The Three HIPAA Rules
HIPAA compliance is structured around three primary rules. The Privacy Rule (effective April 2003) defines Protected Health Information (PHI), establishes 18 types of individually identifiable health data, requires patient rights to access and amend their records, and imposes the minimum necessary standard on all PHI disclosures. The Security Rule (effective April 2005) applies specifically to electronic PHI (ePHI) and requires covered entities and business associates to implement administrative, physical, and technical safeguards — including risk analysis, workforce training, access controls, audit controls, encryption in transit, and device and media controls.
The Breach Notification Rule (effective February 2010 under HITECH) requires covered entities to notify affected individuals within 60 days of discovering a breach, notify HHS for breaches affecting 500+ individuals (triggering immediate publication on the Wall of Shame), and notify HHS annually for breaches affecting fewer than 500 individuals. Media notice is required for breaches affecting 500+ individuals in a state or jurisdiction.
Who Must Comply
The following entities are subject to HIPAA Compliance Hub obligations:
- →Covered Entities: healthcare providers (hospitals, clinics, physicians, pharmacies), health plans (insurers, HMOs), and healthcare clearinghouses
- →Business Associates: any vendor receiving, maintaining, or transmitting PHI — cloud providers, EHR vendors, billing platforms, analytics companies, SaaS tools
- →Subcontractors of Business Associates who handle PHI (downstream BAA chain)
- →Health-tech and digital health startups with access to patient data via API, integration, or data processing agreements
- →Telemedicine platforms, remote patient monitoring companies, and digital therapeutics providers
- →Research institutions receiving patient data from covered entities for clinical research
Penalties and Enforcement History
HIPAA penalties follow a four-tier structure based on culpability. Tier 1 (did not know): $100–$50,000 per violation, $25,000 annual cap per category. Tier 2 (reasonable cause): $1,000–$50,000 per violation, $100,000 annual cap. Tier 3 (willful neglect corrected): $10,000–$50,000 per violation, $250,000 annual cap. Tier 4 (willful neglect uncorrected): $50,000 per violation, $1.9M annual cap per violation category. The 2024 HIPAA Safe Harbor provision reduces penalties for entities that have implemented recognized cybersecurity frameworks (NIST CSF, NIST SP 800-66) in the 12 months preceding a breach. OCR has collected over $135M in settlements and penalties since 2009.
Enforcement Timeline
Regulatory Comparison
| Dimension | HIPAA | GDPR | SOC 2 |
|---|---|---|---|
| Type | US federal regulation | EU data protection law | Voluntary audit/attestation |
| Enforcement Body | HHS Office for Civil Rights | National DPAs + EDPB | No enforcement — commercial |
| Max Annual Penalty | $1.9M per violation category | €20M or 4% global turnover | No fine — lost contracts |
| Breach Notification | 60 days (500+ individuals) | 72 hours to supervisory authority | Not required (contractual SLA) |
| Scope | US PHI only | EU/EEA personal data | Customer data broadly |
| Privacy Officer | Required (Privacy Rule) | DPO required for high-risk | Not required |
Mitigation Strategy
The Security Rule requires a formal risk analysis as a foundation of your HIPAA compliance programme. The risk analysis must identify all ePHI created, received, maintained, or transmitted; identify and evaluate the probability and impact of each threat and vulnerability; implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level; and document the process. Risk analysis must be reviewed and updated in response to environmental or operational changes. OCR consistently cites missing or inadequate risk analysis as the #1 compliance failure in investigations.
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate. HIPAA requires a written Business Associate Agreement (BAA) before any PHI is shared. The BAA must specify permitted uses and disclosures, require the BA to implement appropriate safeguards, require the BA to report breaches, and require the BA to return or destroy PHI at contract termination. Cloud providers (AWS, GCP, Azure) all offer HIPAA-eligible services with BAAs — but signing the BAA and configuring your environment to be HIPAA-eligible are two separate steps. Failure to execute a BAA before sharing PHI is a per-violation HIPAA violation.
Technical safeguards are the most frequently cited area in OCR audits. Required controls: unique user identification (no shared accounts for ePHI systems); automatic logoff after inactivity; encryption and decryption of ePHI in transit (TLS 1.2+ required; TLS 1.3 recommended) and at rest (AES-256 standard); audit logging of all ePHI access, modification, and deletion; and integrity controls to detect unauthorised ePHI alteration. Addressable (required unless documented alternative): encryption at rest, automatic logoff timers, message authentication. The HIPAA Safe Harbor (2024) reduces penalties for entities implementing NIST CSF or NIST SP 800-66 frameworks.
Frequently Asked Questions
A: HIPAA applies to your startup if you are (1) a covered entity — a healthcare provider who transmits health information electronically, a health plan, or a healthcare clearinghouse — or (2) a Business Associate — any company that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Most healthcare technology companies, EHR vendors, patient portal providers, health analytics platforms, telehealth companies, and healthcare AI companies are Business Associates. If your product stores, processes, or transmits identifiable patient health information in the US, you almost certainly need a HIPAA compliance programme and BAAs with your covered entity customers.
A: PHI is health information that identifies an individual and relates to past, present, or future physical or mental health, health care, or payment for health care. The 18 HIPAA identifiers are: name, address (anything more specific than state), dates (except year), phone, fax, email, SSN, medical record number, health plan beneficiary number, account number, certificate/license number, vehicle identifiers, device identifiers, URLs, IP addresses, biometric identifiers, full face photographs, and any other unique identifying number or code. If health information contains any of the 18 identifiers, it is PHI and HIPAA applies. Safe Harbor de-identification requires removing all 18 identifiers before data can be treated as non-PHI.
A: A Business Associate Agreement (BAA) is a written contract that must be executed before a covered entity shares PHI with any Business Associate. The BAA is a HIPAA-mandated document — not just a commercial nicety. It must describe permitted uses and disclosures of PHI, require the BA to implement appropriate safeguards, require reporting of security incidents and breaches, allow the covered entity to terminate the BAA and recover PHI upon violation, and prohibit the BA from further disclosures not permitted by the agreement. Cloud providers (AWS, GCP, Azure) offer BAAs for HIPAA-eligible services — but signing the BAA does not make your entire cloud environment HIPAA-compliant; only HIPAA-eligible services in your specific configuration qualify.
A: A security incident is any attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI — including phishing attempts, ransomware, misconfigured S3 buckets, and accidental disclosures. A breach is a specific type of security incident: the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule, presumed to be a reportable breach unless the covered entity or BA demonstrates through a risk assessment that there is a low probability that PHI was compromised (the 4-factor test). Breach notification timelines: individuals within 60 days; HHS simultaneously for 500+ individual breaches; HHS annually for smaller breaches; media notice for 500+ individuals in a state.
A: HIPAA civil monetary penalties follow a four-tier structure tied to culpability: unknown violation ($100–$50K/violation, $25K annual cap per category); reasonable cause ($1K–$50K, $100K cap); willful neglect corrected ($10K–$50K, $250K cap); willful neglect uncorrected ($50K/violation, $1.9M cap). The 2024 HIPAA Safe Harbor provision reduces penalties for entities that have implemented a recognised cybersecurity framework (NIST CSF, NIST SP 800-66, CIS Controls, ISO 27001, etc.) in the 12 months before the breach. Criminal HIPAA violations are referred to the Department of Justice and can result in up to 10 years imprisonment. State attorneys general can also bring parallel civil enforcement actions, compounding penalties.
HIPAA Compliance Checklist → Business Associate Agreement requirements, ePHI technical safeguards, breach notification timelines, and the 2024 HIPAA Safe Harbor for cybersecurity frameworks.
This hub was written and is maintained by an LLB, LLM-qualified international commercial lawyer, notary, and arbitrator with 20 years of active practice. The analysis draws on direct practitioner experience across UAE, EU, US, UK, and Singapore jurisdictions — not synthesis from secondary sources.