Nexeris

What Is HIPAA Compliance: Definition & Requirements

If you are trying to understand what is HIPAA compliance, it refers to the federal requirements organizations must follow to protect the privacy and security of certain health information. This includes knowing where protected health information is stored, controlling who can access it, protecting electronic systems, training employees, managing third parties, responding to incidents, and keeping the right documentation.

HIPAA compliance is not a one-time project. Technology, vendors, employees, security threats, and business processes change over time, so organizations need an ongoing program that keeps privacy and security practices aligned with their regulatory responsibilities.

What Does HIPAA Compliance Mean?

HIPAA compliance means meeting the applicable requirements of the HIPAA Privacy, Security, Breach Notification, and related rules. These requirements govern how protected health information is used, disclosed, accessed, stored, transmitted, and protected.

Organizations need both documented policies and operational safeguards. Having policies without implementing them, or security controls without appropriate documentation and oversight, can leave significant compliance gaps.

What Does HIPAA Stand For?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996.

The law addresses several areas of healthcare, but HIPAA is most commonly associated with federal standards protecting the privacy and security of health information.

What Are PHI and ePHI?

Protected health information (PHI) generally includes individually identifiable information about a person’s health, healthcare, or payment for healthcare when handled by a covered entity or business associate.

PHI can exist in paper, verbal, or electronic form.

Electronic protected health information (ePHI) is PHI that is created, received, maintained, or transmitted electronically. Examples include information stored in electronic health records, databases, cloud systems, emails, laptops, and other digital environments.

Who Needs to Comply With HIPAA?

HIPAA primarily applies to covered entities and business associates. It does not automatically apply to every organization that collects health-related information.

Which Organizations Are Covered Entities?

Covered entities generally include:

  • Health plans
  • Health care clearinghouses
  • Healthcare providers that conduct certain electronic healthcare transactions

Examples may include hospitals, physicians, clinics, pharmacies, health insurers, and other qualifying healthcare organizations.

What Is a HIPAA Business Associate?

A business associate is generally an organization or person that performs certain functions or services involving PHI on behalf of a covered entity.

Examples may include IT providers, billing companies, cloud service providers, consultants, data processors, attorneys, and record storage companies.

Business associates are directly responsible for complying with certain HIPAA requirements.

Do Business Associate Subcontractors Need to Comply?

A subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate can also qualify as a business associate.

The business associate generally must obtain appropriate contractual assurances from qualifying subcontractors regarding the protection of PHI.

Which Organizations Are Not Automatically Covered by HIPAA?

Not every company handling health-related data is automatically subject to HIPAA.

Depending on how they operate, certain wellness apps, fitness companies, employers, schools, life insurers, and consumer technology platforms may fall outside HIPAA. Other federal or state privacy requirements may still apply.

What Are the Main HIPAA Rules?

Several HIPAA rules work together to establish privacy, security, and breach-response obligations.

What Is the HIPAA Privacy Rule?

The Privacy Rule establishes requirements for how PHI may be used and disclosed and gives individuals certain rights over their health information.

It addresses areas including patient access, privacy notices, permitted disclosures, amendments, workforce responsibilities, and the minimum necessary standard.

What Is the HIPAA Security Rule?

The Security Rule focuses specifically on protecting ePHI.

It requires regulated entities to implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic health information.

What Is the HIPAA Breach Notification Rule?

The Breach Notification Rule establishes requirements for responding to certain breaches of unsecured PHI.

Depending on the circumstances, notification may be required to affected individuals, HHS, and sometimes the media.

Business associates must also report applicable breaches to covered entities. Notification generally must occur without unreasonable delay and no later than 60 calendar days after discovery.

How Do HITECH and the HIPAA Omnibus Rule Affect Compliance?

The HITECH Act strengthened HIPAA enforcement and extended direct responsibility for certain requirements to business associates.

The 2013 HIPAA Omnibus Rule implemented important HITECH-related changes, including expanded business associate responsibilities and requirements involving subcontractors.

What Are the Core HIPAA Compliance Requirements?

Organizations need a coordinated combination of risk analysis, safeguards, policies, workforce controls, vendor oversight, and incident preparedness.

Conduct a HIPAA Risk Analysis

The Security Rule requires an accurate and thorough assessment of risks and vulnerabilities affecting ePHI.

Organizations should identify where ePHI exists, how it moves, what threats could affect it, and which weaknesses require remediation.

A broader cybersecurity risk assessment can also help teams understand security weaknesses and prioritize risk treatment.

Implement Administrative, Physical, and Technical Safeguards

Administrative safeguards address policies, responsibilities, risk management, workforce security, and contingency planning.

Physical safeguards protect facilities, workstations, devices, and media.

Technical safeguards address areas such as access control, authentication, audit controls, integrity, and transmission security.

Maintain HIPAA Policies and Documentation

Organizations should maintain written policies and procedures that accurately reflect how PHI and ePHI are protected.

Security Rule documentation generally must be retained for six years from the later of its creation date or the date it was last in effect.

Train Employees and Control Access to PHI

Employees need appropriate training on privacy and security responsibilities.

Organizations should also limit access according to job responsibilities and promptly change or remove access when employee roles change or employment ends.

Manage Business Associates and BAAs

Organizations should identify vendors that qualify as business associates and maintain appropriate business associate agreements, or BAAs.

Regular vendor security assessments can help identify third-party risks that could affect sensitive information.

Maintain Breach Response Procedures

Organizations need procedures for investigating incidents, determining whether PHI was compromised, documenting findings, and completing required notifications.

Effective incident response planning helps establish responsibilities before a real incident occurs.

What Rights Does HIPAA Give Patients?

The HIPAA Privacy Rule gives individuals several rights over their protected health information. These rights are designed to give patients more control over how their information is accessed, corrected, shared, and communicated.

Right to Access Health Information

Individuals generally have the right to inspect or obtain copies of PHI maintained in designated record sets.

Covered entities generally must act on access requests within 30 calendar days, with one additional 30-day extension allowed in certain circumstances. A pending HIPAA Privacy Rule change could shorten that timeframe to 15 calendar days, with one additional 15-day extension. For now, the current 30-day requirement remains in effect.

Right to Request Corrections

Individuals may request amendments when they believe information in their health or billing records is inaccurate or incomplete.

A covered entity does not have to approve every request, but it must follow the required HIPAA process when responding. If an amendment request is denied, the individual may have additional rights to submit a statement of disagreement.

Right to an Accounting of Disclosures

Individuals can request an accounting of certain disclosures of their PHI made by a covered entity.

This accounting generally covers disclosures that fall outside common activities such as treatment, payment, and healthcare operations. Certain other disclosures are also excluded under the Privacy Rule.

The right gives individuals a way to understand when their information has been shared in circumstances covered by the accounting requirement.

Right to Request Restrictions

Individuals have the right to ask a covered entity to restrict certain uses or disclosures of their PHI, including uses for treatment, payment, or healthcare operations.

Covered entities do not have to agree to every restriction request. However, if a covered entity agrees to a restriction, it generally must follow it. HIPAA also requires providers to agree to certain requests involving disclosures to a health plan when the patient has paid for the applicable item or service in full and other conditions are met.

Right to Confidential Communications

Individuals can request that a healthcare provider communicate with them in a particular way or at an alternative location.

For example, a patient may ask a provider to contact them at work instead of at home or to use a specific phone number or mailing address.

Healthcare providers generally must accommodate reasonable requests for confidential communications. Health plans also have obligations in certain situations where the individual states that disclosure through normal channels could put them in danger.

Right to Receive a Notice of Privacy Practices

Most covered healthcare providers and health plans must provide individuals with a Notice of Privacy Practices.

The notice explains how PHI may be used and disclosed, what privacy responsibilities the organization has, and what rights individuals have under HIPAA.

Right to File a Complaint

Individuals have the right to file a complaint if they believe their HIPAA privacy rights have been violated.

Complaints can be made directly to the covered entity or submitted to the HHS Office for Civil Rights. Organizations are not permitted to retaliate against individuals for exercising their HIPAA rights.

Right to Revoke an Authorization

Individuals generally have the right to revoke a HIPAA authorization they previously provided.

The revocation must be made in writing and becomes effective when the covered entity receives it. It does not undo actions the covered entity already took in reliance on a valid authorization before the revocation was received.

How Do Organizations Become and Stay HIPAA Compliant?

HIPAA compliance is easier to manage when organizations follow a structured process.

Step 1: Determine Whether HIPAA Applies

Identify whether the organization operates as a covered entity, business associate, or qualifying subcontractor.

Step 2: Identify PHI, ePHI, Systems, and Data Flows

Document where sensitive information enters the organization, where it is stored, how it moves, who accesses it, and which third parties receive it.

Step 3: Complete a Risk Analysis and Gap Assessment

Assess threats and vulnerabilities affecting ePHI and compare existing controls against applicable HIPAA requirements.

Step 4: Remediate Security and Privacy Gaps

Prioritize deficiencies based on risk. Common areas include access controls, authentication, logging, vendor management, incident response, and documentation.

Step 5: Implement Policies, Training, and Safeguards

Develop appropriate policies and implement administrative, physical, and technical safeguards. Train employees on their responsibilities.

Step 6: Review Vendors and Business Associate Agreements

Confirm which vendors qualify as business associates and ensure required BAAs are current and appropriate.

Step 7: Monitor Compliance and Maintain Documentation

Continue reviewing controls, risks, access, incidents, vendors, training, and documentation as the organization changes.

Is There an Official HIPAA Certification?

The phrase “HIPAA certified” can be misleading because HIPAA does not provide an official government certification program for organizations.

Can an Organization Become Officially HIPAA Certified?

No official HHS certification permanently establishes that an organization is HIPAA compliant.

Private assessments or certifications may demonstrate that controls were reviewed, but they do not replace legal obligations.

Can a Consultant or Third Party Guarantee HIPAA Compliance?

A consultant can assess gaps, improve controls, conduct risk analysis, develop policies, and help prepare documentation.

However, a third party cannot eliminate an organization’s responsibility for maintaining compliance over time.

How Can an Organization Demonstrate HIPAA Compliance?

Organizations can maintain evidence such as:

  • Risk analyses
  • Risk management records
  • Policies and procedures
  • Training records
  • Access reviews
  • BAAs
  • Incident documentation
  • Security assessments
  • Remediation records

Evidence should show that controls are operating rather than existing only on paper.

What Are the Most Common HIPAA Compliance Violations?

Compliance problems often occur when security controls and operational processes are incomplete or outdated.

Unauthorized Access or Disclosure of PHI

Employees and third parties should only access or disclose PHI when permitted and necessary.

Unauthorized access, accidental disclosures, and improper sharing can create significant compliance risks.

Missing or Incomplete Risk Analysis

A risk analysis that excludes systems, applications, vendors, or locations may leave major risks unidentified.

Weak Security Safeguards and Access Controls

Weak authentication, excessive permissions, poor monitoring, and inadequate device protection can expose ePHI.

Missing Business Associate Agreements

Failing to establish an appropriate BAA with a qualifying business associate can create compliance exposure.

Inadequate Employee Training

Employees who do not understand privacy, security, phishing, disclosure, and incident reporting procedures can increase organizational risk.

Failure to Follow Breach Notification Requirements

Organizations must investigate potential breaches and complete required notifications within applicable deadlines.

What Happens If an Organization Violates HIPAA?

HIPAA violations can result in regulatory investigations, corrective actions, settlements, financial penalties, and potentially criminal referrals.

How Does an OCR Investigation Work?

The HHS Office for Civil Rights, or OCR, enforces the HIPAA Privacy and Security Rules.

OCR may investigate complaints, conduct compliance reviews, and request documentation showing how an organization meets its obligations.

What Penalties and Corrective Actions Can Apply?

Depending on the circumstances, organizations may face financial penalties or be required to implement corrective action plans.

Corrective measures may include new risk analyses, revised policies, improved safeguards, employee training, reporting requirements, and ongoing monitoring.

Can Business Associates Be Directly Liable?

Yes. Business associates can be directly liable for certain HIPAA violations, including failures involving the Security Rule, impermissible uses or disclosures of PHI, breach notifications, and certain subcontractor obligations.

What Is the Status of HIPAA Security Rule Changes in 2026?

In December 2024, HHS proposed the first major update to the HIPAA Security Rule since 2013. It was published in the Federal Register on January 6, 2025. HHS pointed to the rise in healthcare ransomware attacks and large breaches as the reason. The proposal would make the current rule’s flexible standards more specific, and much of it would become mandatory. 

What Changes Are Proposed to the HIPAA Security Rule?

The proposed rule would make several important changes to the current HIPAA Security Rule:

  • No more “addressable” specifications: Nearly all implementation specifications would become required, with only limited exceptions.
  • Encryption and MFA: ePHI would need to be encrypted at rest and in transit, and multi-factor authentication would be required for access to systems that hold ePHI.
  • Asset inventory and network map: Organizations would need to maintain a written inventory of technology assets that affect ePHI, along with a network map showing how ePHI moves through their systems. Both would need to be reviewed at least once a year.
  • More detailed risk analysis: Risk analyses would need to address specific elements such as threats, vulnerabilities, likelihood, and potential impact.
  • Vulnerability management: Organizations would need to conduct vulnerability scans every six months and penetration tests every year. The proposal also includes requirements around network segmentation and patching within defined timeframes.
  • Incident response and recovery: Organizations would need written incident response plans that are tested, along with the ability to restore critical systems within 72 hours.
  • Annual compliance audits: Organizations would need to audit their own Security Rule compliance every year.
  • Business associate oversight: Business associates would need to provide covered entities with written verification of their technical safeguards each year. They would also need to report activation of their contingency plans within 24 hours.

These changes are still proposed and should not yet be treated as current HIPAA requirements.

Are the Proposed Security Rule Changes Currently in Effect?

As of September 30, 2026, HHS continues to identify the cybersecurity changes as a Notice of Proposed Rulemaking, not a final rule. Organizations should therefore not treat the proposed requirements as if they have already replaced the current Security Rule.

What Requirements Apply While the Proposed Changes Are Pending?

Covered entities and business associates must continue complying with the Security Rule currently in effect.

That includes applicable requirements involving risk analysis, risk management, administrative safeguards, physical safeguards, technical safeguards, incident procedures, contingency planning, access controls, business associate arrangements, and documentation.

Organizations can also monitor the proposed changes and strengthen cybersecurity practices that may help prepare them for future regulatory requirements.

How Nexeris Helps Organizations Prepare for HIPAA Compliance

HIPAA compliance requires coordination between cybersecurity, risk management, documentation, employees, vendors, and leadership.

Nexeris helps organizations identify gaps and establish structured processes for addressing applicable HIPAA privacy and security requirements.

HIPAA Risk Analysis and Gap Identification

Nexeris helps organizations identify systems containing ePHI, assess security risks, evaluate existing safeguards, and document compliance gaps that require remediation.

Safeguard, Policy, and Documentation Readiness

Organizations need safeguards that work in practice and documentation that reflects how those controls operate.

Nexeris helps teams align administrative, physical, and technical safeguards with policies, procedures, and supporting evidence.

Vendor and Business Associate Risk Management

Third-party providers can create additional risk when they access, process, or store PHI.

Working with a HIPAA compliance consultant can help organizations assess their readiness, evaluate business associate relationships, address security gaps, and build a repeatable compliance program.

FAQs

What Is HIPAA Compliance?

HIPAA compliance means meeting applicable federal requirements for protecting PHI and ePHI through privacy controls, security safeguards, policies, training, vendor management, and ongoing oversight.

Who Is Required to Comply With HIPAA?

HIPAA primarily applies to covered entities and business associates, including qualifying healthcare providers, health plans, clearinghouses, and organizations handling PHI on their behalf.

What Is Considered PHI Under HIPAA?

PHI generally includes individually identifiable health information relating to a person’s health, healthcare, or payment for healthcare when handled by a covered entity or business associate.

What Is the Difference Between PHI and ePHI?

PHI can exist in multiple forms. ePHI specifically refers to PHI that is created, received, maintained, or transmitted electronically.

What Are the Three Types of HIPAA Security Safeguards?

The three categories are administrative, physical, and technical safeguards.

Is a HIPAA Risk Analysis Required?

Yes. Regulated entities subject to the Security Rule must conduct an accurate and thorough assessment of risks and vulnerabilities affecting ePHI.

Do Business Associates Have to Be HIPAA Compliant?

Yes. Business associates are directly responsible for complying with certain applicable HIPAA requirements.

Is There an Official HIPAA Certification?

No. HHS does not provide an official certification that permanently establishes HIPAA compliance.

How Long Must HIPAA Documentation Be Retained?

HIPAA compliance documentation required under both the Privacy Rule and Security Rule generally must be retained for six years from the later of the date it was created or the date it was last in effect.

This six-year requirement applies to HIPAA-related documents such as policies, procedures, authorizations, training records, risk assessments, and other required compliance records. It does not establish how long medical records themselves must be kept. Medical record retention periods are generally governed by other federal or state laws and can vary by jurisdiction and record type.

What Happens If a Company Is Not HIPAA Compliant?

Noncompliance can result in OCR investigations, corrective action requirements, settlements, civil penalties, additional monitoring, and potentially criminal referrals depending on the circumstances.

Zach Tracy, Nexeris founder and CEO

Zach Tracy, CISA, CISSP

Zach Tracy is the CEO and a cybersecurity executive with more than 10 years of experience in security program management and regulatory compliance. He has served as a fractional Chief Information Security Officer for over 40 organizations and has led more than 100 audits across frameworks including SOC 2, CMMC, NIST CSF, ISO 27001, HIPAA, and HITRUST.

Zach specializes in helping defense contractors and regulated organizations build practical, audit-ready security programs that protect contract eligibility and reduce operational risk. He holds CISA, CISSP, CMMC-RP, and ISO 27001 and 9001 Lead Implementer certifications, along with a B.S. in Cybersecurity from Thomas College.

A Marine Corps veteran and former law enforcement officer, Zach brings a mission-focused, disciplined approach to cybersecurity leadership.

Connect with Zach on LinkedIn

Scroll to Top