HIPAA in Practice: The Privacy, Security and Breach Notification Rules
Key Takeaways
- HIPAA applies to covered entities and business associates, defined by role, not to health information wherever it sits
- Treatment, payment and health care operations are permitted uses that do not require patient authorization
- The minimum necessary standard applies to most uses and disclosures but not to disclosures for treatment
- A breach is presumed unless a four-factor risk assessment shows a low probability that protected health information was compromised
- Business associates carry direct liability for Security Rule compliance, independent of their contract
Who Is Covered
HIPAA does not regulate health information as a category. It regulates two kinds of organization, and information falls in or out of scope depending on who holds it and why.
A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits health information in electronic form in connection with a transaction for which HHS has adopted a standard. That last qualifier matters: a provider who never conducts a covered electronic transaction is not a covered entity, however much clinical data it holds.
A business associate is a person or entity that creates, receives, maintains or transmits protected health information on behalf of a covered entity for a function or activity the regulation lists, or that provides specified services involving disclosure of PHI. The definition reaches cloud service providers that maintain encrypted PHI even without accessing it. Subcontractors that handle PHI on behalf of a business associate are themselves business associates.
Protected health information is individually identifiable health information transmitted or maintained in any form. Employment records held by a covered entity in its role as employer, and education records covered by FERPA, are excluded. Information that has been de-identified under either the Safe Harbor method or the expert determination method is no longer PHI.
The Privacy Rule: Use and Disclosure
The Privacy Rule works by default prohibition. A covered entity may not use or disclose PHI except as the rule permits or requires, or as the individual authorizes in writing.
The central permission covers treatment, payment and health care operations. A covered entity may use and disclose PHI for its own treatment, payment and operations without authorization, and may disclose to another covered entity for that entity's treatment or payment, and in defined circumstances for its operations. This is the permission that allows ordinary clinical and administrative work to proceed.
The rule also permits disclosure without authorization in a set of enumerated public-interest circumstances, including as required by law, for public health activities, about victims of abuse or neglect, for health oversight, in judicial and administrative proceedings subject to conditions, for law enforcement purposes subject to conditions, regarding decedents, for organ donation, for research subject to safeguards, to avert a serious threat to health or safety, for specialized government functions, and for workers' compensation.
Authorization is required for uses and disclosures outside those permissions, and specifically for most uses of psychotherapy notes, for marketing where the covered entity receives remuneration, and for any sale of PHI. A valid authorization has prescribed content, including a description of the information, the recipient, the purpose, an expiration, and a statement of the right to revoke.
Minimum Necessary
When using or disclosing PHI, or requesting it from another covered entity, a covered entity must make reasonable efforts to limit the information to the minimum necessary to accomplish the intended purpose. Implementation involves identifying who needs access to what, and limiting routine disclosures by category rather than case by case.
The standard has significant exceptions. It does not apply to disclosures to or requests by a health care provider for treatment, to disclosures to the individual, to uses or disclosures made under a valid authorization, to disclosures to HHS for enforcement, or to uses or disclosures required by law or required for compliance with the Rules. The treatment exception is the one most often misapplied, since restricting clinical information flow is not what the standard is aimed at.
The Security Rule Safeguards
The Security Rule applies only to electronic PHI and organizes requirements into administrative, physical and technical safeguards, plus organizational requirements and documentation standards.
| Category | Examples of standards | Character |
|---|---|---|
| Administrative | Security management process, workforce security, information access management, security awareness and training, contingency planning, evaluation | Largest category; includes the risk analysis and risk management specifications |
| Physical | Facility access controls, workstation use and security, device and media controls | Covers disposal and re-use of media |
| Technical | Access control, audit controls, integrity, person or entity authentication, transmission security | Encryption is addressable rather than required |
| Organizational | Business associate contracts, requirements for group health plans | Links the Security Rule to contracting |
| Documentation | Policies and procedures, six-year retention, periodic review and update | Written form required; retention runs from creation or last effective date |
Implementation specifications are either required or addressable. Addressable does not mean optional. It means the entity assesses whether the specification is reasonable and appropriate in its environment and, where it is not, documents why and implements an equivalent alternative measure where reasonable and appropriate. Encryption of ePHI at rest and in transit is addressable, which is why unencrypted device losses continue to generate enforcement despite the flexibility.
The Rule is deliberately technology-neutral and scalable, permitting entities to account for size, complexity, technical infrastructure and the cost of security measures against the probability and criticality of potential risks.
Business Associate Agreements
A covered entity may disclose PHI to a business associate only after obtaining satisfactory assurances, in a written contract, that the business associate will appropriately safeguard the information. The contract has prescribed content: permitted uses and disclosures, a prohibition on further use or disclosure, safeguards, reporting of unauthorized use or disclosure and of security incidents, flow-down to subcontractors, availability of PHI for individual rights, availability of records to HHS, return or destruction at termination, and a termination right for material breach.
The HITECH amendments made business associates directly liable for Security Rule compliance and for impermissible uses and disclosures, independent of contract terms. A business associate is therefore exposed to enforcement in its own right, not merely to a contract claim from the covered entity.
The conduit exception is narrow. It covers entities that transport information without accessing it other than randomly or infrequently, such as postal services and their electronic equivalents. Cloud storage providers that maintain PHI persistently do not fall within it, even where they hold only encrypted data and lack the key.
The Breach Notification Rule
A breach is the acquisition, access, use or disclosure of PHI in a manner not permitted by the Privacy Rule which compromises the security or privacy of the information. The rule establishes a presumption: any impermissible use or disclosure is presumed to be a breach unless the entity demonstrates a low probability that the PHI has been compromised based on a risk assessment addressing four factors.
- The nature and extent of the PHI involved, including types of identifiers and the likelihood of re-identification
- The unauthorized person who used the PHI or to whom the disclosure was made
- Whether the PHI was actually acquired or viewed
- The extent to which the risk to the PHI has been mitigated
Three exceptions sit outside the definition: certain unintentional acquisition or use by workforce members acting in good faith within scope of authority, certain inadvertent disclosures between authorized persons at the same entity, and disclosures where the entity has a good-faith belief the unauthorized recipient could not reasonably have retained the information.
Notification to affected individuals is due without unreasonable delay and no later than 60 days after discovery. Where a breach affects 500 or more residents of a state or jurisdiction, notice to prominent media outlets serving that area is required on the same timeline. Notice to HHS is due contemporaneously for breaches affecting 500 or more individuals; smaller breaches are logged and submitted annually, within 60 days of the end of the calendar year. Business associates notify the covered entity, without unreasonable delay and no later than 60 days from discovery.
Breaches involving PHI secured through encryption meeting the specified standard fall outside the notification obligation, which is the practical incentive behind the addressable encryption specification.
Individual Rights
The Privacy Rule gives individuals rights over their own PHI. The right of access entitles an individual to inspect and obtain a copy of PHI in a designated record set, in the form and format requested where readily producible. Action is due within 30 days of the request, with one 30-day extension available on written notice. A reasonable, cost-based fee may be charged, limited to labor for copying, supplies, postage and preparation of an explanation or summary where agreed.
Other rights include amendment of inaccurate or incomplete records, an accounting of certain disclosures, a right to request restrictions on use and disclosure, a right to a restriction the covered entity must honor where the individual pays out of pocket in full, a right to request confidential communications by alternative means, and a right to a notice of privacy practices.
OCR has pursued right-of-access failures as a distinct enforcement priority, and that line of settlements has centered on delay and on fees exceeding the cost-based limit rather than on outright refusal.
Administrative Requirements and the Notice of Privacy Practices
Beyond the substantive rules, the Privacy Rule imposes administrative requirements that apply regardless of whether any disclosure is ever contested. A covered entity must designate a privacy official responsible for developing and implementing policies, and a contact person for receiving complaints. Workforce training on policies and procedures is required, as is a complaint process, sanctions for workforce members who violate policies, and mitigation of known harmful effects of an improper use or disclosure.
The Rule also prohibits retaliation against individuals who exercise rights, file complaints or participate in investigations, and prohibits conditioning treatment, payment, enrollment or benefits eligibility on an individual signing an authorization, outside narrow exceptions.
The notice of privacy practices must describe how the entity may use and disclose PHI, the individual's rights, the entity's legal duties, and how to complain. Health care providers with a direct treatment relationship must provide it no later than the first service delivery and make a good-faith effort to obtain written acknowledgment of receipt. Acknowledgment is not consent: it records that the notice was delivered, and a failure to obtain it must be documented with the reason.
State Law and Preemption
HIPAA sets a floor rather than a ceiling. The Rules preempt contrary provisions of state law, but a state provision is not preempted where it is more stringent than the federal requirement, meaning it provides greater privacy protection or greater rights of access to the individual.
The practical result is that compliance analysis rarely stops at HIPAA. States impose shorter breach notification deadlines, broader definitions of covered information, additional protections for categories such as mental health, substance use disorder, HIV status, genetic information and reproductive health care, and in some cases their own enforcement mechanisms and private rights of action.
Federal law adds further layers for particular data. The confidentiality rules for substance use disorder patient records at 42 CFR Part 2 impose consent requirements stricter than HIPAA's treatment, payment and operations permission, and apply to a defined set of federally assisted programs. An entity subject to both must satisfy the stricter of the two for the records in question.
OCR Enforcement Structure
The HHS Office for Civil Rights enforces the Rules through complaint investigations, compliance reviews and audits. Most matters resolve through voluntary compliance, corrective action or a resolution agreement with a monetary settlement rather than through formal civil money penalties.
Civil money penalties are structured in tiers keyed to culpability: no knowledge, reasonable cause, willful neglect corrected within 30 days, and willful neglect not corrected. Each tier carries a minimum and maximum per violation and an annual cap for identical violations, all adjusted for inflation. Criminal penalties for knowing wrongful disclosure are enforced by the Department of Justice.
OCR also conducts periodic audit programs assessing selected covered entities and business associates against specified provisions, separate from complaint-driven investigations. Findings from those programs have been published in aggregate and have consistently identified the same gaps that appear in individual settlements, particularly around risk analysis and individual access.
State attorneys general also hold authority under HITECH to bring civil actions on behalf of state residents, and state health-privacy statutes frequently impose obligations beyond HIPAA. Whether a particular incident triggers duties under HIPAA, state law, or both is a fact-specific question.
There is no private right of action under HIPAA itself. Individuals who believe their health information was mishandled may complain to OCR, and separately may have claims under state statutory or common law, including negligence and state privacy torts, which courts in some jurisdictions have allowed to proceed using HIPAA as a standard of care rather than as the cause of action.
Background
For the underlying law rather than this development: Healthcare privacy law.
Frequently Asked Questions
Is every health care provider a HIPAA covered entity?
Does the minimum necessary standard apply to treatment?
Is encryption required by the HIPAA Security Rule?
When is an impermissible disclosure not a reportable breach?
Can a cloud provider avoid business associate status by holding only encrypted data?
Sources
Everything above is reported from these documents. Follow them to verify.
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.