Sign In As

AIVANA BRAYNOR · Premium Education Platform

Legal & Governance
20 min read
Updated July 2026

Healthcare Data Protection (HIPAA)

A comprehensive guide to US healthcare data privacy — HIPAA Privacy Rule, Security Rule, Breach Notification requirements, Business Associate obligations, OCR enforcement, and building a compliant health data protection program in the digital health era.

133M+
Records breached in 2023
HHS breach portal
$16M
Largest HIPAA settlement
Anthem, 2018
18
PHI identifiers
HIPAA Privacy Rule
60 days
Breach notification deadline
To affected individuals

Overview

The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996 and substantially strengthened by the HITECH Act (2009) and subsequent regulatory updates, establishes the United States' comprehensive legal framework for protecting individually identifiable health information. In an era of electronic health records, digital health apps, wearables, telehealth, AI-powered diagnostics, and cloud-based health data analytics, HIPAA compliance has become one of the most complex, consequential, and actively enforced areas of US data protection law.

Healthcare is among the highest-risk sectors for data breaches: the HHS breach portal documents hundreds of breaches affecting millions of individuals annually, driven by ransomware attacks on hospital systems, insider threats, misconfigured cloud storage, and third-party vendor vulnerabilities. The financial consequences of HIPAA violations are severe — civil monetary penalties reaching $2 million per violation category per year, criminal penalties including imprisonment for willful violations, and class action litigation from affected patients. The reputational consequences for healthcare organizations that experience major breaches can be existential.

This topic provides a comprehensive, practice-oriented guide to HIPAA compliance covering: who is covered (covered entities and business associates); what information is protected (PHI and ePHI); the obligations imposed by the Privacy Rule, Security Rule, and Breach Notification Rule; OCR enforcement mechanisms and penalty structure; the evolving landscape of digital health data privacy (including HIPAA's interaction with state privacy laws, FTC jurisdiction over health apps, and the 2024 HIPAA proposed updates); and practical guidance for building a compliant health data protection program.

Who Is Covered: Covered Entities and Business Associates

HIPAA's scope is defined by two categories of regulated entities. Covered entities are the organizations that create, receive, maintain, or transmit PHI in the course of providing healthcare: health plans (insurance companies, HMOs, Medicare, Medicaid), healthcare clearinghouses (companies that process nonstandard health information into standard formats), and healthcare providers (physicians, hospitals, pharmacies, nursing homes, dentists, and any other provider that transmits health information electronically in connection with covered transactions).

Business associates are a critically important — and frequently misunderstood — second tier of HIPAA-regulated entities. A business associate is any person or organization that performs functions or activities involving the use or disclosure of PHI on behalf of a covered entity, where the covered entity is not the employer of that person or organization. This definition captures an enormous range of vendors and service providers: cloud computing providers hosting EHR data, billing and revenue cycle management companies, health IT analytics firms, law firms handling health records in litigation, consultants reviewing patient data, document shredding services, and medical transcription companies.

The HITECH Act extended direct HIPAA liability to business associates — they are now directly subject to the Security Rule and certain Privacy Rule provisions and face direct civil and criminal penalties for violations, not merely breach of contract liability to the covered entity. Business associates are themselves responsible for their own subcontractors (sub-business associates or "downstream" business associates) and must flow down HIPAA obligations through a contractual chain. Every business associate relationship must be governed by a Business Associate Agreement (BAA) that meets HIPAA's specific requirements — a missing or deficient BAA is itself a HIPAA violation.

BAA Requirement: No PHI Access Without a Valid Business Associate Agreement

A covered entity may not permit a business associate to access, use, or disclose PHI without a valid Business Associate Agreement in place. BAAs must include specific required provisions: describe permitted uses and disclosures; require safeguards; require reporting of breaches and security incidents; require return or destruction of PHI upon termination; and ensure the business associate's subcontractors are bound by equivalent obligations. Missing BAAs — a common HIPAA violation — are a frequent focus of OCR investigations and enforcement actions.

Protected Health Information (PHI): Scope and Identifiability

PHI is defined as individually identifiable health information that is created or received by a covered entity or business associate in any form (paper, electronic, oral) and that relates to: the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for healthcare. The "individually identifiable" element is determined by whether the information identifies the individual, or whether there is a reasonable basis to believe it could be used to identify the individual.

HIPAA's Privacy Rule defines 18 specific identifiers that, when combined with health information, create PHI: name, geographic data (smaller than state level), dates (birth date, admission date, discharge date, death date, all ages over 89), telephone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers and serial numbers, device identifiers and serial numbers, URLs, IP addresses, biometric identifiers (fingerprints, voice prints), full-face photographs and comparable images, and any other unique identifying number, characteristic, or code.

De-identification of PHI removes HIPAA protections — once properly de-identified, information is no longer PHI and can be used and disclosed without HIPAA restrictions. HIPAA provides two approved de-identification methods: the Expert Determination method (a qualified expert statistically certifies that the risk of re-identification is very small); and the Safe Harbor method (removing all 18 identifiers and having no actual knowledge that residual information could identify an individual). Electronic PHI (ePHI) is the subset of PHI created, received, maintained, or transmitted in electronic form and is the specific subject of the Security Rule.

The Privacy Rule: Permitted Uses, Patient Rights, and Minimum Necessary

The HIPAA Privacy Rule establishes national standards for the protection of individuals' PHI by covered entities. It governs when PHI can be used and disclosed, establishes individual rights with respect to their PHI, and imposes administrative requirements on covered entities. The Privacy Rule permits (but does not require) disclosure of PHI without patient authorization for specific purposes — the most important being treatment, payment, and healthcare operations (collectively, "TPO").

Treatment uses are the broadest: covered entities may use and disclose PHI for providing, coordinating, or managing healthcare, including consultations between healthcare providers. Payment uses include billing, collection, claims management, and utilization review. Healthcare operations include quality assessment, care management, training programs, medical review, auditing, and business management activities. Beyond TPO, HIPAA permits certain disclosures in the public interest without authorization: required by law, public health activities, reporting abuse or neglect, health oversight activities, judicial proceedings, law enforcement, research (with IRB oversight), and certain national security purposes.

The minimum necessary standard requires covered entities and business associates to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum necessary to accomplish the intended purpose. The minimum necessary standard does not apply to disclosures for treatment — a provider treating a patient can share the complete medical record with other treating providers. For all other permitted uses, covered entities must implement policies and procedures that limit PHI access to those who need it and in the amount needed. Individual patients have specific Privacy Rule rights: right to access and receive copies of their PHI; right to request amendments; right to an accounting of disclosures; right to request restrictions; and right to confidential communications.

HIPAA Privacy Rule: Key Uses and Disclosures
CategoryAuthorization Required?Minimum Necessary?Examples
TreatmentNoNoSharing records with specialist, hospital admission
PaymentNoYesBilling insurer, revenue cycle management
Healthcare OperationsNoYesQuality review, staff training, auditing
Public HealthNo (required by law)YesReporting communicable diseases to CDC
ResearchNo (with IRB waiver)YesClinical trial with data use agreement
MarketingYes (written)YesTargeted health marketing campaigns
Sale of PHIYes (written)YesSelling patient data to data brokers

The Security Rule: Administrative, Physical, and Technical Safeguards

The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI they create, receive, maintain, or transmit. The Security Rule is technology-neutral (it does not mandate specific technologies) and scalable (small practices and large health systems may implement safeguards differently based on size, capability, and risk profile), but it is not optional — all required implementation specifications must be implemented; addressable specifications must be implemented if reasonable and appropriate for the entity, or the entity must document why implementation is not reasonable and implement an equivalent alternative.

Administrative safeguards are the policies, procedures, and management activities that protect ePHI and manage workforce behavior: a documented risk analysis and risk management process (the foundational Security Rule requirement); security officer designation; workforce training and sanctions; access management and authorization procedures; contingency planning (business continuity, disaster recovery); and periodic evaluation of compliance. The risk analysis — identifying all ePHI, assessing threats and vulnerabilities, evaluating current safeguards, and determining residual risk — is the most commonly cited deficiency in OCR investigations. Many enforcement actions specifically cite failure to conduct an accurate and thorough risk analysis as a core violation.

Physical safeguards control physical access to ePHI systems and the facilities where they operate: facility access controls, workstation use policies, device and media controls (particularly for mobile devices and portable media that present significant theft and loss risks). Technical safeguards are the technology and policy controls that protect ePHI and control access to it: unique user identification and authentication; automatic logoff; encryption (strongly recommended, and the key to the breach notification safe harbor); audit controls to record system activity; integrity controls; and transmission security. Encryption of ePHI at rest and in transit — while technically "addressable" rather than "required" — is so strongly recommended by OCR that it is effectively standard practice for any competent HIPAA compliance program.

Breach Notification Rule and Encryption Safe Harbor

The HIPAA Breach Notification Rule (established by the HITECH Act in 2009 and finalized in 2013) requires covered entities and business associates to provide notification following a breach of unsecured PHI. A "breach" is defined as an acquisition, access, use, or disclosure of PHI not permitted under the Privacy Rule that compromises the security or privacy of the PHI. There is a rebuttable presumption that any impermissible acquisition, access, use, or disclosure is a breach — the covered entity can rebut this presumption by demonstrating through a four-factor risk assessment that there is a low probability that PHI has been compromised.

When a breach occurs, covered entities must notify: (1) affected individuals within 60 days of discovery, providing a written description of the breach, the PHI involved, recommended steps to protect themselves, what the covered entity is doing to investigate, and contact information for questions; (2) HHS through the OCR online portal — breaches affecting fewer than 500 individuals may be reported annually within 60 days of year-end, while breaches affecting 500 or more individuals must be reported to HHS without unreasonable delay and within 60 days of discovery; (3) prominent media outlets in the relevant state or jurisdiction for breaches affecting 500 or more individuals in that state.

The encryption safe harbor is one of HIPAA's most practically important provisions: if ePHI is encrypted at the time of a breach, in accordance with NIST standards, or is physically destroyed according to NIST standards, the incident does not constitute a reportable breach — because the ePHI was "unsecured" as required for breach notification to apply. This safe harbor is a powerful incentive for implementing encryption: a stolen laptop containing encrypted ePHI does not require breach notification; the same laptop with unencrypted ePHI triggers notification obligations for potentially thousands of individuals, media notification, and OCR reporting — all with their associated costs, reputational damage, and regulatory scrutiny.

OCR Enforcement, Penalties, and Recent Investigation Trends

The Office for Civil Rights (OCR) within HHS is the primary federal enforcer of HIPAA. OCR investigates complaints from individuals, conducts compliance reviews (including targeted audits under the HIPAA Audit Program), and initiates investigations based on media reports of large breaches. The enforcement process typically culminates in a Resolution Agreement and Corrective Action Plan — a negotiated settlement specifying corrective actions and a financial payment — or, for egregious violations, a formal civil money penalty.

HIPAA's civil penalty structure consists of four tiers based on culpability: (1) the covered entity did not know and could not have known of the violation ($100–$50,000 per violation, $25,000 annual cap per violation type); (2) the violation was due to reasonable cause, not willful neglect ($1,000–$50,000 per violation, $100,000 annual cap); (3) willful neglect, timely corrected ($10,000–$50,000 per violation, $250,000 annual cap); (4) willful neglect, not corrected ($50,000 per violation, $1.5 million annual cap). Criminal penalties are also available: knowingly violating HIPAA is punishable by up to 1 year imprisonment; violations under false pretenses, up to 5 years; violations for personal gain or malicious harm, up to 10 years.

Recent OCR enforcement trends highlight the priority areas: risk analysis failures (failure to conduct thorough, accurate risk analyses covering all ePHI across the organization); access control deficiencies (former employees retaining system access after termination, unauthorized workforce access to patient records); ransomware and hacking (OCR has signaled that ransomware incidents will be presumed to be breaches unless the covered entity can demonstrate a low probability of compromise); and right of access enforcement (OCR's Right of Access Initiative has resulted in numerous settlements against covered entities that failed to provide patients timely access to their records at reasonable cost).

Digital Health Privacy: HIPAA's Limits, FTC Jurisdiction, and State Laws

A common and consequential misunderstanding about HIPAA is its scope. HIPAA does not cover all health information — it covers PHI held by covered entities and business associates. This means that health information collected by consumer-facing health apps, wearables, fitness trackers, and direct-to-consumer genetic testing companies (such as consumer versions of 23andMe or direct-to-consumer genomics platforms) is generally NOT subject to HIPAA unless the app is specifically functioning as a business associate of a covered entity.

The Federal Trade Commission (FTC) has asserted jurisdiction over health data privacy practices of non-HIPAA-covered entities under Section 5 of the FTC Act (unfair or deceptive acts or practices) and the Health Breach Notification Rule (which applies to personal health record vendors and similar entities not covered by HIPAA). The FTC's 2023 enforcement action against GoodRx — a prescription discount app — for sharing sensitive prescription data with advertisers without adequate user consent, and the $75 million settlement with Telehealth company Cerebral, signal active FTC engagement in the consumer health data privacy space.

State health privacy laws add another layer of complexity. Several US states have enacted health data privacy protections that go beyond HIPAA: Washington State's My Health MY Data Act (2023) applies to any business that collects consumer health data and is not a covered entity under HIPAA; California's Consumer Privacy Act and its amendment (CPRA) apply to health-adjacent data; and various states have specific genetic privacy, mental health, and reproductive health data protections. The intersection of HIPAA, FTC authority, and state privacy laws creates a complex multi-layered compliance obligation for any company operating in the digital health space.

FAQs: Healthcare Data Protection and HIPAA

Q: Does HIPAA apply to health apps and fitness trackers? A: Generally no, unless the app functions as a business associate of a HIPAA-covered entity (e.g., a telehealth app contracted with a hospital system). Consumer-facing health apps (fitness trackers, symptom checkers, nutrition apps) operating independently are typically not covered entities or business associates and are not subject to HIPAA. However, they may be subject to FTC jurisdiction, state privacy laws (Washington My Health MY Data Act, California CPRA), and the FTC Health Breach Notification Rule.

Q: What is a HIPAA risk analysis, and why is it so frequently cited in enforcement? A: The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI they hold. The risk analysis is the foundational Security Rule requirement — it informs all subsequent safeguard implementation decisions. OCR frequently cites failure to conduct a thorough risk analysis (covering all ePHI across all systems, facilities, and devices, including portable devices) as a primary violation in enforcement cases because many organizations conduct incomplete analyses that exclude entire categories of ePHI.

Q: How does HIPAA apply to cloud computing? A: Cloud service providers that store, process, or transmit ePHI on behalf of covered entities are business associates and must execute a BAA. Under OCR's cloud computing guidance (2016), even if a cloud provider merely stores encrypted ePHI without ever accessing the unencrypted data, it is still a business associate. The BAA must address the provider's obligations regarding ePHI security, breach notification, and return/destruction of ePHI. HIPAA-covered entities should confirm BAA status with all cloud providers handling their ePHI and ensure those BAAs meet the regulatory requirements.

Q: What is the difference between a breach and a security incident under HIPAA? A: A security incident is any attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI or interference with system operations — covered entities must have processes to respond to security incidents, but not all security incidents are breaches. A breach is a specific type of security incident: an impermissible use or disclosure of PHI that poses a significant risk of financial, reputational, or other harm to the individual. The key distinction is whether the impermissible use or disclosure meets the rebuttable presumption of harm, which requires a documented four-factor risk assessment to evaluate probability of compromise.

Q: Can employees access any patient record in the EHR? A: No. The HIPAA Privacy Rule's minimum necessary standard and the Security Rule's access control requirements together require that workforce members have access only to the PHI needed to perform their job functions. Healthcare organizations must implement role-based access controls (RBAC) that limit EHR access to authorized purposes, and must implement audit controls to detect and investigate unauthorized access. Snooping — employees accessing records of patients who are not under their care, out of curiosity — is a common source of HIPAA violations and OCR investigations. Sanctions policies must be implemented and enforced for workforce members who violate privacy policies.

Trending Facts & 2026 Outlook

2023 was the worst year on record for healthcare data breaches: over 133 million records were affected across more than 700 large breaches reported to HHS — a 156% increase from 2022 — driven primarily by ransomware attacks and hacking incidents targeting health IT vendors and hospital systems.

OCR's Right of Access Initiative — launched in 2019 and ongoing — has resulted in 50+ enforcement actions against covered entities that failed to provide patients timely access to their medical records. OCR has demonstrated that even smaller covered entities (individual physician practices, small clinics) will face civil penalties for right of access violations.

The FTC's Health Breach Notification Rule applies to personal health record vendors not covered by HIPAA. The FTC's expanded interpretation (2023) significantly broadened the rule's scope to cover health apps and connected devices that draw information from multiple sources — including consumer fitness and telehealth applications — bringing a vast new category of digital health companies into federal health privacy regulation.

Ransomware attacks on healthcare organizations accounted for over 60% of all healthcare data breaches in 2023-2024. OCR has clarified that ransomware incidents (where ePHI is encrypted by an attacker) are presumed to constitute breaches unless the covered entity can affirmatively demonstrate a low probability that PHI was compromised — making ransomware prevention and incident response a critical HIPAA compliance focus.

HHS proposed significant HIPAA Privacy Rule modifications in 2024, including new protections for reproductive health information (following the Dobbs Supreme Court decision), strengthening protections against disclosure of abortion-related PHI to law enforcement or government entities, and updating the definition of "health care" to reflect contemporary telehealth and digital health practices.

Best Practices

Conduct a Comprehensive, Current Risk Analysis

The risk analysis is the cornerstone of HIPAA Security Rule compliance and the most frequently cited deficiency in OCR enforcement. Conduct a thorough risk analysis covering ALL ePHI across ALL systems, applications, devices (including portable devices and personal devices used for work), and physical locations. Document the analysis with specificity — generic enterprise risk assessments that don't address ePHI specifically do not satisfy HIPAA. Repeat the analysis whenever significant operational, environmental, or technical changes occur.

Implement Encryption as Standard Practice

Encrypt ePHI at rest and in transit across all systems, devices, and media. While encryption is technically "addressable" under the Security Rule, the encryption safe harbor — which eliminates breach notification obligations for incidents involving encrypted ePHI — makes this one of the highest-ROI security investments any covered entity or business associate can make. Full disk encryption for laptops and mobile devices, database encryption for EHR systems, and TLS for data in transit are baseline requirements for any modern HIPAA compliance program.

Build a Rigorous BAA Management Program

Inventory all vendors, contractors, and service providers who access, receive, maintain, or transmit PHI on your behalf. For each, determine whether the relationship creates a business associate relationship requiring a BAA. Maintain a BAA tracking system with execution dates, renewal tracking, and attestation of BAA compliance. Conduct periodic BAA audits — OCR investigations frequently reveal missing or deficient BAAs as primary violations. Ensure BAAs flow down obligations to subcontractors.

Train Workforce Continuously, Not Annually

HIPAA requires ongoing workforce training, but the most effective programs go beyond annual compliance training checkboxes. Implement a continuous security awareness program including targeted training on phishing (the leading cause of healthcare data breaches), reinforcement of minimum necessary principles, mobile device security, and reporting obligations. Test workforce compliance through phishing simulations and scenario-based assessments. Implement and enforce documented sanctions for HIPAA violations — unenforced sanctions policies are ineffective and can increase liability exposure.

Develop and Test a Breach Response Plan

A documented breach response plan — including a response team with defined roles (security, legal, communications, compliance, executive leadership), a four-factor risk assessment protocol for evaluating whether incidents constitute reportable breaches, pre-drafted notification templates, and established relationships with external forensics, legal, and notification service providers — dramatically reduces the confusion, delay, and cost of breach response. Test the plan through tabletop exercises at least annually. The 60-day notification deadline for individual notification creates significant time pressure in complex breach scenarios.

Address Digital Health App PHI Carefully

As healthcare organizations adopt patient-facing apps, telehealth platforms, and third-party health IT tools, carefully analyze each tool's PHI handling and HIPAA status. Apps accessing the EHR through APIs may create business associate relationships requiring BAAs. Apps that collect PHI independently from patients may not be covered entities but may face FTC jurisdiction. Develop a health technology procurement process that includes HIPAA/privacy review, BAA negotiation, and security assessment before any new tool accesses patient data.

Key Takeaways

  • HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule apply to covered entities (health plans, healthcare clearinghouses, healthcare providers) and business associates (vendors handling PHI on their behalf) — direct liability for business associates was established by the HITECH Act and is actively enforced by OCR.
  • PHI encompasses individually identifiable health information in any form containing one or more of 18 specified identifiers — properly de-identified information is no longer PHI and not subject to HIPAA restrictions; encryption of ePHI provides the critical breach notification safe harbor that eliminates notification obligations when encrypted data is lost or stolen.
  • The HIPAA Security Rule requires covered entities and business associates to implement administrative (risk analysis, security officer, workforce training, access management), physical (facility and device controls), and technical safeguards (access control, audit controls, encryption, transmission security) — scaled to the organization's size and complexity.
  • OCR enforcement has focused on risk analysis failures, access control deficiencies, ransomware-related breaches, and right of access violations — with settlements ranging from tens of thousands to $16 million and corrective action plans requiring multi-year compliance monitoring.
  • HIPAA does not cover all health data — consumer health apps, wearables, and direct-to-consumer genetic testing companies that are not covered entities or business associates are subject to FTC jurisdiction, the FTC Health Breach Notification Rule, and state health privacy laws (Washington My Health MY Data Act, California CPRA, state reproductive health privacy laws).
  • Building a compliant HIPAA program requires treating it as an operational discipline — not a one-time project: ongoing risk analysis, continuous workforce training, comprehensive BAA management, current encryption implementation, and a tested breach response plan are the foundations of sustainable HIPAA compliance.