What is HIPAA?
HIPAA is a United States federal law enacted in 1996. For data security and privacy, its key implementing regulations were issued by the Department of Health and Human Services (HHS) and are codified at 45 CFR Parts 160 and 164: the Privacy Rule (rules for using and disclosing protected health information — PHI), the Security Rule (safeguards for electronic health data — ePHI) and the Breach Notification Rule (breach reporting obligations). These rules were strengthened by the HITECH Act of 2009 and the 2013 Omnibus Rule, which extended liability directly to business associates.
The Security Rule is technology-neutral and risk-based: it requires administrative, physical and technical safeguards that are “reasonable and appropriate” for the organisation’s size, resources and risk profile. Implementation specifications are either required or addressable — the latter can be met with an alternative measure, but the decision must be documented. In early 2025 HHS published a proposed update to the Security Rule that would, among other things, make encryption and multi-factor authentication explicitly mandatory — the finalisation of these rules is worth tracking.
Who is it for?
HIPAA applies to two groups. The first is covered entities: healthcare providers that transmit data electronically (hospitals, clinics, pharmacies), health plans (insurers) and healthcare clearinghouses. The second is business associates — any entity that creates, receives, maintains or transmits PHI on behalf of a covered entity: software and cloud vendors, billing companies, law firms, analytics providers. Since the Omnibus Rule, business associates (and their subcontractors) are directly liable to the regulator for Security Rule compliance.
For European technology companies, HIPAA becomes relevant the moment they enter the US market: a SaaS provider serving US healthcare customers acts as a business associate and must sign a Business Associate Agreement (BAA) and implement the required safeguards. Without the ability to sign a BAA, selling into US healthcare is practically impossible.
The Security Rule — three groups of safeguards
The Security Rule (45 CFR §164.302-318) organises the requirements into three groups of safeguards, with risk analysis as the foundation — the first thing the regulator asks about in every investigation.
- Administrative safeguards (§164.308): risk analysis and management, a designated Security Official, workforce security, information access management, training, incident procedures, a contingency plan, periodic evaluation, and business associate contracts.
- Physical safeguards (§164.310): facility access controls, workstation use and security rules, and device and media controls — including permanent data removal before disposal.
- Technical safeguards (§164.312): access control (unique identifiers, emergency access, automatic logoff, encryption), audit controls, data integrity, person or entity authentication, and transmission security.
- Organisational and documentation requirements (§164.314-316): the content of BAA agreements and the obligation to retain policies and records for 6 years.
The Privacy Rule and breach notification
The Privacy Rule defines when PHI (in any form — including paper) may be used and disclosed. Without patient consent, uses for treatment, payment and healthcare operations are generally permitted; other purposes (for example marketing or the sale of data) require a written authorization. The overarching rule is the minimum necessary standard. Patients have rights: access to records (generally within 30 days), amendment, an accounting of disclosures, and requests for restrictions and confidential communications. Organisations must also publish a Notice of Privacy Practices.
The Breach Notification Rule requires notifying about breaches of unsecured PHI: affected individuals without unreasonable delay and no later than 60 days; HHS — within the same deadline for breaches affecting 500 or more people (smaller ones are reported annually); the media — when a breach affects more than 500 residents of a single state. Data encrypted in line with HHS guidance enjoys a safe harbor: its loss is not notifiable. The burden of demonstrating that notifications were made, or were not required, rests with the organisation.
Enforcement, penalties and “certification”
HIPAA is enforced by the HHS Office for Civil Rights (OCR) — through complaints, reported breaches and its own audits. Civil penalties are tiered by culpability (from lack of knowledge to wilful neglect) and reach — after inflation adjustments — around two million dollars per violation category per year; OCR settlements with large organisations have exceeded ten million dollars. Intentional misuse can trigger criminal liability enforced by the Department of Justice. A separate OCR enforcement priority is the patient’s right of access to records (the Right of Access Initiative).
HIPAA has no official certification — no authority issues a “HIPAA certificate”, and vendor claims of “certified compliance” are purely commercial. In market practice, readiness is demonstrated with a documented risk analysis, a complete set of policies and evidence, and independent attestations used by health technology vendors — most often HITRUST CSF or a SOC 2 report extended with HIPAA criteria.
How does Guardiso help?
Guardiso turns HIPAA requirements into a concrete, measurable compliance programme — from the first self-assessment, through risk analysis, to a complete evidence set ready for an OCR audit or customer due diligence.
- HIPAA controls seeded automatically when you enable the standard — administrative, physical and technical safeguards, Privacy Rule and Breach Notification, with implementation statuses and owners.
- A risk register supporting the risk analysis required by §164.308(a)(1) — identifying threats to ePHI, assessment, treatment plans and residual risk.
- Policies and procedures generated from templates (security, incidents, contingency plan, sanctions) with versioning and management approval — ready for the 6-year documentation retention.
- A vendor and business associate register with risk assessment — tracking who you have signed BAAs with and when their safeguards were last assessed.
- Compliance evidence collected in one place: employee training, access reviews, logs, backup restore tests.
- An incident register with an assessment of whether an event is a notifiable breach, and tracking of notification deadlines.
- Cross-mapping to ISO 27001, SOC 2 and NIST CSF — work done for one standard counts towards overlapping HIPAA requirements.
