Regulation
Intermediate

HIPAA Quick-Start

A beginner-friendly walk of HIPAA — the 1996 Health Insurance Portability and Accountability Act, enforced by the HHS Office for Civil Rights (OCR), applicable US-wide to Covered Entities and Business Associates handling Protected Health Information (PHI). The primer names the law, the regulator, and the scope before it opens the Privacy Rule (§164.500–§164.534), the Security Rule (§164.302–§164.318), and the Breach Notification Rule (§164.400–§164.414) subpart by subpart, and pairs each citation with the concrete artifact the audit asks for.

Last updated:

Pair this primer with the full course: Full /courses/hipaa walk →

What HIPAA is

HIPAA — the Health Insurance Portability and Accountability Act of 1996 — is the federal US law that governs how Protected Health Information (PHI) is created, received, maintained, transmitted, and disclosed. It sits in the Privacy Rule (45 CFR §164.500–§164.534), the Security Rule (§164.302–§164.318), and the Breach Notification Rule (§164.400–§164.414), each of which opens a different part of the obligation: the Privacy Rule prescribes what can be done with PHI and to whom; the Security Rule prescribes the administrative, physical, and technical safeguards that protect electronic PHI (ePHI) in doing it; the Breach Notification Rule prescribes what happens when the protection fails.

Enforcement runs through the HHS Office for Civil Rights (OCR). OCR opens the inquiry letter, runs the resolution-agreement cycle, and posts resolution agreements and breach disclosures publicly — the "Wall of Shame" of breaches affecting 500 or more individuals is one of the documents an OCR reviewer will routinely surface during a follow-up. The regulator-first framing matters: OCR reads HIPAA as an evidence obligation, not a policy claim; a written policy without the corresponding artifact is the most common finding pattern.

The scope is national, any US entity, any size. Covered Entities (CE) and Business Associates (BA) are both directly answerable to OCR; the BAA chain does not move accountability downstream, it adds to it. PHI is the HIPAA keyword — the regulation does not call it PII. PHI is any individually identifiable health information held or transmitted by a CE or BA; any brief that touches EU and US data subjects side by side is reading PHI and PII as adjacent but distinct concepts.

Who must comply

  • Covered Entities (CE) — health plans, health-care clearinghouses, and certain health-care providers that transmit health information in electronic form. The CE carries the full §164.308–§164.312 load and answers directly to OCR.
  • Business Associates (BA) — vendors or service providers that create, receive, maintain, or transmit PHI on a Covered Entity's behalf. The list is wide: cloud hosts that store ePHI, billing vendors that touch claims data, transcription services, EHR consultants, and shred-and-disposal contractors that handle PHI-bearing media at end of life.
  • The §164.308(b)(1) BAA gate — before a BA touches PHI, the CE and the BA must execute a written Business Associate Agreement that binds the BA to the §164.308–§164.312 safeguards, requires breach notification to the CE, and authorizes termination for material breach. A vendor contract without a BAA where PHI is exchanged is the most direct path to an OCR finding.
  • Downstream liability — the CE remains ultimately accountable to OCR even after a BAA is signed; the BA inherits direct §164.308–§164.312 obligations toward OCR, and a subcontractor that touches PHI on the BA's behalf needs its own downstream BAA. The chain does not dilute the CE's exposure — it just creates the contractual right of recovery.

Key components — Privacy Rule

  • §164.502 — permitted uses and disclosures of PHI. Treatment, payment, and health-care operations are the default-permitted category; everything else requires a §164.508 written authorization from the individual or a §164.512 public-interest exception (required by law, public health activities, victims of abuse or neglect, research with an IRB waiver, and the like).
  • §164.508 — authorizations. A valid authorization is specific about what is being disclosed and to whom, time-limited, revocable in writing by the individual, and signed by the individual or a personal representative. A blanket "marketing consent" is not a §164.508 authorization; the form and content requirements are themselves auditing territory.
  • §164.510 and §164.512 — public-interest and required-by-law disclosures. Facility directories, disclosures to family members involved in care, law-enforcement disclosures under limited conditions, and the public-interest exceptions for abuse, neglect, and serious threats to health or safety. Each has a written-condition list OCR checks against.
  • §164.522 — the minimum-necessary standard. Uses, disclosures, and requests of PHI must be limited to the minimum necessary to accomplish the intended purpose. The minimum-necessary analysis is itself the artifact; a CE that discloses a full chart where a lab result would have done has failed the standard.
  • §164.524 and §164.526 — individual access and amendment rights. The individual has the right to inspect and obtain a copy of their own designated record set within 30 days (extendable once by 30 days with written notice); the right to request an amendment, which the CE must act on within 60 days. The 30-day clock on access is the workflow the rights-operations team runs from.
  • §164.530 — administrative requirements. Designate a privacy official and a contact person, train workforce members on the privacy policies, implement safeguards (administrative, technical, physical — the same triple the Security Rule uses), establish a complaint process for individuals, apply sanctions against workforce members who violate policies, and retain documentation for six years. A CE that can name the privacy official and produce the training log has the most common §164.530 finding closed.

Key components — Security Rule

  • §164.308 — Administrative safeguards. The security management process (including the §164.308(a)(1)(ii)(A) Risk Analysis and §164.308(a)(1)(ii)(B) Risk Management), assigned security responsibility, workforce security, information access management, security awareness and training, incident procedures, contingency plan, evaluation, and Business Associate Contracts at §164.308(b)(1). The Risk Analysis is the most-cited requirement in OCR resolution agreements.
  • §164.310 — Physical safeguards. Facility access controls, workstation use, workstation security, and device and media controls — the chain that covers how laptops, USB drives, and decommissioned hard drives are inventoried, wiped, and disposed. Disposal of ePHI-bearing media without a documented wipe record is one of the simplest findings to remediate and one of the most common in incident reports.
  • §164.312 — Technical safeguards. Access control (§164.312(a)(1)), audit controls (§164.312(b)), integrity (§164.312(c)(1)), person or entity authentication (§164.312(d)), and transmission security (§164.312(e)(1)) — the five subparts an OCR inquiry letter asks about first. Encryption at rest and in transit sits here; the §164.312(a)(2)(iv) encryption-and-decryption implementation is addressable, and the equivalent-alternative analysis is its own artifact.
  • Addressable vs required — several implementations across the administrative, physical, and technical safeguard categories are marked "addressable," meaning the CE either implements the specification as written or documents an equivalent alternative measure that is reasonable and appropriate. The analysis justifying the alternative is itself the artifact the auditor asks for; a missing equivalent-alternative row is the most common Security Rule finding.

Key components — Breach Notification Rule

  • §164.402 — breach presumption. An unauthorized acquisition, access, use, or disclosure of PHI is presumed to be a breach unless the CE or BA demonstrates, through a four-factor risk assessment, that there is a low probability the PHI has been compromised. The four factors: (1) the nature and extent of the PHI involved; (2) the unauthorized person who used or received the PHI; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated. The four-factor assessment is itself the document OCR pulls first.
  • §164.404 — individual notice. Notice to each affected individual "without unreasonable delay and in no case later than 60 calendar days" after discovery. First-class mail to last known address, or email if the individual has agreed to electronic notice. The 60-day clock is hard, not aspirational.
  • §164.408 — HHS notice. Notice to the Secretary of HHS no later than 60 days after discovery. If the breach affects more than 500 individuals, notice is contemporaneous with the individual notice and is publicly listed on the HHS "Wall of Shame"; 500-or-fewer breaches may be logged annually within 60 days of the calendar-year end.
  • §164.406 — media notice. When a breach affects more than 500 residents of a state or jurisdiction, the CE must notify prominent media outlets serving the affected area. The 500-resident trigger is per-state, not aggregate.
  • §164.410 and §164.412 — administrative requirements and documentation. Maintain a log of breaches affecting fewer than 500 individuals for OCR inspection on request, retain the documentation for six years per §164.530(j), and ensure the notice content meets §164.404(c) (the description of what happened, the types of PHI involved, the steps individuals should take, the steps the CE is taking, and a contact procedure for more information).

How to get started

Confirm scope first. Open with the §164.502 scope question: is the reader's organization a Covered Entity (health plan, health-care clearinghouse, or a health-care provider that transmits health information electronically) or a Business Associate (a vendor creating, receiving, maintaining, or transmitting PHI on a CE's behalf)? If neither, the Privacy, Security, and Breach Notification Rules do not directly apply. Confirming "we are neither, so HIPAA stops here" early is the cheapest document on the page.

Inventory every system that touches PHI. Per the §164.308(a)(1)(ii)(A) Risk Analysis, the inventory must list every system that creates, receives, maintains, or transmits ePHI, the threats against it, the vulnerabilities those threats exploit, the likelihood of materialization, the impact if it does, and the current controls in place. This document is the most-cited OCR artifact and the first one an inquiry letter or a vendor BAA review opens with.

Run the §164.308(a)(1)(ii)(A) Risk Analysis. The OCR inquiry letter opens here. Document the methodology, the assets in scope, the threats catalogued, the vulnerabilities, the likelihood-and-impact scoring, and the current-control set. A Risk Analysis without a paired Risk Management plan is the single most common OCR resolution-agreement trigger.

Pair the §164.308(a)(1)(ii)(B) Risk Management plan to each finding. For every Risk Analysis finding, name a security measure, an owner, a remediation date, and a verification step. The Risk Management plan is what turns the analysis from a finding list into a remediation commitment the AO can sign against.

Confirm every BA has an executed §164.308(b)(1) BAA, and that any subcontractor touching PHI has a downstream BAA. The BAA inventory is itself the second artifact an inquiry letter and a vendor due-diligence review will ask for. A vendor whose contract has no BAA but whose service touches PHI is the single most common §164.308(b)(1) finding.

Rehearse the §164.402 four-factor breach assessment on a tabletop scenario so the §164.404 individual-notice clock (60 days) and the §164.408 HHS-notice clock (60 days, with the 500-or-more trigger earmarked for the HHS Wall of Shame) are wired before a real incident hits. The four-factor worksheet, the notice templates, and the contact lists for HHS, the media, and the affected individuals are the artifacts a tabletop produces.

Two beginner briefs anchor the entry path: Atlas Health Partners (regional integrated delivery network, post-merger HITRUST foundation and an OCR inquiry letter in the next two quarters) runs the annual risk-assessment walkthrough — re-runs the §164.308(a)(1)(ii)(A) Risk Analysis against the post-merger systems inventory, pairs the §164.308(a)(1)(ii)(B) Risk Management plan to each finding, and confirms the BAA inventory. WovenCart (D2C apparel on Shopify Plus, no direct PHI scope, evaluating a benefits-administration SaaS for its own employees' health-plan enrollment) handles a vendor BAA review — walks the §164.308(b)(1) BAA clauses, flags the vendor's carve-outs, and returns a redline that closes the §164.308(b)(1) gap before the pilot starts.

The laminate for HIPAA reads the same way every primer reads: name the rule, name the CFR citation, name the next concrete artifact. The Privacy, Security, and Breach Notification Rules are the three pillars; the CFR citations point to the subpart; the next concrete artifact is the document that proves the rule has been read.

Related primers

  • Course — the full HIPAA walk at /courses/hipaa, with the Security Rule subparts and the Breach Notification four-factor assessment walked article by article.
  • Primary lab — the Gap Analysis lab at /labs/gap-analysis-lab, HIPAA-selectable from the framework picker. Score a real environment against the HIPAA safeguard categories on a 0–3 maturity scale and print a Gap Report (per-category current vs target, average maturity, and a remediation list sorted lowest first).
  • Secondary lab — the Compliance Checklist lab at /labs/compliance-checklist-lab covers HIPAA, PCI, and GDPR side by side; useful when a brief reaches the analyst already framed across multiple US regulations.
  • GDPR primer at /guides/gdpr-quickstart — the PHI ↔ PII cross-walk for any brief that touches EU and US data subjects side by side. PHI is the HIPAA term and is the GDPR-touched concept; PII is the GDPR term. A US-based CE handling EU data subjects is reading HIPAA and GDPR concurrently.
  • SOC 2 primer at /guides/soc-2-quickstart — a Business Associate inherits direct §164.308–§164.312 duties toward OCR, and the SOC 2 Confidentiality and Privacy Trust Services Criteria overlap with the HIPAA Security and Privacy Rules at the safeguard layer. The SOC 2 + HIPAA pair is the dual-framework artifact most BA-side vendors are asked about.
Next
Next: try the Gap Analysis lab

Score a real environment against the HIPAA safeguard categories on a 0–3 maturity scale and print a Gap Report (per-category current vs target, average maturity, and a remediation list sorted lowest first). HIPAA is selectable directly from the lab's free sub-form — no payment required to walk the safeguards and read the gap scoring.

Open the Gap Analysis lab →