Learn about HIPAA‘s rules, the minimum necessary standard, patient rights, HIPAA Privacy & Security Rules, Breach Notification, and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a free consultation, if you are looking for experienced professionals to help you comply with HIPAA, conduct a HIPAA Security Analysis, and for other customized services.
Table of Contents
What are the main HIPAA rules?
HIPAA is composed of four primary rules, each addressing a different aspect of health information protection, and the 2013 Omnibus Rule substantially updated all four. The four rules are:
The Privacy Rule (compliance required by April 2003): Establishes national standards for the use and disclosure of PHI by covered entities and their business associates, and grants patients specific rights over their health information.
The Security Rule (compliance required by April 2005 for most covered entities): Sets standards for protecting ePHI through administrative, physical, and technical safeguards.
The Breach Notification Rule (introduced by the HITECH Act, effective 2009): Requires covered entities and business associates to notify affected individuals, the Department of Health and Human Services (HHS), and in some cases the media following a breach of unsecured PHI.
The Enforcement Rule (effective 2006, substantially updated 2009): Establishes procedures for investigating violations, the tiered civil monetary penalty structure, and the hearing process.
What is the HIPAA Privacy Rule?
The HIPAA Privacy Rule establishes national standards for protecting individually identifiable health information held by covered entities and their business associates. It governs PHI in all forms, electronic, paper, and oral, and permits use or disclosure without patient authorization only for treatment, payment, and healthcare operations. For most other uses, written authorization is required. The Privacy Rule also grants patients the right to access and obtain copies of their health records, request corrections, receive an accounting of certain disclosures, and request restrictions on uses or disclosures. Covered entities must designate a privacy officer, train their workforce on privacy policies and procedures, and provide patients with a Notice of Privacy Practices.
What is the HIPAA “minimum necessary” standard?
The minimum necessary standard requires covered entities and business associates to limit the use, disclosure, and request of PHI to the minimum amount needed to accomplish the intended purpose. A billing department, for example, does not need access to a patient’s complete clinical notes, only the information required for billing. This standard does not apply to disclosures to healthcare providers for treatment, disclosures to the patient about their own information, disclosures to HHS for compliance reviews, or disclosures required by law. Covered entities must establish policies that limit PHI access based on each workforce member’s role and what is minimum necessary for their job function.
What patient rights does HIPAA provide?
HIPAA grants patients six core rights over their protected health information, spanning the right to access and correct their records to the right to restrict certain disclosures. The full set of rights is:
Right of access: Patients may inspect and obtain copies of their PHI held in designated record sets, including medical records, billing records, lab results, imaging, and treatment notes (excluding psychotherapy notes). When records are electronic, patients may request an electronic copy. Covered entities must act within 30 calendar days, with one possible 30-day extension if written notice is provided within the original window.
Right to amend: Patients may request corrections to inaccurate or incomplete PHI.
Right to an accounting of disclosures: Patients may request a list of instances in which their PHI was disclosed for purposes other than treatment, payment, or healthcare operations.
Right to restrict disclosures: Patients may request that covered entities restrict certain uses or disclosures. Covered entities are generally not required to agree, with one exception: if a patient pays entirely out of pocket for a service, they may require that the information not be shared with their health plan.
Right to confidential communications: Patients may request that communications be sent by alternative means or to alternative locations.
Right to file a complaint: Patients may file a complaint with the covered entity or directly with the HHS Office for Civil Rights if they believe their privacy rights have been violated.
What is the HIPAA Security Rule?
The HIPAA Security Rule establishes national standards for protecting electronic protected health information (ePHI). It applies to any covered entity or business associate that creates, receives, maintains, or transmits ePHI, and requires a combination of administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of that data. Unlike the Privacy Rule, the Security Rule applies exclusively to electronic information, it does not govern paper PHI or oral communications. The rule is intentionally flexible: organizations implement safeguards that are reasonable and appropriate given their size, complexity, technical infrastructure, and the specific risks to their ePHI. The HITECH Act extended the Security Rule directly to business associates.
What are the three categories of safeguards under the HIPAA Security Rule?
The HIPAA Security Rule organizes its requirements into three categories, administrative, physical, and technical, that together protect ePHI across people, facilities, and systems.
Administrative Safeguards are the policies, procedures, and management practices governing how an organization selects, develops, and maintains security measures to protect ePHI. They include conducting a documented security risk analysis, implementing a risk management program, creating a sanction policy for workforce violations, running security awareness and training programs, developing contingency and disaster recovery plans, and designating a security officer responsible for HIPAA security compliance.
Physical Safeguards govern the protection of ePHI systems, buildings, and equipment from unauthorized access and environmental threats. They cover facility access controls, workstation use policies that specify how and where ePHI may be accessed, and device and media controls for the handling, transfer, and disposal of electronic media.
Technical Safeguards are technology-based controls that protect ePHI and regulate who can access it. They include access controls (unique user IDs, emergency access procedures, and automatic logoff), audit controls to track activity in systems containing ePHI, integrity controls to prevent improper alteration or destruction of ePHI, and transmission security measures such as encryption.
What is the difference between “required” and “addressable” implementation specifications under the Security Rule?
The HIPAA Security Rule divides its implementation specifications into required and addressable types, but “addressable” does not mean optional. Required specifications must be implemented as stated. Addressable specifications require organizations to assess whether a specific safeguard is reasonable and appropriate given their environment, size, and risk profile. If it is, it must be implemented. If it is not, the organization must document why and either implement an equivalent alternative or document that none exists. In practice, most addressable specifications must be implemented in some form because the overarching obligation to protect ePHI cannot be waived.
Note: HHS’s January 2025 NPRM proposes to eliminate this required/addressable distinction entirely, making all specifications uniformly required. That rule has not been finalized as of March 2026; the current framework remains in effect.
What is the HIPAA Breach Notification Rule?
The HIPAA Breach Notification Rule requires covered entities and business associates to provide timely notifications following a breach of unsecured PHI. A breach is any impermissible use or disclosure that compromises the security or privacy of PHI, and any such incident is presumed to be reportable unless the covered entity can demonstrate a low probability that PHI was compromised. This determination relies on a four-factor risk assessment: the nature and extent of the PHI involved, the identity of the unauthorized person who accessed it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
What are the breach notification timelines and requirements under HIPAA?
A breach of unsecured PHI triggers four distinct notification obligations, each with its own deadline and intended audience.
Notification to affected individuals: Written notice, by first-class mail, or email if the individual has consented, must be sent within 60 calendar days of discovering the breach. The notice must describe what happened, identify the types of PHI involved, advise the individual on protective steps, describe the covered entity’s investigative and mitigation response, and provide contact information for follow-up questions.
Notification to HHS: For breaches affecting 500 or more individuals, covered entities must notify HHS without unreasonable delay and no later than 60 days from discovery. These breaches are posted publicly on the HHS breach notification portal, commonly known as the “Wall of Shame.” For smaller breaches, covered entities may log them internally and report annually to HHS within 60 days of the calendar year-end in which the breaches were discovered.
Media notification: When a breach affects more than 500 residents in a particular state or jurisdiction, covered entities must notify prominent media outlets serving that area within 60 days of discovery. This is in addition to, not in place of, individual and HHS notification.
Business associate obligations: When a breach occurs at or by a business associate, the business associate must notify the covered entity without unreasonable delay and no later than 60 days from discovery, providing identifying information about affected individuals to the extent known.
What is the HITECH Act, and how does it relate to HIPAA?
The HITECH Act fundamentally strengthened HIPAA by extending Security Rule liability directly to business associates, creating the Breach Notification Rule, and substantially raising civil monetary penalties for violations. Enacted on February 17, 2009, as part of the American Recovery and Reinvestment Act, HITECH made business associates independently liable for compliance rather than relying solely on contractual arrangements. It introduced mandatory breach notification requirements, directed HHS to conduct periodic compliance audits of covered entities and business associates, and significantly increased the penalty structure by introducing tiered civil monetary penalties based on culpability. HITECH also included financial incentives to encourage widespread adoption of certified electronic health records by linking payments to meaningful use of certified systems.
What is the HIPAA Omnibus Rule?
The 2013 Omnibus Rule was the most sweeping HIPAA update since the original rules, extending direct liability to business associates, revising the breach standard to a presumption of breach, and strengthening patient rights across the board. Published on January 25, 2013, with a compliance date of September 23, 2013, the rule implemented outstanding changes required by the HITECH Act and the Genetic Information Non-discrimination Act (GINA). Key changes included: making business associates and their subcontractors directly and independently liable for HIPAA Privacy, Security, and Breach Notification Rule compliance; requiring a four-factor risk assessment to avoid breach notification rather than allowing self-certification; strengthening restrictions on the use of PHI for marketing and fundraising; prohibiting the sale of PHI without patient authorization; expanding patients’ rights to obtain electronic copies of their records; and adding protections for genetic information, prohibiting health plans from using it as a basis for underwriting decisions.
What is a HIPAA Notice of Privacy Practices?
A Notice of Privacy Practices (NPP) is a required document that covered entities must provide to patients and plan members, explaining how PHI may be used and disclosed and what rights individuals hold under HIPAA. The NPP must describe permitted uses and disclosures for treatment, payment, and healthcare operations; explain uses requiring authorization; describe patient rights; state the entity’s legal duty to protect PHI; and provide information about how to file a complaint with OCR or with the covered entity. Healthcare providers must make a good-faith effort to obtain written acknowledgment of receipt from patients at the first point of service. Health plans must distribute the NPP to enrollees at enrollment and whenever it is materially revised. The NPP must be posted prominently at the facility and on the covered entity’s website.
As of February 16, 2026, covered entities that create or maintain substance use disorder records under 42 CFR Part 2 must have updated their NPPs to reflect changes from 2024 rulemaking aligning Part 2 with HIPAA. This is a current, active compliance obligation.
What are the HIPAA requirements for workforce training?
HIPAA requires covered entities and business associates to train all workforce members, including employees, volunteers, trainees, and supervised contractors, whose work involves access to PHI or ePHI. The Privacy Rule requires training on privacy policies and procedures. The Security Rule requires a security awareness and training program covering topics such as recognizing malicious software, monitoring login attempts, and creating and safeguarding strong passwords. Training must occur when a new member joins the organization and whenever policies or procedures change in ways affecting their responsibilities. Records of training completion must be retained for at least six years. While HIPAA does not specify a mandatory recurring frequency, annual training is the industry standard. Workforce members who violate HIPAA policies must be subject to documented sanctions consistent with the organization’s sanction policy.
How long must HIPAA-related documents and records be retained?
HIPAA requires covered entities and business associates to retain compliance documentation for a minimum of six years from the date created or the date it was last in effect, whichever is later. This applies to privacy and security policies, notices of privacy practices, complaint records, security risk analyses, risk management plans, training records, BAAs, workforce sanction records, and breach notification documentation. State laws often impose longer retention requirements, and organizations should apply the more stringent standard where both apply. Many organizations adopt a uniform retention policy of seven to ten years to account for both HIPAA requirements and state law variation.
What are incidental disclosures under HIPAA, and are they permitted?
Incidental disclosures are explicitly permitted under HIPAA, they are unavoidable secondary byproducts of an otherwise permissible disclosure, provided the covered entity has applied reasonable safeguards and the minimum necessary standard. Classic examples include a conversation between a physician and a nurse at a nursing station overheard by a nearby patient, a patient’s name being called in a waiting room, or a visitor seeing another patient’s name on a hospital whiteboard. The key conditions are that the covered entity must have implemented reasonable safeguards, using lowered voices in shared spaces, positioning computer screens away from public view, using privacy curtains, and must have applied the minimum necessary standard to the underlying permissible disclosure. An incidental disclosure that results from a failure to apply reasonable safeguards is not protected and may constitute a HIPAA violation.
How does HIPAA apply to research involving patient data?
HIPAA’s Privacy Rule establishes specific pathways for using PHI in research, balancing the public interest in medical advancement against individual privacy rights, with four primary options ranging from full patient authorization to the use of fully de-identified data. Research is defined as a systematic investigation designed to develop or contribute to generalizable knowledge. The four most common pathways are:
(1) Written HIPAA Authorization from each participant, including a description of the PHI to be used, the research purpose, and the right to revoke;
(2) Waiver or alteration of authorization by an Institutional Review Board (IRB) or Privacy Board, requiring a determination that the research involves minimal privacy risk and would be impracticable without the waiver;
(3) A limited data set, PHI with most direct identifiers removed but retaining certain geographic and date information, used pursuant to a data use agreement;
(4) Fully de-identified data, which is not subject to HIPAA at all.
Research using PHI only for preparatory activities, such as assessing study feasibility, may also proceed under certain conditions without authorization, provided no PHI is removed from the covered entity’s premises.
What is a “designated record set” under HIPAA and which records does it include?
A designated record set (DRS) is the defined category of records from which a covered entity uses information to make decisions about individuals, and it is precisely this set of records that patients have the right to access and request corrections to under the HIPAA Privacy Rule. For healthcare providers, the DRS includes medical records, billing records, and any other records used to make decisions about a patient’s care, payment, or eligibility. For health plans, it includes enrollment records, payment records, claims adjudication records, and case or medical management record systems.
In late 2025, OCR issued updated guidance clarifying that the DRS is broader than many covered entities have historically acknowledged. It includes lab results, imaging, clinical notes (excluding psychotherapy notes, which have separate protections), treatment notes, immunization records, referral records, and, importantly, records held by business associates on behalf of the covered entity, such as claims data or care management files stored in a third-party system. Records excluded from the DRS, and therefore not subject to patient access rights, include quality improvement files used only for internal purposes, peer review documents protected by state law, and records prepared in anticipation of litigation.
How long does HIPAA protect the health information of deceased individuals?
HIPAA’s Privacy Rule protects the PHI of deceased individuals for 50 years following the date of death, after which it is no longer subject to HIPAA. During this period, covered entities must handle a decedent’s PHI with the same protections required for living individuals. Covered entities may disclose a decedent’s PHI to surviving family members, personal representatives, or others involved in the decedent’s care if the disclosure is relevant to their involvement, consistent with the decedent’s known preferences, and not contrary to any expressed restrictions. Covered entities must also comply with requests from authorized personal representatives of the estate. State law may impose additional or conflicting obligations, and organizations should apply the more stringent standard where applicable.
How quickly must a covered entity respond to a patient’s request for their records?
Covered entities have 30 calendar days to respond to a records request, either providing the records or issuing a written denial, with one possible 30-day extension if written notice of the delay is sent within the original window. This is an outer limit, not a target; OCR explicitly encourages covered entities to respond as quickly as possible. To use the extension, the covered entity must send the individual a written statement within the original 30-day period explaining the reason for delay and the date by which it will complete the request. Only one extension per request is permitted under any circumstances. Covered entities may not withhold records solely because a patient has an outstanding balance.
Failure to meet these deadlines is among the most actively enforced HIPAA provisions. OCR’s Right of Access Initiative, launched in 2019, has produced more than 54 financial penalties through early 2026, including a $200,000 civil monetary penalty against Oregon Health & Science University in March 2025 for failing to provide a patient’s personal representative with timely access.
What is a HIPAA Authorization, and when is one required?
A HIPAA Authorization is a specific written document, distinct from general consent forms, that gives a covered entity permission to use or disclose an individual’s PHI for purposes not otherwise permitted by the Privacy Rule. A valid Authorization is required for: the use of PHI for marketing where the covered entity receives financial remuneration from a third party; the sale of PHI; disclosures of psychotherapy notes to most parties; most research uses (unless an IRB or Privacy Board waiver is obtained); and most disclosures for purposes unrelated to treatment, payment, or healthcare operations that do not fall under another Privacy Rule exception.
For a HIPAA Authorization to be valid under 45 CFR § 164.508, it must contain eight specific elements:
- a description of the PHI to be used or disclosed
- the name or class of persons authorized to make the disclosure
- the name or class of persons to whom disclosure may be made
- a description of the purpose
- an expiration date or event
- the individual’s signature and the date
- a statement of the right to revoke and the revocation process
- a statement that treatment, payment, enrollment, or eligibility for benefits may not be conditioned on signing, with narrow exceptions.
The Authorization must be written in plain language, and the individual must receive a copy.
Who is a HIPAA “personal representative,” and what rights do they have?
A personal representative is an individual legally authorized under state law to make healthcare decisions on behalf of another, and holds the same HIPAA rights as that individual, including the right to access PHI, request amendments, receive an accounting of disclosures, and authorize uses that otherwise require individual authorization. A covered entity must treat a personal representative exactly as it would treat the individual themselves for all PHI relevant to the representation.
Common categories of personal representatives include parents or guardians of unemancipated minor children (with important exceptions); court-appointed legal guardians for adults lacking decision-making capacity; individuals holding a healthcare power of attorney or durable power of attorney for healthcare decisions; and, following a patient’s death, the executor or administrator of the estate.
The exceptions for minors are significant: a minor generally has independent privacy rights, meaning the parent is not the personal representative, in three circumstances: when state law permits the minor to consent to care without parental involvement (such as for certain reproductive health, mental health, or substance use disorder services); when a court order has removed parental authority over the minor’s healthcare decisions; or when the covered entity reasonably believes that treating the parent as the personal representative could endanger the minor. Covered entities may also decline to recognize a personal representative if they have a reasonable belief that doing so could expose the individual to domestic violence, abuse, or neglect.
What are psychotherapy notes under HIPAA, and why do they receive special protection?
Psychotherapy notes receive the strongest privacy protection of any PHI category under HIPAA, excluded from the patient’s own right of access and requiring a separate written Authorization for virtually every use or disclosure, including disclosure to other treating providers. Under HIPAA (45 CFR § 164.501), psychotherapy notes are defined narrowly as notes documenting or analyzing the contents of a counseling session, stored separately from the rest of the patient’s medical record. The definition does not cover medication prescription records, session start and stop times, treatment modalities, clinical test results, or functional status summaries, those elements are ordinary medical records, not psychotherapy notes.
The heightened protection reflects the particular sensitivity of mental health treatment and the therapeutic relationship’s dependence on confidentiality. Psychotherapy notes are the only PHI category entirely excluded from the patient’s standard right of access. They require a separate, specific written Authorization for virtually every use or disclosure, with only narrow exceptions: use by the originating therapist, use in training programs, use to defend against a legal claim by the patient, oversight of the therapist by a health oversight agency, to avert a serious and imminent threat, or as required by law.
When does HIPAA require a written authorization for marketing communications?
Under HIPAA’s Privacy Rule, most marketing uses of PHI require a valid written authorization, and a communication is classified as marketing when it encourages a recipient to purchase or use a product or service, regardless of whether the content appears educational. Without authorization, a covered entity may use PHI for marketing only in three narrow circumstances: face-to-face communications with an individual, promotional gifts of nominal value, and refill reminders or communications about currently prescribed drugs or biologics where the covered entity receives no financial remuneration from a third party beyond reasonable compensation.
Three situations are commonly misclassified.
First, if a third party pays a covered entity to send a health-related communication to its patients, even apparently educational content, that communication is almost certainly marketing and requires authorization.
Second, communications promoting a covered entity’s own services are not marketing when they relate to the patient’s current treatment, but they are marketing when they promote services unrelated to that treatment.
Third, the 2013 Omnibus Rule substantially tightened these provisions: any subsidized communication a covered entity is paid to make generally requires authorization unless it falls within one of the explicit exceptions. A covered entity found to be conducting marketing without authorization risks civil monetary penalties and OCR investigation.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties