Data protection
Health Insurance Portability and Accountability Act
Published Reviewed
What is HIPAA?
HIPAA sets United States privacy, security and breach-notification duties for covered entities and business associates that create, receive, maintain or transmit protected health information.
| Jurisdiction | United States |
|---|---|
| Authority | HIPAA and 45 CFR Parts 160 and 164 |
| Current status | Rules have different effective dates; verify current HHS rules |
| Reviewed |
Why it matters operationally
HIPAA reaches further than US healthcare providers: any company anywhere that handles protected health information for a US covered entity — a SaaS vendor, an analytics firm, a support contractor — becomes a business associate with direct regulatory exposure and a mandatory contract behind it. Enforcement runs on tiered civil penalties adjusted annually, reaching seven figures per violation category per year, plus state attorney-general actions. And HHS has proposed the Security Rule’s biggest overhaul in twenty years.
Are you aware?
The dates that bind
The breach-notification outer limit
Breaches of unsecured PHI must be notified to affected individuals without unreasonable delay and no later than 60 days after discovery; breaches affecting 500+ people also go to HHS and the media on the same clock.
The Security Rule overhaul proposal
The HHS proposal published in early 2025 would make encryption and multi-factor authentication mandatory, require asset inventories and network maps, and remove the "addressable" flexibility that many programmes leaned on. Final timing is open — the direction is not.
The risk analysis is a standing duty
The Security Rule requires an accurate, thorough risk analysis kept current — it is the first document OCR requests in almost every investigation, and its absence is the most common finding.
Where to start
- 1
Determine your status for each data flow: covered entity, business associate, or neither — and put business associate agreements behind every PHI relationship.
- 2
Run and date the security risk analysis across all systems holding electronic PHI, and track remediation from it.
- 3
Rehearse the breach path: discovery, assessment, the 60-day clock, and the 500-record threshold that adds HHS and media notification.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
We are not a US company — can HIPAA still apply?
Yes, through the business-associate route: if you create, receive, maintain or transmit PHI for a US covered entity, HIPAA’s Security and Breach rules apply to you directly and a business associate agreement is mandatory — wherever you are based.
What counts as protected health information?
Individually identifiable health information held or transmitted by a covered entity or business associate, in any form — including identifiers such as names, dates, device identifiers and IP addresses when linked to health data. De-identification has two defined routes: safe harbor (removing 18 identifiers) or expert determination.
How do penalties actually work?
Four culpability tiers from "did not know" to "wilful neglect, uncorrected", with per-violation amounts adjusted annually and per-category annual caps in the seven figures. Criminal exposure exists for knowing misuse, and state attorneys general can sue in parallel.
A quick self-check
Are you ready?
- Could you produce a current, dated security risk analysis today?
- Is there a signed business associate agreement behind every vendor that touches PHI?
- If a laptop with PHI disappeared this afternoon, who decides whether the 60-day clock starts — and how fast?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.