●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
●Enterprise Cybersecurity & Compliance●Cloud & Infrastructure Security●Offensive Security Testing●Governance & Risk Management
HIPAA Compliance & ePHI Protection

HIPAA compliance consulting — turn privacy obligations into patient trust.

CyberAtrix helps covered entities and business associates build a defensible HIPAA program across the Privacy Rule, the Security Rule and the Breach Notification Rule — grounded in risk analysis, safeguards, Business Associate Agreements, workforce training and OCR audit readiness.

Healthcare cybersecurity and HIPAA compliance environment
● HIPAA READY
Privacy Rule
Security Rule
Breach Rule
3Core HIPAA RulesPrivacy · Security · Breach Notification
18PHI identifiersUsed to define Protected Health Information
3Safeguard categoriesAdministrative · Physical · Technical
$1.5MMax annual CMPPer violation category, per year
HIPAA explained

What is HIPAA — and why does it matter?

HIPAA is the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law enacted to protect the confidentiality, integrity and availability of patients' medical records and health information. HIPAA is not a single set of rules — it is an interconnected framework that governs how healthcare providers, health plans, clearinghouses and their vendors handle Protected Health Information (PHI).

Protects patients

HIPAA gives individuals legal rights over their health information — including access, correction and control over how their PHI is used or disclosed.

Standardizes operations

Administrative simplification provisions require specific codes and identifiers for healthcare transactions, enabling smoother interoperability across providers and payers.

Reduces fraud and risk

Rigorous access and authentication controls help reduce identity theft, false claims and unauthorized access — protecting both patients and healthcare organizations.

Why it matters: HIPAA compliance is not a checkbox. It is a legal, ethical and operational foundation for patient trust. Non-compliance can lead to Civil Money Penalties up to $1.5 million per year for identical violations, corrective action plans, reputational damage and, in cases of willful neglect, criminal prosecution.
Scope

Who has to comply with HIPAA?

HIPAA applies to covered entities and extends to the vendors, subcontractors and service providers that handle PHI on their behalf — the business associates.

01

Healthcare providers

Hospitals, clinics, physicians, dentists, pharmacies, nursing homes and any provider who transmits health information electronically.

02

Health plans

Health insurance companies, HMOs, Medicare, Medicaid and other plans that pay for healthcare.

03

Clearinghouses

Entities that process nonstandard health information into a standard format on behalf of another entity.

04

Business associates

Vendors and subcontractors — including IT, cloud, billing, legal, audit and analytics providers — that create, receive, maintain or transmit PHI.

The three pillars

The Privacy Rule, Security Rule and Breach Notification Rule.

Each pillar addresses a distinct dimension of PHI protection. Together they form an interlocking framework that spans how health information is used, secured and — when something goes wrong — disclosed.

01

Privacy Rule

Establishes national standards for how PHI in any form — written, oral or electronic — is used and disclosed.

  • Patient rights: access, correction, accounting
  • Permitted uses for treatment, payment, operations
  • Notice of Privacy Practices
  • Authorization for non-routine disclosures
  • Minimum Necessary standard
02

Security Rule

Sets national standards specifically for electronic PHI (ePHI), covering confidentiality, integrity and availability.

  • Administrative safeguards
  • Physical safeguards
  • Technical safeguards
  • Required vs. addressable specifications
  • Scalable to organization size and risk
03

Breach Notification Rule

Requires notification when unsecured PHI is impermissibly used or disclosed, subject to a risk assessment.

  • Individual notice within 60 days
  • HHS notification
  • Media notice for 500+ individuals
  • Business associate reporting to covered entity
  • Documentation and record-keeping
04

Enforcement

The HHS Office for Civil Rights (OCR) enforces HIPAA through complaints, investigations and audits.

  • Complaint investigations
  • Desk and onsite audits
  • Corrective Action Plans (CAPs)
  • Civil Money Penalties (CMPs)
  • Criminal referral to DOJ
PHI & ePHI

What is Protected Health Information?

PHI is any individually identifiable information relating to an individual's health status, provision of healthcare or payment for healthcare. HIPAA identifies 18 categories of identifiers that, when linked to health information, create PHI.

The 18 PHI identifiers

  • Name
  • Address (all geographic subdivisions smaller than state)
  • All elements of dates (except year) related to an individual
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health insurance beneficiary numbers
  • Account numbers
  • Certificate / license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • Internet Protocol (IP) addresses
  • Finger or voiceprints
  • Photographic images
  • Any other characteristic that could uniquely identify the individual

PHI in every form

PHI is not confined to electronic records. It exists in written documents, oral conversations and digital systems. A conversation between two clinicians discussing a patient in an elevator can constitute a violation if overheard.

Electronic PHI (ePHI) is the subset of PHI that is created, received, maintained or transmitted in electronic form. The Security Rule focuses exclusively on ePHI.

De-identified data — data stripped of all 18 identifiers — is not subject to the Privacy Rule. However, in a big-data era, re-identification risk must be carefully managed, especially when multiple datasets are combined.

State law overlays: where state laws are stricter than HIPAA — for example, on HIV status or mental health records — covered entities must comply with the more restrictive law.

Security Rule safeguards

Administrative, physical and technical safeguards.

The HIPAA Security Rule prescribes three categories of safeguards for electronic PHI. Each safeguard has required and addressable implementation specifications — organizations must implement reasonable and appropriate measures and document the rationale where a specification is not implemented.

Administrative safeguards

Policies, procedures and management actions that provide governance for ePHI protection.

  • Security Management Process (risk analysis + risk management)
  • Assigned Security Responsibility
  • Workforce Security (authorization, clearance, termination)
  • Information Access Management (least privilege)
  • Security Awareness and Training
  • Security Incident Procedures
  • Contingency Plan (backup, disaster recovery, emergency mode)
  • Evaluation and Business Associate governance

Physical safeguards

Tangible protections for facilities, hardware, workstations, devices and media that hold or access ePHI.

  • Facility Access Controls (contingency operations, security plan, validation, maintenance)
  • Workstation Use policy
  • Workstation Security
  • Device and Media Controls (disposal, reuse, accountability, backup)
  • Surveillance, biometric access, environmental protection
  • Remote-work and telehealth considerations

Technical safeguards

Technology and related policies that protect ePHI and control access to it.

  • Access Control (unique user IDs, emergency access, auto logoff, encryption)
  • Audit Controls (logging and review)
  • Integrity Controls (authentication, checksums)
  • Person or Entity Authentication (MFA, biometrics, tokens)
  • Transmission Security (TLS / SSL, integrity controls)
  • Encryption at rest and in transit
Addressable does not mean optional. Under the Security Rule, if a specification is designated "addressable," the organization must assess whether it is reasonable and appropriate. If it is, it must be implemented. If it is not, the organization must document the rationale and implement an equivalent alternative measure.
Breach Notification Rule

When a breach happens, transparency matters.

Under the Breach Notification Rule, covered entities and business associates must notify affected individuals, the Secretary of HHS and — for breaches affecting 500 or more individuals in a state or jurisdiction — the media. Notification must be made without unreasonable delay and no later than 60 days after discovery.

Risk assessment test

Before notifying, the entity assesses the probability that PHI was compromised using four factors: the nature and extent of the PHI, the unauthorized person involved, whether the PHI was actually acquired or viewed, and the extent of mitigation.

Who must be notified

Affected individuals receive written notice by first-class mail (or email with prior agreement). HHS receives notification — annually for breaches under 500 individuals, and concurrently for breaches of 500 or more. Media notice is required when 500+ individuals in a state are affected.

Business associates

Business associates must notify the covered entity following discovery of a breach. The covered entity then fulfills the notification obligations. Timelines and protocols are typically defined in the Business Associate Agreement.

Documentation is mandatory. Even breaches that do not meet the notification threshold must be documented, with the risk assessment and rationale preserved. These records are the first thing an OCR investigator will request.
Patient rights

What rights does the Privacy Rule give patients?

The Privacy Rule establishes a set of enforceable patient rights. Organizations must have practical workflows to receive, validate, fulfill and document each request within defined timeframes.

01Right to accessInspect and obtain copies of PHI, typically within 30 days.
02Right to amendRequest corrections to inaccurate or incomplete records.
03Right to an accountingObtain a list of certain disclosures of PHI.
04Right to restrictRequest restrictions on uses and disclosures in certain cases.
05Right to confidential communicationRequest communication by alternative means or locations.
06Right to a paper copyReceive a paper copy of the Notice of Privacy Practices.
07Right to revoke authorizationRevoke previously granted authorizations in writing.
08Right to file a complaintFile a complaint with the covered entity or with HHS OCR.
Enforcement & penalties

What happens when HIPAA is violated?

The HHS Office for Civil Rights (OCR) enforces HIPAA through complaint investigations, compliance reviews and proactive audits. Consequences range from voluntary compliance to Civil Money Penalties and — in cases of willful neglect or intentional misconduct — criminal referral to the Department of Justice.

TierCulpabilityPer-violation rangeAnnual maximum
Tier 1Lack of knowledge (could not have realistically avoided with reasonable diligence)$100 – $50,000$1.5M
Tier 2Reasonable cause, not willful neglect$1,000 – $50,000$1.5M
Tier 3Willful neglect — corrected within 30 days$10,000 – $50,000$1.5M
Tier 4Willful neglect — not corrected$50,000$1.5M

Complaints & investigations

Individuals can file complaints with OCR within 180 days of an alleged violation. OCR reviews jurisdiction, opens an investigation, requests documentation and may conduct interviews or onsite visits.

Corrective Action Plans

A CAP is a binding agreement that specifies actions, timelines, staff training and periodic reporting to OCR — often spanning one to three years. Failure to comply can trigger Civil Money Penalties.

Criminal penalties

OCR can refer cases involving intentional misconduct to the DOJ. Criminal penalties may include fines and imprisonment depending on the nature of the offense.

Lessons from enforcement

What OCR enforcement cases teach us.

Across HIPAA enforcement actions, a consistent set of failure patterns emerges. Understanding them is the fastest way to strengthen a compliance program.

Risk analysis is missing

Many enforcement actions cite inadequate or outdated risk analysis. Risk analysis is not a one-time event — it must be revisited with business, technology and workforce changes.

Training is undocumented

Human error remains a leading cause of breaches. Documented, role-appropriate, refreshed workforce training is the strongest preventive control available.

Devices and remote work

Lost or stolen unencrypted laptops and mobile devices are common breach sources. Encryption, device management and remote access policies are essential.

Breach notification delays

Late or missing breach notifications are heavily penalized. Documented incident response with clear escalation and notification workflows is critical.

Weak BAAs

Missing or inadequate Business Associate Agreements leave covered entities liable for vendor failures. Due diligence and ongoing oversight are required.

No small-entity exemption

OCR has repeatedly fined small practices, clinics and individual providers. Every covered entity and business associate is expected to comply, regardless of size.

CyberAtrix HIPAA Services

From gap assessment to auditable compliance evidence.

CyberAtrix delivers HIPAA consulting across every part of the program — governance, risk, safeguards, business associates, breach readiness and audit preparation.

HIPAA gap assessment

Assess current practices against the Privacy, Security and Breach Notification Rules and produce a prioritized remediation roadmap.

Risk analysis & management

Identify where ePHI is created, received, maintained and transmitted. Assess threats, vulnerabilities, likelihood and impact. Document decisions.

Policies & procedures

Develop the administrative, physical and technical safeguard documentation HIPAA expects — including sanctions, contingency, incident response and device management.

BAA governance

Review, draft and negotiate Business Associate Agreements. Establish due diligence, sub-processor oversight and ongoing vendor assurance.

Workforce training

Role-appropriate training for clinical, administrative, IT, HR and leadership teams. Documented attendance, content and assessments.

Breach readiness

Build the incident response and breach assessment workflows — evidence preservation, risk assessment, individual notice, HHS reporting and, where required, media notice.

OCR audit preparation

Prepare documentation, evidence and interview readiness for desk reviews, onsite audits and potential investigations.

Integrated GRC mapping

Map HIPAA requirements to ISO 27001, ISO 27701, SOC 2 and NIST controls so a single program supports multiple obligations.

HIPAA implementation roadmap

An eight-stage path to a defensible HIPAA program.

A practical sequence for organizations starting a HIPAA program or maturing an existing one. The order matters — risk analysis is the foundation everything else is built upon.

01

Scope & applicability

Determine whether you are a covered entity or business associate, which locations, systems and workforce members fall within scope, and which PHI or ePHI you handle.

02

Risk analysis

Identify where PHI and ePHI are stored, processed and transmitted. Identify threats, vulnerabilities, likelihood and impact. Document the analysis — this is the most frequently cited gap in OCR enforcement.

03

Risk management

Choose reasonable and appropriate safeguards to reduce identified risks to a reasonable and acceptable level. Document the decisions, including rationale for addressable specifications.

04

Policies & procedures

Develop administrative, physical and technical safeguards as documented policies and procedures — sanctions, contingency, incident response, device management, access control and others.

05

Business Associate governance

Execute BAAs with every relevant vendor and subcontractor. Conduct due diligence, review safeguards and maintain ongoing oversight.

06

Workforce training & awareness

Train all workforce members on the policies and procedures relevant to their role. Document attendance, content and assessments. Refresh periodically.

07

Breach readiness & notification

Define incident response and breach assessment processes. Build notification workflows for individuals, HHS and — where required — the media. Rehearse the plan.

08

Monitor, audit & improve

Run regular internal audits, review logs, revisit risk analysis after change, close corrective actions and keep evidence current and organized.

HIPAA in a digital age

Telehealth, cloud, mHealth and big data — same rules, new risk.

Digital transformation has not changed the core of HIPAA — protect PHI and respect patient rights — but it has transformed where PHI lives and how it flows.

TELEHEALTH

Secure remote care

Telehealth platforms must use end-to-end encryption, role-based access and auditable logs. A BAA is required with platform providers handling ePHI. Patients should be educated about their own environment and network security.

CLOUD

Business associate model

Cloud service providers that store, process or transmit PHI are business associates. Requirements include BAAs, encryption at rest and in transit, access controls, audit trails, backup and physical data-center security.

MOBILE HEALTH

mHealth apps

When an mHealth app handles PHI on behalf of a covered entity, HIPAA applies. Requirements include encryption, strong authentication, access controls, integrity controls and secure transmission.

BIG DATA

Analytics & re-identification

De-identified datasets are useful for research, but re-identification risk grows when datasets are combined. Robust de-identification techniques, privacy-by-design and purpose limitation reduce risk.

IoT

Connected devices

Connected medical devices and wearables expand the attack surface. Device management, network segmentation and security assessments are essential parts of a modern HIPAA program.

AI

Algorithmic privacy

AI and machine learning introduce questions about training data, model governance, algorithmic bias and re-identification risk. HIPAA principles — data minimization, purpose limitation and accountability — remain the guide.

Integrated compliance

HIPAA does not live alone.

Most organizations face multiple frameworks — HIPAA, ISO 27001, GDPR, SOC 2 and PCI DSS. A well-designed governance program shares controls and evidence across obligations, reducing duplication and improving assurance.

HIPAA + ISO 27001

ISO 27001's ISMS provides the management-system backbone. HIPAA safeguards map cleanly to ISO 27002 controls for access, cryptography, supplier relationships, incident management and business continuity.

HIPAA + GDPR

Both protect personal data but from different angles. GDPR focuses on European data subjects; HIPAA focuses on U.S. health information. Organizations handling both can share governance, records, DPIAs and incident response processes.

HIPAA + SOC 2

SOC 2 Trust Services Criteria overlap with HIPAA Security Rule safeguards on access, change management, monitoring and vendor oversight. Shared evidence reduces audit fatigue.

CyberAtrix methodology

Discover. Assess. Remediate. Demonstrate.

Our HIPAA engagements follow a practical operating model that leadership, legal, compliance, security, IT and clinical teams can actually execute together.

01
DiscoverScope, PHI / ePHI inventory, systems, workforce, vendors.
02
AssessRisk analysis, gap assessment, policy and evidence review.
03
RemediateSafeguards, BAAs, training, incident and breach workflows.
04
DemonstrateEvidence, internal audit, corrective action, continuous improvement.
E-E-A-T · Author

Who reviews this content

This page is reviewed by CyberAtrix leadership and grounded in the primary texts of the HIPAA Privacy, Security and Breach Notification Rules.

Rakesh H Kotian

Chief Executive Officer, CyberAtrix

ISO 27001 Lead Auditor (LA) • ISO 27001 Lead Implementer (LI) · GRC, privacy and healthcare-compliance engagements across multiple sectors.

Reviewed & updated: 22 September 2026
FAQ

HIPAA questions, answered.

Common questions from healthcare providers, payers, business associates and technology vendors.

What is HIPAA?

HIPAA is the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law that protects the confidentiality, integrity and availability of Protected Health Information. HIPAA is built on three pillars: the Privacy Rule, the Security Rule and the Breach Notification Rule, plus administrative simplification provisions.

Who has to comply with HIPAA?

HIPAA applies to covered entities — healthcare providers, health plans and healthcare clearinghouses that transmit health information electronically — and to their business associates: vendors and subcontractors that create, receive, maintain or transmit PHI on their behalf.

What is Protected Health Information (PHI)?

PHI is any individually identifiable information relating to health status, provision of healthcare or payment for healthcare. HIPAA identifies 18 categories of identifiers — including name, address, dates, telephone numbers, email addresses, Social Security numbers, medical record numbers, account numbers, device identifiers, web URLs, IP addresses, biometric identifiers and photographic images — that when linked to health information create PHI.

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule applies to PHI in all forms — written, oral and electronic — and governs when PHI may be used or disclosed. The Security Rule focuses exclusively on electronic PHI (ePHI) and prescribes administrative, physical and technical safeguards to protect its confidentiality, integrity and availability.

What is the Breach Notification Rule?

The Breach Notification Rule requires covered entities and business associates to notify affected individuals, the Secretary of Health and Human Services and — for breaches affecting 500 or more individuals in a state or jurisdiction — the media. Notification must be made without unreasonable delay and no later than 60 days after discovery.

What is a Business Associate Agreement (BAA)?

A Business Associate Agreement is a legally binding contract that outlines how a business associate will safeguard Protected Health Information when performing services for or on behalf of a covered entity. BAAs are required by HIPAA and describe permitted uses, disclosures, safeguards and reporting obligations.

What are the HIPAA administrative, physical and technical safeguards?

Administrative safeguards are policies and procedures such as risk analysis, workforce security, training and incident procedures. Physical safeguards cover facility access, workstation use and device and media controls. Technical safeguards include access control, audit controls, integrity controls, person or entity authentication and transmission security.

How much can a HIPAA violation cost?

Civil money penalties under HIPAA are tiered by culpability, ranging from $100 to $50,000 per violation, with a maximum annual penalty of $1.5 million for identical provisions. Criminal penalties can apply in cases of intentional misconduct and may include imprisonment.

Does HIPAA apply to telehealth, cloud services and mobile health apps?

HIPAA can apply to telehealth platforms, cloud service providers and mobile health apps when they create, receive, maintain or transmit ePHI on behalf of a covered entity or business associate. Cloud providers and many technology vendors act as business associates and require a BAA.

Does every organization need a HIPAA compliance officer?

HIPAA requires covered entities and business associates to designate a privacy official and a security official responsible for developing and implementing policies and procedures. The role may be combined with other responsibilities in smaller organizations, but the designation is required.

How often should a HIPAA risk analysis be performed?

Risk analysis under the Security Rule is not a one-time activity. It should be reviewed regularly — at least annually — and revisited whenever there are significant changes to business, technology, systems, workforce or threats.

Does HIPAA require encryption?

Encryption and decryption are addressable implementation specifications under the Security Rule, not mandatory absolute requirements. However, if an organization determines that encryption is not reasonable and appropriate, it must document the rationale and implement an equivalent alternative measure.

How does HIPAA relate to ISO 27001 and other frameworks?

HIPAA is a U.S. regulation; ISO 27001 is an international certifiable management-system standard. Many organizations map HIPAA requirements against ISO 27001, ISO 27701, SOC 2 and NIST controls to reduce duplication and build one integrated compliance program.

What happens during an OCR audit?

The HHS Office for Civil Rights can investigate complaints, conduct compliance reviews and perform audits. Audits may start as desk reviews and escalate to onsite reviews with interviews. If violations are found, OCR may seek voluntary compliance, a Corrective Action Plan or Civil Money Penalties.

Start with clarity

Know where your HIPAA program stands.

Get a scoped HIPAA assessment and a practical roadmap for privacy governance, risk analysis, safeguards, Business Associate governance, breach readiness and OCR audit preparation.

Talk to a HIPAA Specialist