The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that governs how protected health information (PHI) is handled, stored, and protected.
HIPAA is often misunderstood as a healthcare-only regulation. In reality, it reaches a wide range of organizations - many of which don't consider themselves "healthcare companies" at all.
At its core, HIPAA exists to keep sensitive health information confidential, available when needed, and protected from unauthorized access or disclosure. Achieving that depends heavily on IT systems, cybersecurity controls, and operational discipline.
HIPAA compliance is built around four key rules, published by the HHS Office for Civil Rights:
From a practical standpoint, the Security Rule drives most of the IT and cybersecurity work.
One status note worth knowing: HHS published a proposed update to the Security Rule on December 27, 2024. It would strengthen cybersecurity requirements, but it has not been finalized. The current rule remains in effect, and this page reflects it.
HIPAA applies to two main groups.
Covered entities:
Business associates: any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity, including:
If you touch PHI in any way, HIPAA likely applies to you - even if healthcare is not your primary business.
HIPAA regulates protected health information (PHI): any health-related data that can identify an individual. That includes:
When PHI is stored or transmitted electronically, it becomes ePHI. That is where IT and cybersecurity controls become critical.
HIPAA is the base layer of U.S. healthcare compliance. Several other requirements build on it:
Being HIPAA compliant does not satisfy these on its own - and using certified or compliant vendors does not make you compliant either.
HIPAA does not prescribe specific tools. It requires reasonable and appropriate safeguards based on risk, organized into three categories under the Security Rule.
Administrative safeguards:
Technical safeguards:
Physical safeguards:
HIPAA compliance fails most often when technical safeguards are weak or undocumented.
Many organizations think HIPAA is about avoiding fines. In reality, HIPAA failures often lead to:
OCR enforcement increasingly focuses on whether organizations took reasonable steps to protect ePHI - not whether an attack was sophisticated. A missing or undocumented risk analysis is a recurring finding in OCR enforcement actions.
HIPAA aligns closely with widely used frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001, SOC 2, and HITRUST CSF.
That means HIPAA compliance is largely built on the same cybersecurity fundamentals used across industries. The difference is the sensitivity of the data and the documentation required.
Here's the truth most organizations don't hear: most HIPAA requirements are basic cybersecurity best practices.
MFA is MFA. Encryption is encryption. Logging is logging.
HIPAA doesn't demand cutting-edge technology. It demands discipline, consistency, and proof that reasonable safeguards are in place.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment evaluates your environment against HIPAA's Security Rule safeguards - administrative, physical, and technical - and documents the risk analysis the rule explicitly requires.
Document the systems that store or process PHI, the data flows between them, who has access, and which vendors and third parties are involved. You can't secure PHI you don't know about.
HIPAA explicitly requires a risk analysis (45 CFR 164.308(a)(1)). Identify threats and vulnerabilities, evaluate likelihood and impact, and document mitigation steps. A missing risk analysis is a recurring finding in OCR enforcement actions.
At minimum: MFA for systems handling PHI (best practice today, proposed as a requirement in the pending Security Rule update), encryption of data and backups, endpoint and email security, logging and monitoring, secure remote access, and regular patching.
HIPAA expects documented security policies, incident response plans, backup and disaster recovery procedures, and access management processes. Policies must reflect how systems actually work, not theoretical controls.
Ensure Business Associate Agreements are in place, vendors meet security expectations, and ongoing oversight exists. You remain responsible for PHI - even when vendors are involved.
Employees should understand how PHI is handled, security best practices, how to recognize and report incidents, and their role in protecting patient data. Human error remains a top cause of HIPAA incidents.
If you're a healthcare provider, health plan, or clearinghouse, yes. If you create, receive, maintain, or transmit PHI on behalf of one - as an IT provider, billing service, SaaS vendor, or consultant - you're a business associate, and HIPAA applies directly to you. If you touch PHI in any way, assume it applies until you've confirmed otherwise.
OCR can impose civil penalties in tiers based on culpability, and criminal penalties exist for knowing violations. The practical consequences arrive faster: breaches, downtime, insurance complications, and lost patient trust. Enforcement focuses on whether you took reasonable, documented steps - not on whether the attack was sophisticated.
It depends on your starting point. The assessment that shows you exactly where you stand typically runs 2 to 4 weeks. Remediation is then prioritized by risk - some gaps close in days, others become planned projects. HIPAA is an ongoing risk management process, not a one-time project.
It depends on the size of your environment and the gaps we find - which is exactly what the assessment establishes. You get a firm quote after the assessment; the conversation costs nothing.
Probably - most IT providers manage technology, not compliance evidence. HIPAA requires a documented risk analysis, policies, training records, and BAAs that day-to-day IT rarely produces. Our co-managed approach adds that layer alongside your existing provider without replacing anyone.
HIPAA defines the rules for protecting health information. HITECH enforces them harder - it raised penalties, extended direct liability to business associates, and expanded breach notification. If HIPAA applies to you, HITECH does too.
Some organizations can, with the right internal discipline. The parts that trip up DIY efforts are the formal risk analysis, defensible documentation, and keeping it all current. Our DIY-with-support tier exists for exactly this: you manage, we provide the executive decision support.
Start by finding out where you actually stand. Our Cyber Risk & Compliance Gap Assessment maps your PHI exposure, evaluates your safeguards against the Security Rule, and gives you a prioritized roadmap. No pressure. No jargon. Just clear insights and your best next steps.
HIPAA is the floor in Florida, not the ceiling. The Florida Information Protection Act (F.S. 501.171) adds a state breach-notification layer on top of HIPAA - and its definition of personal information expressly includes medical history, condition, treatment, and diagnosis information, plus health insurance policy numbers.
What the statute requires:
Note the clock: HIPAA's Breach Notification Rule allows up to 60 days for individual notice. Florida allows 30. A Florida practice plans to the stricter deadline.
On the Treasure Coast, this is not an abstract concern - hospital systems, independent practices, specialty clinics, and treatment centers across Martin, St. Lucie, and Palm Beach counties handle PHI every day, and every one of them carries both the federal and the Florida obligations.
Official source: HHS Office for Civil Rights
Secondary source: eCFR - 45 CFR Part 164
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25