across the ePHI estate.

Security Rule

Risk analysis and management

The risk analysis the Security Rule actually mandates: threats and vulnerabilities to the confidentiality, integrity and availability of ePHI, with likelihood, impact and a remediation plan attached. This is the first document OCR asks for.

Privacy · Security

Policy and procedure set

The required policies and procedures with version control, approval and a review cycle — covering both rules, and the workforce training that has to sit behind them.

Breach Notification

Breach response and the 60-day clock

The path from discovery to notification, with the four-factor harm assessment written down before you need it: who decides, who drafts to OCR, who tells the individuals, and when the media threshold trips.

Privacy · Security

Business associate management

Every business associate and subcontractor with BAA status, risk assessment and ongoing monitoring — the third-party oversight both rules require and almost nobody keeps current.

Every activity is dated, owned and evidenced. That trail is what an OCR investigation runs on: the question is rarely whether you had a policy, but whether you can show the risk analysis was done, reviewed and acted on before the complaint arrived.

Coverage

Complete HIPAA requirements coverage

The assessment tests against every requirement across the four rules that carry obligations. Nothing in scope is left to a follow-up engagement.

34
HIPAA requirements
34
Covered by the assessment
100%
Coverage across all rules
Privacy Rule PHI use and disclosure, individual rights, the minimum necessary standard and the notice.
8 of 8 by the assessment
Security Rule The eighteen administrative, physical and technical safeguard standards.
18 of 18 by the assessment
Breach Notification Discovery, the harm assessment, notification and the documentation behind it.
4 of 4 by the assessment
Enforcement Investigation readiness, penalties, corrective action and audit response.
4 of 4 by the assessment
Built for healthcare

Scoped for healthcare compliance from the ground up

OCR audit readiness

The evidence pack an investigation or compliance review asks for, assembled before it is requested.

60-day breach clock

The notification path with named owners and decision points, rehearsed rather than written.

BAA coverage

Business associates and subcontractors tracked with agreement status and current risk position.

AI in healthcare

HIPAA read together with AI governance, for clinical models trained on or prompted with PHI.

The structure

Key HIPAA rules

Five rules, and what each one actually asks for. The last of them is why a vendor contract is no longer where your liability ends.

Privacy Rule

Controls the use and disclosure of protected health information, and establishes individual rights over it.

  • The minimum necessary standard
  • Individual rights: access, amendment, accounting
  • Notice of privacy practices
  • A designated privacy officer
  • Workforce training and sanctions

Security Rule

National standards protecting electronic protected health information.

  • Administrative safeguards: 9 standards
  • Physical safeguards: 4 standards
  • Technical safeguards: 5 standards
  • Organisational requirements
  • Documented policies and procedures

Breach Notification Rule

Requires notification to individuals, to HHS and sometimes to the media when PHI is breached.

  • Breach discovery and harm assessment
  • Individual notification within 60 days
  • HHS notification, annual or immediate
  • Media notification above 500 individuals
  • Documentation and mitigation

Enforcement Rule

Procedures for investigations, hearings and the imposition of civil money penalties.

  • OCR compliance investigations
  • The civil money penalty tiers
  • Criminal prosecution referrals
  • Corrective action plans
  • Resolution agreements

Omnibus Rule

Gave business associates direct liability, widened breach notification and implemented the HITECH Act.

  • Business associate direct liability
  • Subcontractor BAA requirements
  • Strengthened enforcement
  • Expanded individual rights
  • Genetic information protections
The Security Rule

Security Rule safeguards breakdown

Eighteen standards across three families: nine administrative, four physical and five technical. The chip on each card names its family, so the count in the coverage ledger and the list here stay readable against each other.

Administrative

Security management process

Risk analysis, risk management, a sanction policy and review of information system activity.

Administrative

Assigned security responsibility

A designated security official, named, who is responsible for HIPAA security.

Administrative

Workforce security

Authorisation, supervision, clearance procedures and — the one that lapses — termination procedures.

Administrative

Information access management

Access authorisation, establishment and modification, applied per role rather than per request.

Administrative

Security awareness and training

Security reminders, protection from malicious software, log-in monitoring and password management.

Administrative

Security incident procedures

Response to and reporting of security incidents, with the route defined before one happens.

Administrative

Contingency plan

Data backup, disaster recovery, emergency mode operation, testing, and criticality analysis of applications and data.

Administrative

Evaluation

Periodic technical and non-technical evaluation of how well the security measures still fit.

Administrative

Business associate contracts

Written contracts carrying satisfactory assurances that PHI will be safeguarded.

Physical

Facility access controls

Contingency operations, a facility security plan, access control and validation, and maintenance records.

Physical

Workstation use

Policies covering the functions performed at a workstation and how it should be used.

Physical

Workstation security

Physical safeguards restricting workstation access to authorised users.

Physical

Device and media controls

Disposal, media re-use, accountability, and data backup and storage before a device moves.

Technical

Access control

Unique user identification, emergency access procedure, automatic logoff, and encryption and decryption.

Technical

Audit controls

Hardware, software and procedural mechanisms that record and examine access to ePHI.

Technical

Integrity

Policies ensuring ePHI is not improperly altered or destroyed, and a way to detect it if it is.

Technical

Person or entity authentication

Procedures verifying that a person or entity seeking access to ePHI is who they claim to be.

Technical

Transmission security

Integrity controls and encryption for ePHI moving across a network.

The engagement

24-week implementation roadmap

A practical path to HIPAA compliance with clear milestones. The weeks are indicative — the variable is how much of the PHI estate turns out to exist once you go looking.

  1. Weeks 1-4

    Foundation and gap analysis

    Name the owners, then find out what you actually hold.

    • Designate the privacy and security officers
    • Run an initial HIPAA gap assessment
    • Build the PHI inventory and data flow maps
    • Review the existing policies and procedures
  2. Weeks 5-10

    Risk analysis and planning

    The document OCR asks for first, done properly rather than quickly.

    • Complete a full risk analysis
    • Identify threats and vulnerabilities to ePHI
    • Prioritise remediation by risk
    • Build the security management plan
  3. Weeks 11-20

    Safeguards implementation

    Where the eighteen standards stop being a list and start being controls.

    • Implement the administrative safeguards
    • Deploy the physical security controls
    • Configure the technical safeguards
    • Put business associate agreements in place
  4. Weeks 21-24

    Training and validation

    The stage that turns a control set into something a workforce actually follows.

    • Run workforce privacy and security training
    • Test the incident response procedure
    • Validate the technical controls
    • Document the compliance evidence
Consequences

HIPAA penalties and enforcement

Civil money penalties are assessed per violation and scale with culpability. The jump between tier three and tier four is the whole argument for correcting a known problem inside thirty days.

Tier Culpability Per violation Annual maximum
Tier 1 Did not know, and reasonable diligence would not have revealed it $100 to $50,000 $25,000
Tier 2 Reasonable cause, not willful neglect $1,000 to $50,000 $100,000
Tier 3 Willful neglect, corrected within 30 days $10,000 to $50,000 $250,000
Tier 4 Willful neglect, not corrected within 30 days $50,000 $1,500,000

These figures are the tier structure, not a current-year table. OCR adjusts the amounts for inflation annually, so check the published figures before relying on any number here. Penalties are assessed per violation, and multiple violations of different requirements can exceed the annual maximum shown for any one of them.

Criminal exposure

Criminal penalties

Three offences, prosecuted by the Department of Justice rather than pursued by OCR. What separates the tiers is intent.

Tier 1

Up to $50,000 and 1 year

Knowingly obtaining or disclosing protected health information.

  • Knowledge of the act is enough
  • No intent to profit required
  • Imprisonment up to one year
Tier 2

Up to $100,000 and 5 years

Obtaining protected health information under false pretences.

  • Deception is the aggravating element
  • Applies to individuals as well as entities
  • Imprisonment up to five years
Tier 3

Up to $250,000 and 10 years

Obtaining or disclosing PHI intending to sell it, or for commercial advantage, personal gain or malicious harm.

  • Intent to sell, transfer or use
  • Commercial advantage or malicious harm
  • Imprisonment up to ten years

Criminal prosecutions are handled by the Department of Justice; OCR refers them. In practice most organisations meet HIPAA through the civil route, and the criminal tiers matter mainly as the reason workforce sanctions policies have to have teeth.

Policy templates

HIPAA policy template library

Ready-to-use HIPAA policy templates covering the Privacy Rule, the Security Rule and Breach Notification, mapped across to SOC 2 and ISO 27001 so one document set answers more than one auditor.

Privacy Rule policies

  • Notice of Privacy Practices
  • Minimum Necessary Policy
  • Individual Rights Policy
  • Privacy Officer Designation
  • PHI Use and Disclosure Policy
  • Accounting of Disclosures
  • Amendment Request Process

Security Rule policies

  • Security Management Process
  • Access Control Policy
  • Audit Controls Policy
  • Encryption and Decryption Standard
  • Incident Response Plan
  • Contingency Plan
  • Workforce Security Policy

Breach and compliance

  • Breach Notification Policy
  • Breach Risk Assessment
  • Business Associate Agreement
  • Sanctions Policy
  • Training and Awareness Programme
  • Compliance Monitoring
  • Risk Assessment Policy
Questions

Frequently asked questions

Scope, what counts as PHI, the breach clock, and the two questions that decide how much of your estate is in the assessment.

1 Scope and the basics
Who enforces HIPAA?

The Office for Civil Rights within the Department of Health and Human Services. OCR conducts compliance reviews, investigates complaints, runs audits and imposes civil money penalties. Criminal enforcement is handled by the Department of Justice on referral.

What is protected health information?

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form — electronic, paper or spoken. It turns on eighteen identifiers including names, dates, contact details, medical record numbers, health plan numbers and biometric identifiers, once they are linked to health information. Electronic PHI carries the additional Security Rule obligations on top.

What is the difference between a covered entity and a business associate?

Covered entities are healthcare providers, health plans and clearinghouses that handle PHI directly. Business associates are third parties performing services involving PHI on their behalf — EHR vendors, billing companies, consultants. Since the Omnibus Rule in 2013 business associates carry direct HIPAA liability and must themselves comply with the Security Rule and the Breach Notification Rule.

Do we need a business associate agreement?

Yes. A covered entity must have a signed BAA with each business associate before any PHI is shared, and a business associate must have one with each of its subcontractors. The agreement has to include specific provisions on safeguarding, breach notification, return or destruction of PHI, and liability. No compliant BAA means no lawful sharing.

2 The duties themselves
What triggers the Breach Notification Rule?

Acquisition, access, use or disclosure of PHI that compromises its security or privacy. You run a four-factor risk assessment; unless an exclusion applies and the assessment shows a low probability that PHI was compromised, notification is required within 60 days to the individuals affected and to HHS, and to the media where 500 or more individuals in a state or jurisdiction are involved.

What does the Security Rule risk analysis have to cover?

Where ePHI is created, received, maintained and transmitted; the threats to it, human, natural and environmental; the security measures currently in place; the likelihood and impact of each threat; and the resulting risk levels with remediation priorities. It has to be documented and kept current. It is the single most commonly cited deficiency in OCR enforcement, usually because it was done once and never revisited.

Do we have to encrypt all PHI?

Encryption is addressable rather than required, which is not the same as optional. If you do not encrypt, you must document why, and what equivalent alternative measure is in place instead. Encrypting to a NIST-validated standard with proper key management is strongly worth doing regardless, because breached data that was properly encrypted does not trigger the notification duty.

What workforce training is required?

Training on your privacy and security policies is required; the frequency and format are not specified. Annual training for the whole workforce, including volunteers, trainees and contractors, with extra depth for elevated PHI access, is the defensible position. Cover both rules, breach notification, sanctions, individual rights, minimum necessary and business associate obligations — and keep attendance records, because the training you cannot evidence did not happen.

3 Cloud, AI, states and the engagement
How does HIPAA apply to cloud and SaaS vendors?

A provider that stores, processes or transmits ePHI is a business associate and must sign a BAA. The covered entity stays responsible for confirming the vendor has appropriate safeguards; a provider attestation does not transfer your obligations. Review the vendor's security practice, certifications and incident response before engaging, and document the responsibility split.

Where does AI touch HIPAA scope?

In the same three places it touches every data regime, and they matter more here because the identifiers are so broad. PHI copied into a training set or feature store is maintained PHI. A prompt containing patient detail is PHI in transmission, and the model vendor receiving it is a business associate. Inference logs retained for debugging are a copy of both. Each pulls its host system into scope, which is why the PHI inventory is the first workstream on this page.

How does HIPAA relate to state privacy laws?

HIPAA is a federal floor. A state law that gives greater privacy protection or stronger individual rights applies on top, and several states impose shorter breach notification timelines. You comply with both. Unlike SOC 2, which is voluntary and market-driven, HIPAA is mandatory for anyone within its scope.

What does an iDharma HIPAA assessment cover, and how long does it take?

It is scoped before you are charged. The variables are the size of the PHI estate, whether a current risk analysis exists, and whether PHI has reached analytics or model pipelines. A programme typically runs six to nine months end to end; the gap assessment that tells you which of those apply is much shorter. We tell you the shape after a short scoping call.

Get started

Ready to achieve HIPAA compliance?

Start with a gap assessment and a real risk analysis — where PHI actually lives, which of the eighteen safeguards are evidenced, and what the 60-day clock would find if it started tomorrow.

This page is guidance on how we scope an assessment, not legal advice. HHS and OCR publish the rules, the enforcement figures and their own guidance; where a scoping call turns on the wording or on a current penalty amount, go to them rather than to this page.