HIPAA
HIPAA
Definition: The Health Insurance Portability and Accountability Act, a US law setting strict requirements for how healthcare-related personal data (PHI, Protected Health Information) must be handled, protected, and disclosed.
How It Works
- Covers two groups: “covered entities” (healthcare providers, insurers, clearinghouses) and their “business associates” (any vendor that creates, receives, maintains, or transmits PHI on their behalf, including most software vendors)
- The Privacy Rule governs how PHI can be used and disclosed; the Security Rule sets technical, physical, and administrative safeguards specifically for electronic PHI (ePHI)
- Required technical safeguards: encryption at rest and in transit, role-based access controls, audit logging, automatic session timeouts
- Required administrative safeguards: a designated security officer, workforce training, a documented incident response plan, periodic risk assessments
- Required physical safeguards: facility access controls, workstation security, and device/media disposal procedures for anything that ever stored PHI
- A vendor handling PHI must sign a Business Associate Agreement (BAA) with the covered entity before touching any PHI, this is a contract, not a certification
- The Breach Notification Rule requires notifying affected individuals, HHS, and sometimes the media, on a strict timeline once a breach is confirmed
- The “minimum necessary” standard limits access and disclosure to the smallest amount of PHI needed for a given purpose, not blanket access for every employee
- Patients have a legal right of access to their own records, a covered entity must provide copies within 30 days of a request (extendable once by 30 days with notice)
- The 2013 Omnibus Rule extended direct liability under HIPAA to subcontractors of business associates, not just the primary vendor a covered entity contracts with directly
- Enforcement uses four penalty tiers based on culpability, from unknowing violations up through willful neglect that’s never corrected, with per-violation and annual caps that adjust for inflation
| Tier | Culpability | Relative severity |
|---|---|---|
| 1 | Unknowing violation | Lowest per-violation penalty |
| 2 | Reasonable cause, not willful neglect | Moderate |
| 3 | Willful neglect, corrected within 30 days | High |
| 4 | Willful neglect, not corrected | Highest, largest annual cap |
Under the Hood
HHS guidance lists four factors used in the risk assessment step, to decide whether a security incident rises to a reportable breach:
- the nature and extent of the PHI involved (does it include SSNs, diagnoses, financial data)
- who the unauthorized person was and whether they had any legitimate reason to see it
- whether the PHI was actually acquired or viewed, versus just theoretically exposed
- the extent to which the risk was mitigated (e.g. a remote-wiped device, a confirmed-deleted email)
Worked example 1: large breach
- Given: a hospital’s billing vendor discovers on March 1 that an unencrypted laptop holding 1,200 patient records was stolen the week before
- Step 1: risk assessment finds the data was unencrypted and accessible, so this is a reportable breach
- Step 2: the 60-day clock starts at discovery (March 1), not at the theft date
- Step 3: individual notification deadline is April 30 (60 days from discovery)
- Step 4: 1,200 exceeds the 500-person threshold, so HHS notification and a prominent media notice are both required, on the same 60-day clock
- Answer: notify all 1,200 individuals, HHS, and local media by April 30
Worked example 2: small breach
- Given: a clinic employee emails 12 patient records to the wrong address, discovered the same day
- Step 1: risk assessment concludes PHI was compromised (recipient unknown, deletion unconfirmed)
- Step 2: 12 is under the 500-person threshold, so no media notification is required
- Step 3: individuals must still be notified within 60 days of discovery
- Step 4: for sub-500 breaches, HHS notification can be bundled into an annual log, due within 60 days of the end of the calendar year
- Answer: notify the 12 individuals within 60 days; report to HHS in the annual log, not immediately
Worked example 3: patient access request
- Given: a patient emails their primary care clinic on June 1 asking for a full copy of their chart
- Step 1: the clinic must respond within 30 days of the request, by default
- Step 2: if the records are unusually voluminous or stored offsite, the clinic can invoke a single 30-day extension, but must notify the patient in writing before the original deadline
- Step 3: worst case (extension invoked) the records are due by July 31; best case, by July 1
- Answer: 30 days from request, extendable once to 60 days total with written notice
Why It Matters
- Any product touching US health data needs HIPAA-eligible infrastructure from day one, this narrows which cloud services, analytics tools, and even email providers are usable
- A missing or unsigned BAA with a vendor is itself a violation, independent of whether any data was ever actually breached
- Breach notification isn’t optional PR, it’s a legal deadline with individual, federal, and sometimes press-facing components
- Non-compliance exposure scales with how much PHI a product touches, this shapes build-vs-buy decisions for anything from file storage to customer support tooling
- Subcontractor liability under the Omnibus Rule means compliance has to be verified down the whole vendor chain, not just at the first contract layer
- Patient access rights turn “export my data” from a nice-to-have feature into a hard legal deadline with a real clock attached
- The penalty tiers reward having a real compliance program: the same incident is punished far more lightly if it’s an unknowing gap than if it’s neglect nobody bothered to fix
Common Pitfalls
This is general information, not legal advice, consult a healthcare compliance attorney for a real system.
- Picking a cloud service or SaaS tool before confirming it will sign a BAA, then discovering the incompatibility after the product is already built
- Assuming encryption alone satisfies HIPAA, the Security Rule also requires access controls, audit logging, workforce training, and incident response
- Using consumer-grade tools (personal email, free-tier chat apps, generic form builders) for anything touching PHI because they’re convenient
- Treating the Business Associate Agreement as boilerplate paperwork instead of an actual scope-of-responsibility document
- Missing the 60-day notification clock because the “discovery” date wasn’t tracked precisely
- Forgetting that de-identified data (stripped of the 18 HIPAA identifiers) is no longer PHI and isn’t subject to these rules, over-restricting harmless data
- Ignoring a subcontractor’s compliance posture because the direct contract is with a business associate, not the covered entity
- Granting broad database access to an entire engineering team instead of scoping it to the “minimum necessary” for each role
- Storing PHI in staging or analytics environments that were never brought under the same safeguards as production
- Assuming a third-party storage vendor’s own security posture is someone else’s problem, rather than something the covered entity remains accountable for
- Skipping the periodic risk assessment because nothing has “changed” recently, when new integrations and features quietly change the actual risk surface
Comparison
| HIPAA | GDPR | SOC 2 | CCPA | |
|---|---|---|---|---|
| Scope | US healthcare data (PHI) | Any personal data of EU residents | Any system a company chooses to have audited | California residents’ personal data |
| Enforced by | HHS Office for Civil Rights | EU data protection authorities | No government enforcement, contractual/market pressure | California Attorney General, CPPA |
| Core mechanism | Safeguards plus breach notification rules | Consent, data rights, lawful basis | Independent audit of controls | Consumer rights (opt-out, deletion, access) |
| Certification | No formal certification, self-attestation plus audits | No formal certification | Formal auditor report (Type I/II) | No formal certification |
| Breach notice deadline | 60 days | 72 hours to regulator | Not breach-specific | Without unreasonable delay |
| Applies to vendors via | Business Associate Agreement | Data Processing Agreement | Subservice organization carve-outs in the audit report | Service provider contract terms |
Example
Anthem Inc., one of the largest US health insurers, disclosed in 2015 that attackers had accessed a database containing personal information for approximately 78.8 million people, including names, birthdates, and Social Security numbers. It remains one of the largest healthcare data breaches publicly reported in the US, led to a major HHS settlement, and is a standard case study in why breach scale drives both notification scope and regulatory consequences.
A second widely reported case: HCA Healthcare disclosed in 2023 that data for roughly 11 million patients across its facilities was exposed after information was stolen from an external storage location and posted for sale on a hacking forum, illustrating that breach risk extends beyond a hospital’s own systems to any third party storing its data.
HIPAA and SOC 2 are often confused because both come up in vendor security reviews: HIPAA is a specific legal requirement tied to health data, while SOC 2 is a voluntary audit that can cover any kind of sensitive data, healthcare or otherwise. A company can be SOC 2 compliant and still not be HIPAA compliant, and vice versa, they answer different questions for different audiences.
Related Terms
Referenced by