Summary. HIPAA is misunderstood in both directions — providers refuse to share information the rules plainly permit, and organizations holding enormous quantities of health data assume the rules do not reach them. This article sets out who is covered, what protected health information is, the disclosures permitted without authorization, the risk analysis anchoring the Security Rule, and the four-factor assessment determining whether an incident is a reportable breach. It also covers the business associate relationship where most enforcement now originates, the OCR penalty structure and what triggers a large settlement, the right of access initiative, and HIPAA's interaction with state law, Part 2 records, and reproductive health privacy.


Two scenes, both common, both wrong.

A hospital nurse tells a patient's adult daughter that she cannot discuss her father's condition "because of HIPAA." The father is conscious, oriented, and has said in the daughter's presence that he wants her involved. The Privacy Rule expressly permits the disclosure. 45 C.F.R. § 164.510(b). The refusal is not compliance; it is a misunderstanding that produced a worse outcome for the patient and no legal benefit to anyone.

Meanwhile, a wellness app collects symptom logs, medication reminders, and menstrual cycle data from four million users, sells de-identified analytics, and shares identifiers with advertising platforms through a tracking pixel embedded in its symptom questionnaire. Its privacy policy says nothing about the pixel. The company's counsel has concluded, correctly, that it is not a covered entity and has no business associate agreement with anyone — and therefore, incorrectly, that health privacy law does not apply to it.

The first organization is over-complying with a rule it has not read. The second is under-complying with a body of law that is not HIPAA — the FTC Act, the FTC's Health Breach Notification Rule, state consumer health data statutes, and wiretapping claims — but that reaches the same conduct with fewer defenses.

HIPAA is narrow in scope and specific in content. Both facts get lost.

Who is covered

Covered entities are three categories, and only three:

Health plans — insurers, HMOs, employer group health plans with 50 or more participants or administered by a third party, Medicare, Medicaid, and similar programs.

Health care clearinghouses — entities that translate health information between standard and nonstandard formats.

Health care providers who transmit health information electronically in connection with a covered transaction — claims, eligibility inquiries, referral authorizations, and the other transactions listed in 45 C.F.R. Part 162. Note the qualifier: a provider who never bills electronically and conducts no covered transaction is not a covered entity. In practice nearly all do.

Business associates are persons who create, receive, maintain, or transmit protected health information on behalf of a covered entity, or provide services to a covered entity involving PHI — billing companies, IT vendors, cloud hosts, transcription services, shredding companies, consultants, lawyers, accountants, e-prescribing gateways, health information exchanges, and personal health record vendors offering the record on behalf of a covered entity. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance, for impermissible uses and disclosures, and for breach notification to the covered entity — not merely contractually liable.

Subcontractors of business associates that handle PHI are themselves business associates, and the obligation flows down the chain indefinitely.

A conduit exception exists but is genuinely narrow: it covers entities like the postal service and internet service providers that transport information without accessing it other than randomly or infrequently. A cloud service provider that stores encrypted PHI is a business associate even if it holds no decryption key.

Hybrid entities — organizations with both covered and non-covered functions — may designate health care components and apply HIPAA only to them, with firewalls between components. Affiliated covered entities under common ownership may designate themselves a single covered entity. Organized health care arrangements permit clinically integrated participants to share a notice of privacy practices and use PHI for joint operations.

Who is not covered: employers acting as employers (employment records are excluded from PHI), life insurers, workers' compensation carriers, schools with FERPA records, most fitness and wellness apps, most consumer genetic testing companies, and law enforcement. The fact that information is health information does not make it PHI; the source determines coverage.

What is protected

Protected health information is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. It covers past, present, or future physical or mental health, the provision of care, or payment for care, where the information identifies the individual or where there is a reasonable basis to believe it can be used to identify them.

Exclusions: employment records held by a covered entity in its role as employer; FERPA education records; and information about a person deceased more than 50 years.

De-identification removes information from the rule entirely. Two methods under 45 C.F.R. § 164.514:

  • Expert determination — a qualified statistician determines the risk of re-identification is very small and documents the analysis.
  • Safe harbor — removal of 18 enumerated identifiers, including names, all geographic subdivisions smaller than a state (with a limited three-digit ZIP exception), all date elements more specific than year (and any age over 89 aggregated into a 90-or-over category), contact information, identifying numbers, biometric identifiers, full-face photographs, and any other unique identifying number, characteristic, or code — plus the absence of actual knowledge that the remaining information could identify the individual.

A limited data set — with direct identifiers removed but dates and city/state/ZIP retained — may be used for research, public health, and health care operations under a data use agreement.

The Privacy Rule

The Privacy Rule's basic architecture: PHI may be used or disclosed only as permitted or required by the rule, or with the individual's authorization.

Required disclosures: to the individual, and to HHS for enforcement.

Permitted without authorization:

  • Treatment, payment, and health care operations — the workhorse. A provider may share PHI with another provider for treatment without authorization, without a business associate agreement, and without the patient's consent. Disclosures for another entity's operations are permitted only in narrower circumstances, where both have a relationship with the individual and the disclosure is for specified operations purposes.
  • To the individual.
  • Opportunity to agree or object — facility directories, and disclosures to family, friends, and others involved in care or payment, including after death to those who were involved. If the individual is present and capable, obtain agreement or reasonably infer it from the circumstances; if not, exercise professional judgment about the individual's best interests. This is the provision the opening example ignored.
  • Incident to a permitted use or disclosure, where reasonable safeguards and minimum necessary are applied.
  • Twelve public interest and benefit categories: as required by law; public health activities; victims of abuse, neglect, or domestic violence; health oversight activities; judicial and administrative proceedings; law enforcement (with detailed sub-rules); decedents, to coroners and funeral directors; cadaveric organ donation; research, with IRB or Privacy Board waiver, or under limited preparatory and decedent provisions; to avert a serious and imminent threat; specialized government functions; and workers' compensation as authorized by law.

Minimum necessary45 C.F.R. § 164.502(b) — requires reasonable efforts to limit use and disclosure to the minimum needed for the purpose. It does not apply to disclosures to or requests by a provider for treatment, to the individual, pursuant to an authorization, required by law, or to HHS. Implementing it means role-based access, not case-by-case judgment.

Authorizations — required for marketing, for the sale of PHI, for most psychotherapy notes disclosures, and for anything else not otherwise permitted. A valid authorization has core elements: a specific description of the information, who may disclose, to whom, the purpose, an expiration date or event, the individual's signature and date, and statements about the right to revoke, conditioning of treatment, and potential redisclosure.

Marketing is defined broadly — a communication about a product or service that encourages its purchase — with exceptions for treatment communications, care coordination, and communications about the entity's own health-related products, and with an authorization required whenever the covered entity receives financial remuneration from a third party for the communication.

Individual rights — the operational heart of the rule:

  • Access to inspect and obtain a copy of PHI in a designated record set, in the form and format requested if readily producible, within 30 days (with a single 30-day extension), for a reasonable, cost-based fee limited to labor for copying, supplies, postage, and preparing a requested summary. Note that after Ciox Health, LLC v. Azar, 435 F. Supp. 3d 30 (D.D.C. 2020), the fee limitation applies to requests by the individual, and the third-party directive is limited to electronic copies of electronic PHI.
  • Amendment of inaccurate or incomplete PHI, with a right to a statement of disagreement if denied.
  • Accounting of disclosures for six years, excluding treatment, payment, and operations disclosures and several other categories.
  • Restriction requests, which the entity generally need not grant — except a request to restrict disclosure to a health plan for an item or service paid out of pocket in full, which must be honored.
  • Confidential communications by alternative means or at alternative locations.
  • Notice of privacy practices, provided at first service delivery, with acknowledgment of receipt requested, posted, and available on the website.

Right of access is the most-enforced provision in HIPAA. OCR's Right of Access Initiative has produced dozens of settlements, most against small practices, most for amounts between $3,500 and $240,000, and nearly all arising from a simple failure to send records within 30 days. If an organization does one thing, it should be to make records requests work.

The Security Rule

The Security Rule, 45 C.F.R. §§ 164.302–164.318, applies to electronic PHI and requires covered entities and business associates to ensure confidentiality, integrity, and availability of ePHI; protect against reasonably anticipated threats and impermissible uses; and ensure workforce compliance.

It is scalable and flexible — an entity may consider its size, complexity, capabilities, infrastructure, cost, and the probability and criticality of potential risks. That flexibility is genuine and frequently misused as an excuse for doing nothing.

Standards are either required or addressable. "Addressable" does not mean optional. It means the entity must assess whether the implementation specification is reasonable and appropriate, implement it if so, and if not, document why and implement an equivalent alternative measure if reasonable. An addressable specification that is neither implemented nor documented is a violation.

Administrative safeguards (§ 164.308) — the largest category and the one OCR examines first:

  • Security management process, including the risk analysis and risk management, sanction policy, and information system activity review.
  • Assigned security responsibility.
  • Workforce security — authorization, clearance, and termination procedures.
  • Information access management — access authorization, establishment, and modification.
  • Security awareness and training — reminders, malware protection, log-in monitoring, password management.
  • Security incident procedures — response and reporting.
  • Contingency plan — data backup, disaster recovery, emergency mode operation, testing, and criticality analysis.
  • Evaluation — periodic technical and nontechnical assessment.
  • Business associate contracts.

Physical safeguards (§ 164.310) — facility access controls, workstation use and security, and device and media controls including disposal, reuse, accountability, and backup.

Technical safeguards (§ 164.312) — access control (unique user identification, emergency access, automatic logoff, encryption and decryption), audit controls, integrity controls, person or entity authentication, and transmission security.

Organizational requirements, policies, procedures, and documentation (§§ 164.314, 164.316) — retain documentation for six years from creation or last effective date, review and update periodically.

The risk analysis

The risk analysis is the foundation of the entire rule, and its absence or inadequacy is the most frequently cited failure in OCR enforcement. § 164.308(a)(1)(ii)(A).

An adequate risk analysis is not a checklist and not a vendor questionnaire. It requires:

  1. A complete inventory of ePHI — every system, application, device, medium, and location where ePHI is created, received, maintained, or transmitted, including vendors, backups, mobile devices, and shadow IT.
  2. Identification of threats and vulnerabilities to each.
  3. Assessment of current security measures.
  4. Determination of likelihood and impact.
  5. Determination of risk level.
  6. Documentation.
  7. Periodic review and update — after any material change to operations, technology, or environment.

The recurring defect is scope: a risk analysis that covers the electronic health record and omits the imaging system, the research database, the billing vendor, the shared drives, and the laptops. OCR settlements repeatedly describe an entity that had "a risk analysis" that was not enterprise-wide.

Encryption is addressable, not required — but it is also the safe harbor in the Breach Notification Rule. PHI encrypted consistent with NIST guidance is not "unsecured PHI," and its loss is not a breach requiring notification. The practical consequence: encrypting laptops, mobile devices, portable media, and data at rest converts the most common category of incident from a reportable breach into a non-event. Very few decisions in this area have a better return.

The Breach Notification Rule

45 C.F.R. §§ 164.400–414. A breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule, which is presumed to be a breach unless the entity demonstrates a low probability that the PHI has been compromised, based on a risk assessment of at least four factors:

  1. The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or to whom the disclosure was made.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

Note the burden: the presumption is that it is a breach, and the entity must document its analysis to overcome it.

Three exceptions are outside the definition entirely: unintentional acquisition by a workforce member acting in good faith within scope of authority, with no further impermissible use; inadvertent disclosure between authorized persons at the same entity or organized health care arrangement, with no further impermissible use; and a disclosure where the entity has a good faith belief the recipient could not reasonably have retained the information.

Notification obligations:

  • To individuals — without unreasonable delay and no later than 60 days after discovery, by first-class mail or email if agreed, with substitute notice for insufficient contact information. Content is prescribed: what happened, what information was involved, steps individuals should take, what the entity is doing, and contact procedures.
  • To HHS — for breaches affecting 500 or more individuals, contemporaneously with individual notice; for smaller breaches, in an annual log within 60 days after the end of the calendar year.
  • To the media — for breaches affecting more than 500 residents of a state or jurisdiction, to prominent media outlets serving that area.
  • By business associates to covered entities — without unreasonable delay and no later than 60 days after discovery, though most business associate agreements shorten this substantially, and should.

Discovery is the first day the breach is known, or by exercising reasonable diligence would have been known, to any person other than the person who committed it — which imputes a workforce member's knowledge to the entity.

Ransomware. OCR's position is that a ransomware attack encrypting ePHI is a presumed breach, because the malware has acquired the information, unless the entity demonstrates low probability of compromise under the four factors. The fact that the entity restored from backup and paid nothing does not end the analysis.

Enforcement

No private right of action. HIPAA creates none, and courts have consistently so held. Acara v. Banks, 470 F.3d 569 (5th Cir. 2006).

That does not mean no civil liability. Many state courts use HIPAA as the standard of care in negligence, negligent infliction, and breach of confidentiality claims — Byrne v. Avery Center for Obstetrics & Gynecology, P.C., 314 Conn. 433 (2014) is the leading example — and state consumer protection and privacy statutes provide independent causes of action. State attorneys general may enforce HIPAA directly under HITECH.

Civil monetary penalties are tiered by culpability, 42 U.S.C. § 1320d-5, with annual caps per identical violation, indexed for inflation:

  • No knowledge (the entity did not know and would not have known by exercising reasonable diligence) — lowest tier.
  • Reasonable cause and not willful neglect — second tier.
  • Willful neglect, corrected within 30 days — third tier.
  • Willful neglect, not corrected — highest tier.

The 30-day cure window for willful neglect is worth noting: prompt correction moves the violation down a tier.

Criminal penalties, 42 U.S.C. § 1320d-6, prosecuted by the Department of Justice: knowing wrongful disclosure, up to one year; under false pretenses, up to five years; with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm, up to ten years. These are brought against individuals — employees who snoop or sell records — far more often than against organizations.

Most resolutions are settlements with a corrective action plan and monitoring, typically two years. The pattern in the larger settlements is consistent: no enterprise-wide risk analysis, no encryption on mobile devices, no business associate agreement, inadequate access controls or audit logging, and failure to respond to a known vulnerability.

OCR audits and investigations arise from breach reports, individual complaints, media reports, and periodic audit programs. The single most common complaint is a denied or delayed access request.

Business associate agreements

Most enforcement now touches the vendor relationship, and most business associate agreements are treated as a formality.

Required content, 45 C.F.R. § 164.504(e): permitted uses and disclosures; a prohibition on other uses; appropriate safeguards including Security Rule compliance; breach and security incident reporting; flow-down to subcontractors; making PHI available for access, amendment, and accounting; making practices available to HHS; return or destruction at termination; and termination for material breach.

What a good agreement adds:

  • A short breach notification deadline — 24 to 72 hours, not 60 days, because the covered entity's own 60-day clock runs from the business associate's discovery in many circumstances and it needs time to act.
  • Cooperation in investigation and notification, and allocation of notification costs, which for a large incident is the entire economic question.
  • Specific security requirements — encryption at rest and in transit, multifactor authentication, logging, minimum necessary access, vulnerability management, personnel screening.
  • Audit and assessment rights, or at minimum delivery of SOC 2 Type II reports.
  • Subcontractor approval rather than unrestricted flow-down.
  • Indemnification and a carve-out from the liability cap for privacy and security breaches — the single most negotiated commercial term, and the one that decides who actually bears the loss.
  • Cyber insurance requirements with proof of coverage.
  • Data location and return provisions, including format and timing.
  • Prohibition on de-identification and secondary use unless expressly permitted. Vendors routinely reserve the right to use "de-identified" data for their own purposes; whether the covered entity wants that is a business decision, but it should be a decision.

Enter the agreement before disclosure, and maintain an inventory. Settlements for disclosing PHI to a vendor with no agreement in place are routine and entirely avoidable.

Beyond HIPAA

Preemption. HIPAA sets a floor. More stringent state laws — those providing greater privacy protection or greater individual rights — are not preempted. 45 C.F.R. Part 160, Subpart B. State laws on mental health, HIV status, genetic information, minors' records, and breach notification frequently exceed HIPAA and must be layered on.

42 C.F.R. Part 2 governs records of federally assisted substance use disorder programs and has historically been far more restrictive than HIPAA — generally requiring written consent for disclosure, including for treatment. The 2024 final rule aligned Part 2 substantially with HIPAA, permitting a single consent for all future treatment, payment, and operations uses, aligning breach notification and enforcement, and adding a patient right to an accounting. It remains a distinct regime with its own consent and redisclosure notice requirements.

Reproductive health privacy. The 2024 Privacy Rule amendments prohibit the use or disclosure of PHI to investigate or impose liability on a person for seeking, obtaining, providing, or facilitating lawful reproductive health care, and require an attestation that a request for such PHI is not for a prohibited purpose. The rule's status has been subject to litigation; verify its current operation before relying on it, and note that state law in this area is moving quickly in both directions.

The FTC and non-covered health data. The Health Breach Notification Rule, 16 C.F.R. Part 318, applies to vendors of personal health records and related entities that are not HIPAA-covered, requiring notification of unauthorized disclosure — and the FTC has read "breach of security" to include voluntary disclosures to advertisers, producing enforcement actions against app developers and telehealth companies. Section 5 of the FTC Act reaches deceptive privacy representations independently.

Tracking technologies. Pixels, session-replay tools, and advertising SDKs on patient-facing web pages and portals transmit identifiers and URLs to third parties. OCR issued guidance treating these transmissions as disclosures of PHI in many circumstances; a court vacated part of that guidance as applied to unauthenticated public pages. The litigation exposure is independent of the regulatory question: dozens of class actions have been filed under state wiretapping and video privacy statutes over healthcare website tracking. Inventory every tag on every patient-facing page, and remove what is not necessary.

State consumer health data laws — Washington's My Health My Data Act, Nevada's analogue, and the health provisions of comprehensive state privacy statutes — reach consumer health data held by entities HIPAA does not cover, some with a private right of action.

What to actually do

  1. Complete a real, enterprise-wide risk analysis, and update it annually and on material change. Nothing else in this article matters as much.
  2. Encrypt laptops, mobile devices, removable media, backups, and transmissions. It is the breach safe harbor.
  3. Make the access process work. Thirty days, cost-based fee, requested format. This is where enforcement lives.
  4. Inventory business associates, execute agreements before disclosure, and negotiate the breach clock, cost allocation, and liability carve-out.
  5. Implement role-based access and audit logging, and actually review the logs. Snooping cases are found in logs or not at all.
  6. Train on scenarios, not statutes — the family-member disclosure, the phone request, the phishing email, the lost device.
  7. Write and test an incident response plan with the four-factor assessment built into it, and pre-select breach counsel and a forensic firm.
  8. Audit tracking technologies on every patient-facing property.
  9. Layer state law onto the HIPAA baseline, particularly for mental health, HIV, genetic, and minors' records.
  10. Document everything, and keep it six years.

Conclusion

HIPAA rewards operational discipline and punishes documentation gaps. The Privacy Rule permits more sharing than most workforces believe and less than most vendors would like. The Security Rule is flexible but not permissive, and its flexibility only protects an organization that documented the reasoning. The Breach Notification Rule presumes the worst and requires the entity to prove otherwise, in writing, within a clock that starts when any employee learns of the problem.

Two facts drive most outcomes. The risk analysis is the foundation of everything, and OCR's settlements read as a decade-long catalogue of entities that did not have one that covered their whole environment. And the right of access — the least technical obligation in the rule — has generated more enforcement actions than every sophisticated security theory combined.

Finally, HIPAA's boundaries are not the boundaries of health privacy law. The organizations facing the largest current exposure are frequently those that correctly concluded HIPAA did not apply to them and stopped the analysis there.

Frequently asked questions

Can a doctor tell my spouse about my condition? Yes, if you agree, or if you do not object when given the opportunity, or if the provider reasonably infers from the circumstances that you do not object. 45 C.F.R. § 164.510(b). If you are incapacitated, the provider exercises professional judgment about whether disclosure is in your best interests. "HIPAA forbids it" is almost always wrong.

Does a provider need my permission to send records to a specialist? No. Treatment disclosures between providers require no authorization, no consent, and no business associate agreement.

Is a HIPAA authorization required for an employer to see medical information? Yes, if the information comes from a covered entity. Note that records the employer holds as an employer — FMLA certifications, ADA accommodation records, workers' compensation files — are not PHI in the employer's hands, though the ADA and other statutes impose their own confidentiality requirements.

Can I be charged for my own records? Yes, but only a reasonable, cost-based fee limited to labor for copying, supplies, postage, and preparing a requested explanation or summary. Search and retrieval costs are not chargeable to the individual. Fees are the most common source of access complaints.

Is a text message to a patient a HIPAA violation? Not inherently. The Security Rule requires reasonable safeguards for transmission; OCR has recognized that individuals may request communications by unencrypted means after being warned of the risk, and the provider may honor that request. Document the warning and the request.

Does HIPAA apply to my fitness tracker or symptom app? Almost never. The FTC's Health Breach Notification Rule, Section 5 of the FTC Act, and state consumer health data laws generally do.

Do I have to report every lost laptop? Only if it held unsecured PHI. An encrypted laptop is not a breach. That distinction is worth the cost of encryption by itself.

How long must records be kept? HIPAA requires six years of retention for its own documentation — policies, risk analyses, authorizations, notices, and breach assessments. Medical record retention itself is governed by state law and payor requirements, which vary substantially.

A short case study

A 40-physician multispecialty group discovers that a former medical assistant accessed 340 patient records over eleven months with no treatment relationship, including records of several local public figures.

Day 1 — containment. Access is terminated. The audit log is preserved. Counsel is engaged, and the forensic review is directed by counsel to support privilege.

Days 2–10 — scope. The log review establishes exactly which records were opened and when. Because the group had configured audit logging and retained it, the scope is knowable — the single control that turns an unbounded incident into a bounded one.

Days 10–20 — assessment. The four-factor analysis is documented. Factor one: full records including diagnoses and identifiers, weighing toward compromise. Factor two: a workforce member with no authorization, weighing toward compromise. Factor three: actual viewing is established by the logs. Factor four: mitigation is limited — the employee signed an attestation of non-disclosure, but there is evidence of at least one verbal disclosure. Conclusion: reportable breach.

Days 20–45 — notification. Individual notices are mailed with the prescribed content and a credit monitoring offer. Because 340 individuals are affected, the breach is logged for the annual HHS submission rather than reported contemporaneously, and no media notice is required. State breach law is checked separately; two states in which patients reside require attorney general notification at lower thresholds, and those are made.

Parallel tracks. The employee is referred for potential prosecution under 42 U.S.C. § 1320d-6. The group's cyber policy is noticed. A state licensing complaint is anticipated.

Remediation. Role-based access is narrowed so that clinical staff can reach only records within their assigned care teams; break-the-glass access requires a documented reason and generates an alert; monthly log reviews are assigned to a named person with a documented procedure; and the risk analysis is updated to reflect the newly identified vulnerability.

Outcome. OCR opens an investigation on the breach report, reviews the risk analysis, the access controls, the log review procedure, and the remediation, and closes with technical assistance rather than a settlement. The determinative facts are that the group had logging in place, found the problem, assessed it correctly, notified on time, and fixed the control. An identical incident at an organization without audit logging is unbounded in scope, unreportable with confidence, and far more likely to end in a corrective action plan.


Related articles

This article is provided for general informational purposes and does not constitute legal advice. HIPAA obligations depend on an organization's specific role, systems, and state law, and several rules discussed here have been subject to litigation and amendment. Consult qualified healthcare privacy counsel before relying on any analysis in this article.