Health Insurance Portability and Accountability Act (HIPAA)

A practical introduction to HIPAA, including who counts as a covered entity or business associate, what the rules require, and how compliance is actually demonstrated.

healthcare

Edited by Jeff Stiles, CISSP, Colin Doubek, CISSP, and Garrett Stiles, CISSP

Quick decision helper

Answer one question to see where your organization likely stands under HIPAA.

Which best describes your organization?


Deciding something else? How much does HIPAA compliance cost?

What is HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 U.S. federal law. For compliance purposes, what matters is not the statute itself but the regulations issued under it: the Privacy Rule, the Security Rule, and the Breach Notification Rule, which together govern how protected health information (PHI) may be used, disclosed, and safeguarded.

HIPAA exists because health information moves constantly between providers, insurers, billing services, and software vendors, and the people it describes have almost no ability to protect it themselves. The rules put the obligation on the organizations that hold the data.

The rule set in force today took its current shape with the 2013 Omnibus Rule. A significant Security Rule update was proposed in January 2025 and is still in rulemaking, with final action currently projected for July 2027; the existing rule applies until a final rule says otherwise. See our coverage of the timeline.

The most common misconception first: there is no official HIPAA certification. No government body certifies organizations as HIPAA compliant, and no seal or badge changes your legal position. Compliance is something you do and document, not something you are awarded.

Who HIPAA applies to

HIPAA applies to two groups:

  • Covered entities: health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with standard transactions such as billing. In practice, almost any provider that bills insurance qualifies.
  • Business associates: organizations that create, receive, maintain, or transmit PHI on a covered entity’s behalf. That includes billing companies, cloud and hosting providers, IT firms, transcription services, law firms, and analytics vendors. Subcontractors of business associates are covered too, all the way down the chain.

The surprise case is the technology company that never thought of itself as a healthcare business. If your software stores patient data for clinics, you are likely a business associate with direct liability under the Security and Breach Notification Rules, and your customer should be handing you a business associate agreement (BAA) to sign.

Two boundaries worth knowing. Employment records held by an employer are not PHI, even when they contain health information. And consumer health apps with no covered entity relationship generally fall outside HIPAA, though the Federal Trade Commission’s separate health breach rules may still apply to them.

Who manages and enforces HIPAA

The U.S. Department of Health and Human Services (HHS) writes the rules, and its Office for Civil Rights (OCR) interprets and enforces them.

Enforcement usually starts one of three ways: a complaint (anyone can file one), a breach report you are required to submit, or an OCR compliance review. Investigations commonly end in technical assistance or corrective action; more serious cases end in resolution agreements with monetary settlements and multi-year corrective action plans, or in civil money penalties. Penalties are tiered by culpability, from violations the organization could not reasonably have known about up to willful neglect left uncorrected, with annual caps in the millions of dollars per violation category.

State attorneys general can also bring HIPAA actions, and the Department of Justice prosecutes knowing misuse of PHI criminally.

Two patterns dominate recent enforcement: incomplete or missing risk analysis, and late breach notification, especially after ransomware. OCR’s July 2026 settlement with OSF Healthcare is a representative example of both; see our summary. If you want to predict what an investigator will ask for first, it is your risk analysis.

What is in scope

HIPAA protects PHI: individually identifiable health information held or transmitted by a covered entity or business associate, in any form. The Security Rule applies to the electronic subset, ePHI. Identifiability is broad; names, dates, addresses, device identifiers, and anything else that could reasonably identify the person count when tied to health information.

Properly de-identified data, stripped of identifiers under the rule’s specific methods, falls outside HIPAA. De-identification is a defined technical bar, not a synonym for “we removed the names.”

For scoping a security program, the working question is where ePHI lives and moves. A useful trace:

  1. Where does ePHI enter the organization (EHR, intake forms, faxes, patient portals, phone recordings)?
  2. Which systems store it, including email, file shares, backups, and spreadsheets that escaped the official system?
  3. Who can access it, and is that access limited to what their job requires?
  4. Which vendors receive it, and does each have a signed BAA?
  5. Where does it leave (claims, referrals, analytics, offshore support)?

Most organizations discover ePHI in more places than they expected, and that sprawl, not the EHR itself, is where breaches tend to happen.

What HIPAA requires

The obligations come from three rules:

  • The Privacy Rule governs uses and disclosures of PHI in any form. It permits use for treatment, payment, and healthcare operations, requires authorization for most other purposes, imposes the minimum necessary standard, and gives individuals rights to access, amend, and receive an accounting of their information. Providers must publish a Notice of Privacy Practices.
  • The Security Rule requires safeguards for ePHI in three families: administrative (risk analysis, workforce training, access management, incident procedures, contingency planning), physical (facility and device controls), and technical (access controls, audit logging, integrity, transmission security, encryption). Some specifications are required outright; others are addressable, meaning you assess whether they are reasonable and appropriate for your environment and document the decision. Addressable does not mean optional.
  • The Breach Notification Rule requires notifying affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI, notifying HHS (immediately for breaches affecting 500 or more people, annually for smaller ones), and notifying media for large breaches in a state or jurisdiction.

The Security Rule’s cornerstone is the risk analysis: an accurate, thorough assessment of risks to all ePHI you hold. Every other safeguard decision is supposed to flow from it, and its absence is the most commonly cited failure in enforcement actions. If you are doing it yourself for the first time, our free risk assessment tool walks through the NIST method in your browser and produces a register and report you keep.

How compliance is demonstrated

HIPAA has no certification, no standard report, and no required external audit, which raises the practical question of what “being compliant” looks like. The answer is documentation that would satisfy an investigator:

  • a current, enterprise-wide risk analysis and the risk management plan acting on it;
  • written policies and procedures mapped to the rules, with documented review;
  • training records for the workforce;
  • signed BAAs for every vendor touching PHI;
  • documentation of addressable-specification decisions;
  • incident and breach logs with the notifications sent; and
  • six years of retention for the above, which is the rule’s documentation window.

Outside help fits in two honest ways. A third-party assessment or gap analysis can test your program against the rules and strengthen your documentation. Technical testing such as vulnerability scanning and penetration testing supports the risk analysis, though HIPAA does not mandate a penetration test by name. Adjacent attestations like SOC 2 or HITRUST certification can help demonstrate diligence to customers, but none of them is HIPAA compliance itself.

Be skeptical of products sold as “HIPAA certification.” A vendor’s seal has no regulatory standing. What stands up is your own risk analysis, your safeguards, and your paper trail.

The HIPAA compliance process

A practical first cycle:

  1. Confirm your status. Covered entity, business associate, or neither, and for hybrid organizations, which parts of the business are covered.
  2. Assign ownership. Designate the privacy and security officials the rules require; in small organizations this is one person with the duty written down.
  3. Trace ePHI and run the risk analysis. Inventory systems, data flows, and vendors, then assess threats and vulnerabilities against them.
  4. Remediate by risk. Implement or tighten safeguards, starting with the findings that most endanger ePHI: access control, encryption, backups, logging.
  5. Write the policies and train. Policies that match what you actually do, and training records for everyone with PHI access.
  6. Paper the vendors. BAAs with every business associate, and a look at their security posture, since their breach becomes your notification problem.
  7. Prepare for incidents. A response plan that can meet the 60-day clock, tested before it is needed.

Who decides, and what to ask

HIPAA is unusual among the standards on this site: no one assigns you an obligation, receives a filing, or tells you which form to complete. You determine your own status, and OCR appears only after a complaint, a breach report, or a compliance review. The questions that shape your program are therefore aimed at the organizations around you rather than at a regulator. Ask, and keep the answers in writing:

  • The covered entities you serve, or your customers. Do they consider you a business associate? Will they send a BAA, or do they expect yours? What does their BAA require beyond the rules, such as encryption standards, notification windows shorter than 60 days, or audit rights?
  • Your vendors. Which of them handle PHI for you, and will each sign a BAA? Some large cloud and software vendors offer a BAA only on specific plans or for specific services, and the answer changes what you can put where.
  • Anyone asking you to “prove HIPAA compliance.” Do they mean HIPAA itself, HITRUST certification, or a SOC 2 report? The budgets differ by an order of magnitude, and the contract usually names one.
  • Your cyber insurer. What controls does the policy require for a breach to be covered (multi-factor authentication, backups, training), and how quickly must you notify them of an incident?
  • Your own leadership. Who is the designated privacy official and who is the security official? The rules require both to be named, and in a small organization it can be one person.

None of those parties can make you compliant, but their answers set the practical requirements you will actually be held to, often more concretely than the regulation text does.

The risk analysis dominates the calendar in a first cycle, and remediation dominates the budget. The documentation, done alongside rather than after, is comparatively cheap.

Cost, time, and internal effort

HIPAA has no required audit, certification, or filing fee. Unlike most standards on this site, there is no external validation you must buy, which is why this page shows no typical-cost range. The required work is the risk analysis, safeguards, policies, and training, and you can do all of it internally.

Many organizations still buy an optional third-party security risk assessment for independence or expertise. Small practices commonly pay $2,000 to $8,000; larger or multi-site organizations can exceed $50,000 when technical testing is in scope. Beyond that, spend is work: staff time, remediation, tooling, and any outside policy or testing help. A hospital system or software vendor with complex infrastructure can reach six figures once remediation and tooling are counted. A full breakdown, including where these figures come from, is in How much does HIPAA compliance cost?

One market reality changes this picture for many companies: payers, health systems, and partners often demand HITRUST certification as their proof of HIPAA-grade security. HITRUST is a separate framework with its own assessors and fees, and its cost typically runs several times a standalone HIPAA assessment. If a contract names HITRUST, that requirement, not the regulation, sets your audit budget.

The page’s ranges are directional, not a quote. The strongest predictors:

  • workforce size, which drives training and access management;
  • how many systems and vendors touch ePHI;
  • security maturity before you start;
  • how much remediation the risk analysis surfaces; and
  • whether you buy outside assessment, policy, or testing help.

Time follows the same logic. An organized small practice can stand up a credible program in weeks. A first-time enterprise effort with real remediation runs months. The 60-day breach clock, however, applies from day one, so incident readiness should not wait for the rest of the program.

Maintaining compliance

HIPAA expects the program to keep running:

  • Refresh the risk analysis periodically and when the environment changes: new systems, new vendors, new locations, or an acquisition.
  • Keep the risk management plan alive, with owners and dates, not a findings PDF no one reopens.
  • Train continuously: new hires promptly, everyone on a recurring cycle, with records.
  • Review access as people join, move, and leave.
  • Manage BAAs as vendors change, and re-check key vendors’ posture occasionally.
  • Exercise incident response against the notification deadlines.
  • Watch the rulemaking. The proposed Security Rule update would tighten several safeguard expectations if finalized. Do not wait for it to close known gaps, and do not treat proposal text as a current obligation either. Follow HIPAA on this site for developments.

Scope drift is the quiet risk here too: a new telehealth tool, analytics vendor, or marketing pixel can move PHI somewhere your last risk analysis never considered. Put a HIPAA check into procurement and change management.

How to get started

If HIPAA just became your problem, start with five concrete actions:

  1. Establish your status in writing: covered entity, business associate, or both, and for which lines of business. Everything else depends on this.
  2. Inventory where PHI lives. One list: systems, storage, devices, and vendors, including the unofficial ones like inboxes and spreadsheets.
  3. Collect or create your BAAs. Find every vendor touching PHI and confirm a signed agreement exists for each.
  4. Run a risk analysis. Self-performed with a structured method, or with outside help, but genuinely thorough and covering everything from your inventory.
  5. Fix the notification gap first. Confirm someone owns breach response and can meet the 60-day individual and HHS deadlines today, because that clock runs regardless of program maturity.

HHS’s HIPAA for Professionals hub has the rule text, guidance, and breach reporting portal.

The first goal is not mastering three rules at once. It is knowing your status, where PHI actually lives, and that you could respond to an incident tomorrow. With those settled, the rest of the program is a sequence of manageable projects.

Guides

  • How much does HIPAA compliance cost?

    HIPAA has no required audit or certification fee. See what the work actually costs, from a self-conducted risk analysis to optional third-party assessments and first-year program budgets.

Version history

VersionStatusReleasedEffectiveRetiredSummary
Security Rule update (proposed) upcoming Jan 6, 2025Proposed rule to strengthen ePHI cybersecurity, including risk analysis, encryption, and multi-factor authentication expectations. Final action is projected for July 2027 on the federal agenda; the current Security Rule remains in force.
2013 Omnibus Rule current Jan 25, 2013Sep 23, 2013Implemented the HITECH Act. Made business associates directly liable, tightened the breach notification standard, and consolidated earlier amendments into the rule set in force today.
HITECH updates retired
→ 2013 Omnibus Rule
Aug 24, 2009Sep 23, 2009Sep 22, 2013Added the Breach Notification Rule and tiered civil penalties following the HITECH Act, and set the stage for direct business associate liability.
Privacy and Security Rules (original) retired
→ HITECH updates
Dec 28, 2000Apr 20, 2005Sep 22, 2009The original Privacy Rule (compliance 2003) and Security Rule (compliance 2005) that established PHI protections and the safeguard structure still used today, later amended by HITECH-era rulemaking.

New versions are announced in news. Follow this standard to get notified.