Status: A proposed update to the HIPAA Security Rule was published December 27, 2024 and is not yet final. The current rule remains in effect; this page reflects it.

What Is HIPAA and Why It Matters

The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that governs how protected health information (PHI) is handled, stored, and protected.

HIPAA is often misunderstood as a healthcare-only regulation. In reality, it reaches a wide range of organizations - many of which don't consider themselves "healthcare companies" at all.

At its core, HIPAA exists to keep sensitive health information confidential, available when needed, and protected from unauthorized access or disclosure. Achieving that depends heavily on IT systems, cybersecurity controls, and operational discipline.

What It Is

HIPAA compliance is built around four key rules, published by the HHS Office for Civil Rights:

  • Privacy Rule: defines how PHI may be used and disclosed, and establishes patient rights.
  • Security Rule: requires administrative, physical, and technical safeguards to protect electronic PHI (45 CFR Part 164, Subpart C).
  • Breach Notification Rule: mandates notification to affected individuals, HHS, and sometimes the media after certain breaches. The media requirement applies when a breach affects more than 500 residents of a state or jurisdiction.
  • Enforcement Rule: defines penalties and enforcement mechanisms.

From a practical standpoint, the Security Rule drives most of the IT and cybersecurity work.

One status note worth knowing: HHS published a proposed update to the Security Rule on December 27, 2024. It would strengthen cybersecurity requirements, but it has not been finalized. The current rule remains in effect, and this page reflects it.

Who It Applies To

HIPAA applies to two main groups.

Covered entities:

  • Healthcare providers: clinics, hospitals, and practices - but only if they transmit health information electronically in connection with a transaction for which HHS has adopted a standard. Nearly all modern providers do.
  • Health plans: insurers and HMOs.
  • Healthcare clearinghouses: entities that process health information between standard and nonstandard formats.

Business associates: any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity, including:

  • MSPs and IT providers: anyone managing systems that touch PHI.
  • Cloud and SaaS vendors: hosting or processing counts, even without viewing the data.
  • Billing and claims processors: payment workflows run on PHI.
  • EHR vendors and data analytics providers: the systems of record themselves.
  • Managed security providers, consultants, and professional services firms: access is enough.

If you touch PHI in any way, HIPAA likely applies to you - even if healthcare is not your primary business.

What Information Is Regulated

HIPAA regulates protected health information (PHI): any health-related data that can identify an individual. That includes:

  • Names, addresses, and dates of birth
  • Medical records and diagnoses
  • Treatment and prescription data
  • Insurance and billing information
  • Patient portal credentials
  • Appointment and communication records
  • Any combination of data that identifies a patient

When PHI is stored or transmitted electronically, it becomes ePHI. That is where IT and cybersecurity controls become critical.

Relation to Other Frameworks

HIPAA is the base layer of U.S. healthcare compliance. Several other requirements build on it:

  • HITECH strengthens HIPAA's enforcement, extends direct liability to business associates, and expands breach notification.
  • 42 CFR Part 2 adds stricter confidentiality rules for substance use disorder treatment records.
  • ONC Health IT Certification verifies that EHR technology supports the security capabilities HIPAA expects you to operate.
  • HITRUST CSF is a certifiable framework that maps HIPAA's requirements alongside dozens of other standards.

Being HIPAA compliant does not satisfy these on its own - and using certified or compliant vendors does not make you compliant either.

IT Requirements

HIPAA does not prescribe specific tools. It requires reasonable and appropriate safeguards based on risk, organized into three categories under the Security Rule.

Administrative safeguards:

  • Risk analysis and risk management: explicitly required at 45 CFR 164.308(a)(1). This is the foundation everything else stands on.
  • Security policies and procedures: documented and current.
  • Workforce training: everyone who touches PHI.
  • Incident response and breach handling processes: defined before you need them.
  • Vendor management and Business Associate Agreements (BAAs): required for every vendor touching PHI.

Technical safeguards:

  • Unique user identification: required - no shared accounts (45 CFR 164.312(a)).
  • Access controls and least privilege: limit access to the minimum necessary.
  • Person or entity authentication: the rule requires you to verify that a person seeking access to ePHI is who they claim to be, without prescribing the method. Multi-factor authentication is the best practice for meeting it - and it is a named requirement in the pending Security Rule proposal, so building it now is building ahead of the rule.
  • Encryption at rest and in transit: an addressable specification (45 CFR 164.312(a)(2)(iv) and (e)(2)(ii)). Addressable does not mean optional - you implement it if reasonable and appropriate, or document why not and implement an equivalent alternative. In practice, encryption is almost always the answer, and it triggers the breach-notification safe harbor.
  • Audit logs and monitoring: you must be able to show who accessed what.
  • Secure remote access: every remote path into PHI is in scope.

Physical safeguards:

  • Device and media controls: track where PHI-bearing hardware lives and goes.
  • Secure workstation and server access: physical access is access.
  • Secure disposal: of hardware and data both.

HIPAA compliance fails most often when technical safeguards are weak or undocumented.

Why It Matters

Many organizations think HIPAA is about avoiding fines. In reality, HIPAA failures often lead to:

  • Data breaches and ransomware incidents: the same gaps that fail an audit invite an attacker.
  • Operational downtime: a breached practice can't see patients.
  • Reputational damage and lost trust: patients and partners both.
  • Insurance complications: carriers scrutinize whether required safeguards were actually in place.

OCR enforcement increasingly focuses on whether organizations took reasonable steps to protect ePHI - not whether an attack was sophisticated. A missing or undocumented risk analysis is a recurring finding in OCR enforcement actions.

How It Fits Into Cyber Risk Management

HIPAA aligns closely with widely used frameworks such as the NIST Cybersecurity Framework, NIST SP 800-53, ISO/IEC 27001, SOC 2, and HITRUST CSF.

That means HIPAA compliance is largely built on the same cybersecurity fundamentals used across industries. The difference is the sensitivity of the data and the documentation required.

How We Help With HIPAA Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates your environment against HIPAA's Security Rule safeguards - administrative, physical, and technical - and documents the risk analysis the rule explicitly requires.

How to Prepare

  1. 01Identify where PHI exists

    Document the systems that store or process PHI, the data flows between them, who has access, and which vendors and third parties are involved. You can't secure PHI you don't know about.

  2. 02Conduct a risk assessment

    HIPAA explicitly requires a risk analysis (45 CFR 164.308(a)(1)). Identify threats and vulnerabilities, evaluate likelihood and impact, and document mitigation steps. A missing risk analysis is a recurring finding in OCR enforcement actions.

  3. 03Implement or strengthen core security controls

    At minimum: MFA for systems handling PHI (best practice today, proposed as a requirement in the pending Security Rule update), encryption of data and backups, endpoint and email security, logging and monitoring, secure remote access, and regular patching.

  4. 04Formalize policies and procedures

    HIPAA expects documented security policies, incident response plans, backup and disaster recovery procedures, and access management processes. Policies must reflect how systems actually work, not theoretical controls.

  5. 05Manage vendor and third-party risk

    Ensure Business Associate Agreements are in place, vendors meet security expectations, and ongoing oversight exists. You remain responsible for PHI - even when vendors are involved.

  6. 06Train your workforce

    Employees should understand how PHI is handled, security best practices, how to recognize and report incidents, and their role in protecting patient data. Human error remains a top cause of HIPAA incidents.

Frequently Asked Questions

Does HIPAA apply to my business?

If you're a healthcare provider, health plan, or clearinghouse, yes. If you create, receive, maintain, or transmit PHI on behalf of one - as an IT provider, billing service, SaaS vendor, or consultant - you're a business associate, and HIPAA applies directly to you. If you touch PHI in any way, assume it applies until you've confirmed otherwise.

What happens if we're not compliant with HIPAA?

OCR can impose civil penalties in tiers based on culpability, and criminal penalties exist for knowing violations. The practical consequences arrive faster: breaches, downtime, insurance complications, and lost patient trust. Enforcement focuses on whether you took reasonable, documented steps - not on whether the attack was sophisticated.

How long does it take to become HIPAA compliant?

It depends on your starting point. The assessment that shows you exactly where you stand typically runs 2 to 4 weeks. Remediation is then prioritized by risk - some gaps close in days, others become planned projects. HIPAA is an ongoing risk management process, not a one-time project.

What does HIPAA compliance cost?

It depends on the size of your environment and the gaps we find - which is exactly what the assessment establishes. You get a firm quote after the assessment; the conversation costs nothing.

We already have an IT provider. Do we still need this?

Probably - most IT providers manage technology, not compliance evidence. HIPAA requires a documented risk analysis, policies, training records, and BAAs that day-to-day IT rarely produces. Our co-managed approach adds that layer alongside your existing provider without replacing anyone.

What's the difference between HIPAA and HITECH?

HIPAA defines the rules for protecting health information. HITECH enforces them harder - it raised penalties, extended direct liability to business associates, and expanded breach notification. If HIPAA applies to you, HITECH does too.

Can we handle HIPAA compliance ourselves?

Some organizations can, with the right internal discipline. The parts that trip up DIY efforts are the formal risk analysis, defensible documentation, and keeping it all current. Our DIY-with-support tier exists for exactly this: you manage, we provide the executive decision support.

Where do we start?

Start by finding out where you actually stand. Our Cyber Risk & Compliance Gap Assessment maps your PHI exposure, evaluates your safeguards against the Security Rule, and gives you a prioritized roadmap. No pressure. No jargon. Just clear insights and your best next steps.

HIPAA in Florida

HIPAA is the floor in Florida, not the ceiling. The Florida Information Protection Act (F.S. 501.171) adds a state breach-notification layer on top of HIPAA - and its definition of personal information expressly includes medical history, condition, treatment, and diagnosis information, plus health insurance policy numbers.

What the statute requires:

  • Reasonable security measures: every covered business must take reasonable measures to protect and secure electronic data containing personal information (F.S. 501.171(2)).
  • Individual notice within 30 days: affected individuals must be notified without unreasonable delay, and no later than 30 days after a breach is determined (F.S. 501.171(4)).
  • State notice at 500 records: a breach affecting 500 or more individuals in Florida must be reported to the Florida Department of Legal Affairs within 30 days, with a 15-day extension available for good cause (F.S. 501.171(3)).
  • Credit bureaus at 1,000: a breach affecting more than 1,000 individuals requires notice to the nationwide consumer reporting agencies.
  • Encryption matters here too: data that is encrypted or otherwise stripped of identifying elements falls outside the statute's notification trigger.
  • Late notice carries penalties: up to $1,000 per day for the first 30 days of violation, then up to $50,000 per subsequent 30-day period, capped at $500,000 (F.S. 501.171(9)).

Note the clock: HIPAA's Breach Notification Rule allows up to 60 days for individual notice. Florida allows 30. A Florida practice plans to the stricter deadline.

On the Treasure Coast, this is not an abstract concern - hospital systems, independent practices, specialty clinics, and treatment centers across Martin, St. Lucie, and Palm Beach counties handle PHI every day, and every one of them carries both the federal and the Florida obligations.

Official source

Official source: HHS Office for Civil Rights

Secondary source: eCFR - 45 CFR Part 164

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25