RegTech Reviews

HIPAA Compliance Requirements for Healthcare Providers

Contributing Editor · · 11 min read
Cover illustration for “HIPAA Compliance Requirements for Healthcare Providers”
Industry-Specific Regulations · July 30, 2026 · 11 min read · 2,559 words

HIPAA is not one rule. It is three interlocking rules, plus a fourth instrument that tightened the whole structure in 2013, and providers who treat any piece of it as a standalone checklist discover the gaps at the worst possible moment.

The Privacy Rule governs who can access and use PHI, in any format. The Security Rule governs how ePHI must be protected through administrative, technical, and physical safeguards. The Breach Notification Rule governs what must happen when PHI is improperly accessed or disclosed. Each has its own scope and its own enforcement teeth, but they create liability in combination. An impermissible disclosure under the Privacy Rule often simultaneously triggers a Breach Notification obligation. A Security Rule failure, say a misconfigured server or an absent encryption policy, frequently causes the breach that triggers both.

The 2013 Omnibus Rule functions as a fourth major instrument. It did not create a new regulatory territory so much as extend direct liability to business associates and their subcontractors, and tighten the existing structure considerably. Before 2013, a business associate's HIPAA obligation was largely contractual. After it, business associates face the same civil and criminal penalty exposure as covered entities. That is a meaningful distinction, and vendors who haven't absorbed it are a liability problem for the covered entities working with them.

Treating these four instruments as a coherent system, rather than isolated compliance tasks, is the difference between a program that holds up under scrutiny and one that doesn't.

Table: HIPAA's Four Major Instruments. Compares Governs, Key Obligation and Top Enforcement Failure by Privacy Rule, Security Rule, Breach Notification Rule and 2013 Omnibus Rule.

What the Privacy Rule Requires Providers to Do

The Privacy Rule's core obligations are more operational than most providers initially appreciate, and that gap between appreciation and reality is exactly where enforcement actions originate.

You need written policies and procedures governing how your organization uses and discloses PHI. You need a documented process for managing patient access requests and correction requests, and a clear procedure for obtaining patient authorization when a disclosure requires it. You must publish a Notice of Privacy Practices and ensure patients actually receive it, not just that a copy exists somewhere on a shelf. You must designate a privacy officer who is genuinely accountable for evaluating compliance across the organization. And you must train every employee on your privacy policies, not just clinical staff.

The minimum necessary standard is the requirement that gets underenforced most consistently. When using or disclosing PHI, providers must limit what they share to only what is necessary to accomplish the intended purpose. In practice, a billing department should not have access to clinical notes it doesn't need to process a claim. Documented policies that fail to translate into actual access controls are, functionally, no policy at all. OCR has heard that distinction argued in enforcement proceedings and has not found it persuasive.

The complaint pattern OCR receives from patients is a useful diagnostic tool for where compliance programs break down in practice. Impermissible uses and disclosures of PHI rank first in complaint frequency. Lack of safeguards follows. Lack of patient access, insufficient administrative safeguards for ePHI, and use of more than the minimum necessary PHI round out the most common allegations. These violations rarely stem from deliberate wrongdoing. They stem from missing or unenforced policies, which is both a more honest diagnosis and a more actionable one.

Website Tracking as an Emerging Privacy Rule Exposure

Web tracking is where providers consistently get caught flat-footed, and I understand why: it doesn't feel like a HIPAA problem until it is. Through bulletins issued between 2022 and 2024, OCR established that using tracking technologies, analytics pixels, third-party data tools, in ways that share PHI with outside vendors constitutes an impermissible disclosure under the Privacy Rule. If your patient portal or scheduling platform uses standard web analytics and those tools transmit any combination of identifiers alongside health-related activity, you are in violation.

OCR continued scrutinizing this area into 2025 and has signaled it will treat continued use after public guidance as willful neglect. Willful neglect is the highest civil penalty tier. This is not a theoretical risk waiting to materialize. The agency issued the guidance, gave the industry time to respond, and is now watching to see who updated their practices and who didn't.

What the Security Rule Requires for Electronic PHI

The Security Rule organizes its requirements into three categories of safeguard. Administrative safeguards include security management processes, a designated security officer, workforce training, and a formal security risk analysis. Physical safeguards govern facility access controls, workstation use policies, and device and media controls. Technical safeguards cover access controls, audit controls, integrity controls, and transmission security.

The Security Rule was originally structured around a distinction between required safeguards and addressable safeguards, where addressable specifications had to be implemented unless the entity documented a genuinely reasonable alternative. In practice, organizations used the "addressable" classification to defer encryption and other protective controls, not because they had a reasonable alternative, but because the flexibility was there and the scrutiny was absent. OCR has identified this pattern repeatedly in breach investigations. The distinction is not a loophole in the legal text. It became a loophole in actual practice, and the proposed 2025 rule is designed specifically to close it.

The security risk analysis is the cornerstone obligation. Covered entities must identify potential threats to PHI security and develop reasonable and appropriate policies in response. OCR's enforcement record is unambiguous: failure to conduct or properly document a risk analysis is the single most common Security Rule deficiency found in breach investigations, appearing in more than half of the enforcement actions resolved in 2024 and 2025. If I had to identify the one thing that separates organizations that survive breach investigations from those that don't, it is this. A documented, current, rigorous risk analysis. Everything else flows from it.

One more thing worth stating plainly: the Security Rule requires confidentiality, integrity, and availability. Not just preventing unauthorized access, but ensuring PHI remains accurate and accessible to authorized users. A system that keeps data away from intruders but makes it unavailable to a treating physician when needed is out of compliance. All three dimensions carry weight, and availability is the one that gets overlooked until a ransomware event makes it impossible to ignore.

How the Breach Notification Rule Works and What Triggers It

Under the Breach Notification Rule, any use or disclosure of PHI not permitted under the Privacy Rule is presumed to be a breach. The presumption is not automatic liability, but it is a formal presumption, and the only way to rebut it is through a documented four-factor risk assessment demonstrating a low probability that the PHI has been compromised. The four factors: the nature and extent of the PHI involved, who accessed or received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. If you can't show your work on all four, the presumption stands.

Notification timelines are strict. Affected individuals must receive written notice no later than 60 calendar days after discovery. For breaches affecting 500 or more individuals, HHS must be notified simultaneously. Smaller breaches are reported through an annual log submission. Breaches affecting 500 or more residents of a single state or jurisdiction also require notification to prominent media outlets serving that area, a requirement that surprises some providers the first time they encounter it, usually because they are encountering it mid-crisis.

The notice itself must include a description of the breach, the types of PHI involved, steps individuals should take to protect themselves, what the entity is doing to investigate and mitigate harm, and contact information for questions.

Business associates occupy a specific position in this structure. If a BA discovers a breach, it must notify the covered entity within 60 days of discovery. But the covered entity remains responsible for notifying individuals and HHS, and the business associate's delay does not extend the covered entity's clock. Providers who assume a slow-moving vendor buys them more time on notification are exposed in ways they often don't realize until it's too late.

The single most consequential practical point: the 60-day clock starts at discovery, not at the conclusion of an internal investigation. A provider who sits on a breach while conducting a thorough internal review is accumulating enforcement risk with every passing day.

The Patient Right of Access and What OCR's Enforcement Record Reveals About It

The right of access requires covered entities to provide individuals access to their PHI in designated record sets upon request: the right to inspect, obtain a copy, or direct a copy to a third party of the individual's choosing. Following the Omnibus Rule, this explicitly covers ePHI held in electronic health records.

The deadline is 30 calendar days from the date of the request. One 30-day extension is permitted if, and only if, the entity provides written notice of the reason for the delay and the expected completion date within that initial 30-day window. Not after it. Within it.

As of December 2025, OCR had reached 55 resolutions with covered entities specifically for right-of-access violations. In March 2025, OCR announced its 53rd right-of-access enforcement action: a $200,000 civil monetary penalty against an academic medical center that failed to provide complete records to a patient's personal representative. The initial requests began in April 2019. Records were not fully delivered until August 2021. The gap between those two dates is the violation. There is nothing ambiguous about that timeline.

What the cumulative enforcement pattern reveals is not that providers lack written policies on access. Most have them. The failure is execution: documented procedures that break down in the actual handling of specific patient requests, requests that fall into organizational gaps, miss deadlines quietly, and never get escalated until a complaint is filed. That is not a policy problem. It is a workflow and tracking problem. Entities need a mechanism to log requests at intake, monitor deadlines in real time, and escalate anything approaching the 30-day threshold. Policy language sitting in a compliance manual does nothing to prevent the next $200,000 penalty.

The Proposed 2025 Security Rule Overhaul and What It Would Change

HHS published a Notice of Proposed Rulemaking on January 6, 2025. The public comment period closed March 7, 2025. OCR had initially targeted May 2026 for a final rule. That date passed without action. The OMB's Unified Agenda now places the target at July 2027, a timeline that is not legally binding and will shift again. As of this writing, the proposed rule remains proposed.

Industry opposition has been substantial. In February 2025, CHIME and seven other healthcare associations, joined by more than 100 hospital systems, sent a formal letter to the Trump administration requesting withdrawal of the rule. The objection was not principally about the direction of the requirements. It was about cost. OCR estimated first-year compliance costs across all covered entities and business associates at $9 billion, a figure the industry did not absorb quietly.

The single largest structural change in the proposed rule is the elimination of the required-versus-addressable distinction. Every implementation specification would become mandatory, with limited exceptions. The flexibility that allowed organizations to defer encryption and other controls would be gone.

The proposed rule also introduces specific new technical requirements: encryption of ePHI in transit and at rest, multi-factor authentication, biannual vulnerability scanning, annual penetration testing, network segmentation, and security incident response with system restoration capability within 72 hours. On the documentation side, covered entities would need an annual technology asset inventory and network map covering all systems that touch ePHI, including AI tools. Security risk analyses would need to be tied directly to those inventories. Formal compliance audits would be required at least annually. Business associate oversight would tighten as well; under the proposed rule, BAs would need to confirm their adherence to safeguards and contingency plans within 24 hours of activation.

The rule is not final. But the technical controls it proposes, encryption, MFA, documented risk analysis, represent requirements that align with current enforcement priorities regardless of whether the rule clears the regulatory finish line. Preparing for them now is not premature. It is rational, and organizations that wait for the final rule to start will be behind before they begin.

The 2024 Reproductive Health Privacy Update and Its Subsequent Vacatur

In April 2024, HHS finalized updates to the Privacy Rule intended to restrict the use of PHI related to reproductive healthcare and, separately, to integrate substance use disorder treatment records into HIPAA's standard framework. The reproductive health provisions were designed to prevent PHI from being used to investigate or prosecute individuals seeking care that was lawful in the state where it was provided.

On June 18, 2025, the U.S. District Court for the Northern District of Texas declared the reproductive health privacy update unlawful and vacated most of it. The court held that HHS had exceeded its statutory authority and that the rule improperly limited states' ability to enforce their own laws regarding abortion and gender-affirming care. HHS chose not to appeal. The rule was rescinded.

What remains in force is specific and worth tracking precisely. The revisions governing substance use disorder treatment records under 42 CFR Part 2, which integrated those records into HIPAA's standard compliance framework, were not vacated. Covered entities were required to update their Notices of Privacy Practices to reflect those 42 CFR Part 2 changes by February 16, 2026. That deadline is real and active, and it did not move because the reproductive health provisions were struck down.

For providers who updated their policies in anticipation of the full reproductive health rule, the practical obligation now is to review which of those changes are still required, which remain legally supportable as organizational policy, and which should be rolled back to avoid inconsistency with the current legal landscape. The February 2026 NPP update deadline for substance use disorder records does not go away.

The Current Enforcement Environment and What Penalties Actually Look Like

Civil monetary penalties under HIPAA scale by culpability. The lowest tier covers violations where the covered entity did not know, and could not reasonably have known, of the violation. The highest tier covers willful neglect that is not corrected. The spread between those tiers is enormous, and OCR's characterization of a violation's culpability level has significant financial consequences for the organization involved. That characterization is not arbitrary. It is driven by what the organization knew, when it knew it, and what it did in response.

The enforcement record across the past several years reflects consistent prioritization of a few recurring failure categories. Right-of-access violations have generated more than 50 enforcement resolutions since OCR launched its focused initiative. Risk analysis failures appear in the majority of recent Security Rule enforcement actions. Web tracking practices represent an emerging priority where continued noncompliance after public warning will be treated as willful neglect.

What the enforcement pattern reflects, in aggregate, is not a regulator hunting for technicalities. OCR's resolutions disproportionately involve situations where an organization had some version of a policy on paper and failed to execute it in practice, or where the organization had no meaningful safeguard at all. That is the real picture. The organizations that fare best in this environment treat compliance as an operational discipline, not an annual documentation exercise. Risk analysis, access request tracking, workforce training, vendor oversight: these are not compliance theater. They are the actual substance of what OCR is looking for when it comes in.

Sources

  1. kiteworks.com
  2. mcneelylaw.com
  3. cms.gov
  4. hhs.gov

More in Industry-Specific Regulations