What It Is

HIPAA compliance is built around four key rules, published by the HHS Office for Civil Rights:

  • Privacy Rule: defines how PHI may be used and disclosed, and establishes patient rights.
  • Security Rule: requires administrative, physical, and technical safeguards to protect electronic PHI (45 CFR Part 164, Subpart C).
  • Breach Notification Rule: mandates notification to affected individuals, HHS, and sometimes the media after certain breaches. The media requirement applies when a breach affects more than 500 residents of a state or jurisdiction.
  • Enforcement Rule: defines penalties and enforcement mechanisms.

From a practical standpoint, the Security Rule drives most of the IT and cybersecurity work.

One status note worth knowing: HHS published a proposed update to the Security Rule on December 27, 2024. It would strengthen cybersecurity requirements, but it has not been finalized. The current rule remains in effect, and this page reflects it.

What Information Is Regulated

HIPAA regulates protected health information (PHI): any health-related data that can identify an individual. That includes:

  • Names, addresses, and dates of birth
  • Medical records and diagnoses
  • Treatment and prescription data
  • Insurance and billing information
  • Patient portal credentials
  • Appointment and communication records
  • Any combination of data that identifies a patient

When PHI is stored or transmitted electronically, it becomes ePHI. That is where IT and cybersecurity controls become critical.

IT Requirements

HIPAA does not prescribe specific tools. It requires reasonable and appropriate safeguards based on risk, organized into three categories under the Security Rule.

Administrative safeguards:

  • Risk analysis and risk management: explicitly required at 45 CFR 164.308(a)(1). This is the foundation everything else stands on.
  • Security policies and procedures: documented and current.
  • Workforce training: everyone who touches PHI.
  • Incident response and breach handling processes: defined before you need them.
  • Vendor management and Business Associate Agreements (BAAs): required for every vendor touching PHI.

Technical safeguards:

  • Unique user identification: required - no shared accounts (45 CFR 164.312(a)).
  • Access controls and least privilege: limit access to the minimum necessary.
  • Person or entity authentication: the rule requires you to verify that a person seeking access to ePHI is who they claim to be, without prescribing the method. Multi-factor authentication is the best practice for meeting it - and it is a named requirement in the pending Security Rule proposal, so building it now is building ahead of the rule.
  • Encryption at rest and in transit: an addressable specification (45 CFR 164.312(a)(2)(iv) and (e)(2)(ii)). Addressable does not mean optional - you implement it if reasonable and appropriate, or document why not and implement an equivalent alternative. In practice, encryption is almost always the answer, and it triggers the breach-notification safe harbor.
  • Audit logs and monitoring: you must be able to show who accessed what.
  • Secure remote access: every remote path into PHI is in scope.

Physical safeguards:

  • Device and media controls: track where PHI-bearing hardware lives and goes.
  • Secure workstation and server access: physical access is access.
  • Secure disposal: of hardware and data both.

HIPAA compliance fails most often when technical safeguards are weak or undocumented.

How It Fits Into Cyber Risk Management

HIPAA aligns closely with widely used frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001, SOC 2, and HITRUST CSF.

That means HIPAA compliance is largely built on the same cybersecurity fundamentals used across industries. The difference is the sensitivity of the data and the documentation required.

How We Help With HIPAA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates your environment against HIPAA's Security Rule safeguards - administrative, physical, and technical - and documents the risk analysis the rule explicitly requires.

How to Prepare

  1. Identify where PHI exists

    Document the systems that store or process PHI, the data flows between them, who has access, and which vendors and third parties are involved. You can't secure PHI you don't know about.

  2. Conduct a risk assessment

    HIPAA explicitly requires a risk analysis (45 CFR 164.308(a)(1)). Identify threats and vulnerabilities, evaluate likelihood and impact, and document mitigation steps. A missing risk analysis is a recurring finding in OCR enforcement actions.

  3. Implement or strengthen core security controls

    At minimum: MFA for systems handling PHI (best practice today, proposed as a requirement in the pending Security Rule update), encryption of data and backups, endpoint and email security, logging and monitoring, secure remote access, and regular patching.

  4. Formalize policies and procedures

    HIPAA expects documented security policies, incident response plans, backup and disaster recovery procedures, and access management processes. Policies must reflect how systems actually work, not theoretical controls.

  5. Manage vendor and third-party risk

    Ensure Business Associate Agreements are in place, vendors meet security expectations, and ongoing oversight exists. You remain responsible for PHI - even when vendors are involved.

  6. Train your workforce

    Employees should understand how PHI is handled, security best practices, how to recognize and report incidents, and their role in protecting patient data. Human error remains a top cause of HIPAA incidents.

HIPAA in Florida

HIPAA is the floor in Florida, not the ceiling. The Florida Information Protection Act (F.S. 501.171) adds a state breach-notification layer on top of HIPAA - and its definition of personal information expressly includes medical history, condition, treatment, and diagnosis information, plus health insurance policy numbers.

What the statute requires:

  • Reasonable security measures: every covered business must take reasonable measures to protect and secure electronic data containing personal information (F.S. 501.171(2)).
  • Individual notice within 30 days: affected individuals must be notified without unreasonable delay, and no later than 30 days after a breach is determined (F.S. 501.171(4)).
  • State notice at 500 records: a breach affecting 500 or more individuals in Florida must be reported to the Florida Department of Legal Affairs within 30 days, with a 15-day extension available for good cause (F.S. 501.171(3)).
  • Credit bureaus at 1,000: a breach affecting more than 1,000 individuals requires notice to the nationwide consumer reporting agencies.
  • Encryption matters here too: data that is encrypted or otherwise stripped of identifying elements falls outside the statute's notification trigger.
  • Late notice carries penalties: up to $1,000 per day for the first 30 days of violation, then up to $50,000 per subsequent 30-day period, capped at $500,000 (F.S. 501.171(9)).

Note the clock: HIPAA's Breach Notification Rule allows up to 60 days for individual notice. Florida allows 30. A Florida practice plans to the stricter deadline.

On the Treasure Coast, this is not an abstract concern - hospital systems, independent practices, specialty clinics, and treatment centers across Martin, St. Lucie, and Palm Beach counties handle PHI every day, and every one of them carries both the federal and the Florida obligations.

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25