Data protection

Health Insurance Portability and Accountability Act

HIPAA and 45 CFR Parts 160 and 164 United States Rules have different effective dates; verify current HHS rules

Published Reviewed

What is HIPAA?

HIPAA sets United States privacy, security and breach-notification duties for covered entities and business associates that create, receive, maintain or transmit protected health information.

At a glance
JurisdictionUnited States
AuthorityHIPAA and 45 CFR Parts 160 and 164
Current statusRules have different effective dates; verify current HHS rules
Reviewed

Why it matters operationally

HIPAA reaches further than US healthcare providers: any company anywhere that handles protected health information for a US covered entity — a SaaS vendor, an analytics firm, a support contractor — becomes a business associate with direct regulatory exposure and a mandatory contract behind it. Enforcement runs on tiered civil penalties adjusted annually, reaching seven figures per violation category per year, plus state attorney-general actions. And HHS has proposed the Security Rule’s biggest overhaul in twenty years.

Are you aware?

The dates that bind

60 days

The breach-notification outer limit

Breaches of unsecured PHI must be notified to affected individuals without unreasonable delay and no later than 60 days after discovery; breaches affecting 500+ people also go to HHS and the media on the same clock.

Proposed

The Security Rule overhaul proposal

The HHS proposal published in early 2025 would make encryption and multi-factor authentication mandatory, require asset inventories and network maps, and remove the "addressable" flexibility that many programmes leaned on. Final timing is open — the direction is not.

Annual

The risk analysis is a standing duty

The Security Rule requires an accurate, thorough risk analysis kept current — it is the first document OCR requests in almost every investigation, and its absence is the most common finding.

Where to start

  1. 1

    Determine your status for each data flow: covered entity, business associate, or neither — and put business associate agreements behind every PHI relationship.

  2. 2

    Run and date the security risk analysis across all systems holding electronic PHI, and track remediation from it.

  3. 3

    Rehearse the breach path: discovery, assessment, the 60-day clock, and the 500-record threshold that adds HHS and media notification.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

We are not a US company — can HIPAA still apply?

Yes, through the business-associate route: if you create, receive, maintain or transmit PHI for a US covered entity, HIPAA’s Security and Breach rules apply to you directly and a business associate agreement is mandatory — wherever you are based.

What counts as protected health information?

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form — including identifiers such as names, dates, device identifiers and IP addresses when linked to health data. De-identification has two defined routes: safe harbor (removing 18 identifiers) or expert determination.

How do penalties actually work?

Four culpability tiers from "did not know" to "wilful neglect, uncorrected", with per-violation amounts adjusted annually and per-category annual caps in the seven figures. Criminal exposure exists for knowing misuse, and state attorneys general can sue in parallel.

A quick self-check

Are you ready?

  • Could you produce a current, dated security risk analysis today?
  • Is there a signed business associate agreement behind every vendor that touches PHI?
  • If a laptop with PHI disappeared this afternoon, who decides whether the 60-day clock starts — and how fast?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.