Protects patients
HIPAA gives individuals legal rights over their health information — including access, correction and control over how their PHI is used or disclosed.
CyberAtrix helps covered entities and business associates build a defensible HIPAA program across the Privacy Rule, the Security Rule and the Breach Notification Rule — grounded in risk analysis, safeguards, Business Associate Agreements, workforce training and OCR audit readiness.

HIPAA is the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law enacted to protect the confidentiality, integrity and availability of patients' medical records and health information. HIPAA is not a single set of rules — it is an interconnected framework that governs how healthcare providers, health plans, clearinghouses and their vendors handle Protected Health Information (PHI).
HIPAA gives individuals legal rights over their health information — including access, correction and control over how their PHI is used or disclosed.
Administrative simplification provisions require specific codes and identifiers for healthcare transactions, enabling smoother interoperability across providers and payers.
Rigorous access and authentication controls help reduce identity theft, false claims and unauthorized access — protecting both patients and healthcare organizations.
HIPAA applies to covered entities and extends to the vendors, subcontractors and service providers that handle PHI on their behalf — the business associates.
Hospitals, clinics, physicians, dentists, pharmacies, nursing homes and any provider who transmits health information electronically.
Health insurance companies, HMOs, Medicare, Medicaid and other plans that pay for healthcare.
Entities that process nonstandard health information into a standard format on behalf of another entity.
Vendors and subcontractors — including IT, cloud, billing, legal, audit and analytics providers — that create, receive, maintain or transmit PHI.
Each pillar addresses a distinct dimension of PHI protection. Together they form an interlocking framework that spans how health information is used, secured and — when something goes wrong — disclosed.
Establishes national standards for how PHI in any form — written, oral or electronic — is used and disclosed.
Sets national standards specifically for electronic PHI (ePHI), covering confidentiality, integrity and availability.
Requires notification when unsecured PHI is impermissibly used or disclosed, subject to a risk assessment.
The HHS Office for Civil Rights (OCR) enforces HIPAA through complaints, investigations and audits.
PHI is any individually identifiable information relating to an individual's health status, provision of healthcare or payment for healthcare. HIPAA identifies 18 categories of identifiers that, when linked to health information, create PHI.
PHI is not confined to electronic records. It exists in written documents, oral conversations and digital systems. A conversation between two clinicians discussing a patient in an elevator can constitute a violation if overheard.
Electronic PHI (ePHI) is the subset of PHI that is created, received, maintained or transmitted in electronic form. The Security Rule focuses exclusively on ePHI.
De-identified data — data stripped of all 18 identifiers — is not subject to the Privacy Rule. However, in a big-data era, re-identification risk must be carefully managed, especially when multiple datasets are combined.
State law overlays: where state laws are stricter than HIPAA — for example, on HIV status or mental health records — covered entities must comply with the more restrictive law.
The HIPAA Security Rule prescribes three categories of safeguards for electronic PHI. Each safeguard has required and addressable implementation specifications — organizations must implement reasonable and appropriate measures and document the rationale where a specification is not implemented.
Policies, procedures and management actions that provide governance for ePHI protection.
Tangible protections for facilities, hardware, workstations, devices and media that hold or access ePHI.
Technology and related policies that protect ePHI and control access to it.
Under the Breach Notification Rule, covered entities and business associates must notify affected individuals, the Secretary of HHS and — for breaches affecting 500 or more individuals in a state or jurisdiction — the media. Notification must be made without unreasonable delay and no later than 60 days after discovery.
Before notifying, the entity assesses the probability that PHI was compromised using four factors: the nature and extent of the PHI, the unauthorized person involved, whether the PHI was actually acquired or viewed, and the extent of mitigation.
Affected individuals receive written notice by first-class mail (or email with prior agreement). HHS receives notification — annually for breaches under 500 individuals, and concurrently for breaches of 500 or more. Media notice is required when 500+ individuals in a state are affected.
Business associates must notify the covered entity following discovery of a breach. The covered entity then fulfills the notification obligations. Timelines and protocols are typically defined in the Business Associate Agreement.
The Privacy Rule establishes a set of enforceable patient rights. Organizations must have practical workflows to receive, validate, fulfill and document each request within defined timeframes.
The HHS Office for Civil Rights (OCR) enforces HIPAA through complaint investigations, compliance reviews and proactive audits. Consequences range from voluntary compliance to Civil Money Penalties and — in cases of willful neglect or intentional misconduct — criminal referral to the Department of Justice.
| Tier | Culpability | Per-violation range | Annual maximum |
|---|---|---|---|
| Tier 1 | Lack of knowledge (could not have realistically avoided with reasonable diligence) | $100 – $50,000 | $1.5M |
| Tier 2 | Reasonable cause, not willful neglect | $1,000 – $50,000 | $1.5M |
| Tier 3 | Willful neglect — corrected within 30 days | $10,000 – $50,000 | $1.5M |
| Tier 4 | Willful neglect — not corrected | $50,000 | $1.5M |
Individuals can file complaints with OCR within 180 days of an alleged violation. OCR reviews jurisdiction, opens an investigation, requests documentation and may conduct interviews or onsite visits.
A CAP is a binding agreement that specifies actions, timelines, staff training and periodic reporting to OCR — often spanning one to three years. Failure to comply can trigger Civil Money Penalties.
OCR can refer cases involving intentional misconduct to the DOJ. Criminal penalties may include fines and imprisonment depending on the nature of the offense.
Across HIPAA enforcement actions, a consistent set of failure patterns emerges. Understanding them is the fastest way to strengthen a compliance program.
Many enforcement actions cite inadequate or outdated risk analysis. Risk analysis is not a one-time event — it must be revisited with business, technology and workforce changes.
Human error remains a leading cause of breaches. Documented, role-appropriate, refreshed workforce training is the strongest preventive control available.
Lost or stolen unencrypted laptops and mobile devices are common breach sources. Encryption, device management and remote access policies are essential.
Late or missing breach notifications are heavily penalized. Documented incident response with clear escalation and notification workflows is critical.
Missing or inadequate Business Associate Agreements leave covered entities liable for vendor failures. Due diligence and ongoing oversight are required.
OCR has repeatedly fined small practices, clinics and individual providers. Every covered entity and business associate is expected to comply, regardless of size.
CyberAtrix delivers HIPAA consulting across every part of the program — governance, risk, safeguards, business associates, breach readiness and audit preparation.
Assess current practices against the Privacy, Security and Breach Notification Rules and produce a prioritized remediation roadmap.
Identify where ePHI is created, received, maintained and transmitted. Assess threats, vulnerabilities, likelihood and impact. Document decisions.
Develop the administrative, physical and technical safeguard documentation HIPAA expects — including sanctions, contingency, incident response and device management.
Review, draft and negotiate Business Associate Agreements. Establish due diligence, sub-processor oversight and ongoing vendor assurance.
Role-appropriate training for clinical, administrative, IT, HR and leadership teams. Documented attendance, content and assessments.
Build the incident response and breach assessment workflows — evidence preservation, risk assessment, individual notice, HHS reporting and, where required, media notice.
Prepare documentation, evidence and interview readiness for desk reviews, onsite audits and potential investigations.
Map HIPAA requirements to ISO 27001, ISO 27701, SOC 2 and NIST controls so a single program supports multiple obligations.
A practical sequence for organizations starting a HIPAA program or maturing an existing one. The order matters — risk analysis is the foundation everything else is built upon.
Determine whether you are a covered entity or business associate, which locations, systems and workforce members fall within scope, and which PHI or ePHI you handle.
Identify where PHI and ePHI are stored, processed and transmitted. Identify threats, vulnerabilities, likelihood and impact. Document the analysis — this is the most frequently cited gap in OCR enforcement.
Choose reasonable and appropriate safeguards to reduce identified risks to a reasonable and acceptable level. Document the decisions, including rationale for addressable specifications.
Develop administrative, physical and technical safeguards as documented policies and procedures — sanctions, contingency, incident response, device management, access control and others.
Execute BAAs with every relevant vendor and subcontractor. Conduct due diligence, review safeguards and maintain ongoing oversight.
Train all workforce members on the policies and procedures relevant to their role. Document attendance, content and assessments. Refresh periodically.
Define incident response and breach assessment processes. Build notification workflows for individuals, HHS and — where required — the media. Rehearse the plan.
Run regular internal audits, review logs, revisit risk analysis after change, close corrective actions and keep evidence current and organized.
Digital transformation has not changed the core of HIPAA — protect PHI and respect patient rights — but it has transformed where PHI lives and how it flows.
Telehealth platforms must use end-to-end encryption, role-based access and auditable logs. A BAA is required with platform providers handling ePHI. Patients should be educated about their own environment and network security.
Cloud service providers that store, process or transmit PHI are business associates. Requirements include BAAs, encryption at rest and in transit, access controls, audit trails, backup and physical data-center security.
When an mHealth app handles PHI on behalf of a covered entity, HIPAA applies. Requirements include encryption, strong authentication, access controls, integrity controls and secure transmission.
De-identified datasets are useful for research, but re-identification risk grows when datasets are combined. Robust de-identification techniques, privacy-by-design and purpose limitation reduce risk.
Connected medical devices and wearables expand the attack surface. Device management, network segmentation and security assessments are essential parts of a modern HIPAA program.
AI and machine learning introduce questions about training data, model governance, algorithmic bias and re-identification risk. HIPAA principles — data minimization, purpose limitation and accountability — remain the guide.
Most organizations face multiple frameworks — HIPAA, ISO 27001, GDPR, SOC 2 and PCI DSS. A well-designed governance program shares controls and evidence across obligations, reducing duplication and improving assurance.
ISO 27001's ISMS provides the management-system backbone. HIPAA safeguards map cleanly to ISO 27002 controls for access, cryptography, supplier relationships, incident management and business continuity.
Both protect personal data but from different angles. GDPR focuses on European data subjects; HIPAA focuses on U.S. health information. Organizations handling both can share governance, records, DPIAs and incident response processes.
SOC 2 Trust Services Criteria overlap with HIPAA Security Rule safeguards on access, change management, monitoring and vendor oversight. Shared evidence reduces audit fatigue.
Our HIPAA engagements follow a practical operating model that leadership, legal, compliance, security, IT and clinical teams can actually execute together.
Common questions from healthcare providers, payers, business associates and technology vendors.
HIPAA is the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law that protects the confidentiality, integrity and availability of Protected Health Information. HIPAA is built on three pillars: the Privacy Rule, the Security Rule and the Breach Notification Rule, plus administrative simplification provisions.
HIPAA applies to covered entities — healthcare providers, health plans and healthcare clearinghouses that transmit health information electronically — and to their business associates: vendors and subcontractors that create, receive, maintain or transmit PHI on their behalf.
PHI is any individually identifiable information relating to health status, provision of healthcare or payment for healthcare. HIPAA identifies 18 categories of identifiers — including name, address, dates, telephone numbers, email addresses, Social Security numbers, medical record numbers, account numbers, device identifiers, web URLs, IP addresses, biometric identifiers and photographic images — that when linked to health information create PHI.
The Privacy Rule applies to PHI in all forms — written, oral and electronic — and governs when PHI may be used or disclosed. The Security Rule focuses exclusively on electronic PHI (ePHI) and prescribes administrative, physical and technical safeguards to protect its confidentiality, integrity and availability.
The Breach Notification Rule requires covered entities and business associates to notify affected individuals, the Secretary of Health and Human Services and — for breaches affecting 500 or more individuals in a state or jurisdiction — the media. Notification must be made without unreasonable delay and no later than 60 days after discovery.
A Business Associate Agreement is a legally binding contract that outlines how a business associate will safeguard Protected Health Information when performing services for or on behalf of a covered entity. BAAs are required by HIPAA and describe permitted uses, disclosures, safeguards and reporting obligations.
Administrative safeguards are policies and procedures such as risk analysis, workforce security, training and incident procedures. Physical safeguards cover facility access, workstation use and device and media controls. Technical safeguards include access control, audit controls, integrity controls, person or entity authentication and transmission security.
Civil money penalties under HIPAA are tiered by culpability, ranging from $100 to $50,000 per violation, with a maximum annual penalty of $1.5 million for identical provisions. Criminal penalties can apply in cases of intentional misconduct and may include imprisonment.
HIPAA can apply to telehealth platforms, cloud service providers and mobile health apps when they create, receive, maintain or transmit ePHI on behalf of a covered entity or business associate. Cloud providers and many technology vendors act as business associates and require a BAA.
HIPAA requires covered entities and business associates to designate a privacy official and a security official responsible for developing and implementing policies and procedures. The role may be combined with other responsibilities in smaller organizations, but the designation is required.
Risk analysis under the Security Rule is not a one-time activity. It should be reviewed regularly — at least annually — and revisited whenever there are significant changes to business, technology, systems, workforce or threats.
Encryption and decryption are addressable implementation specifications under the Security Rule, not mandatory absolute requirements. However, if an organization determines that encryption is not reasonable and appropriate, it must document the rationale and implement an equivalent alternative measure.
HIPAA is a U.S. regulation; ISO 27001 is an international certifiable management-system standard. Many organizations map HIPAA requirements against ISO 27001, ISO 27701, SOC 2 and NIST controls to reduce duplication and build one integrated compliance program.
The HHS Office for Civil Rights can investigate complaints, conduct compliance reviews and perform audits. Audits may start as desk reviews and escalate to onsite reviews with interviews. If violations are found, OCR may seek voluntary compliance, a Corrective Action Plan or Civil Money Penalties.
Get a scoped HIPAA assessment and a practical roadmap for privacy governance, risk analysis, safeguards, Business Associate governance, breach readiness and OCR audit preparation.