Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Health Insurance Portability & Accountability Act (HIPAA)

The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996. As part of HIPAA, Congress called for regulations promoting administrative simplification of healthcare transactions as well as regulations ensuring the privacy and security of patient information. HIPAA is designed to protect confidential healthcare information through improved security standards and federal privacy legislation. It defines requirements for storing patient information before, during and after electronic transmission. It also identifies compliance guidelines for critical business tasks such as risk analysis, awareness training, audit trail, disaster recovery plans and information access control and encryption.

Covered Entities (CEs) must comply with the HIPAA Security Rule. This applies to health plans (e.g. HMOs and group health plans), health care clearinghouses (e.g. billing companies), or health care providers (e.g. doctors, dentists and hospital) who transmit or store any Electronic Protected Health Information (EPHI). CEs must maintain reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of their EPHI against any reasonably anticipated risks.

CEs must take appropriate measures to mitigate all reasonably-anticipated risks to their EPHI. They must balance their resources and business requirements against the risks to their EPHI. All members of a CE's workforce, including management and those who work from home, must comply with the rule.

CEs must formally document and approve a wide variety of security processes, policies, and procedures. Additionally, CEs must provide regular security training and awareness to its workforce and revise its security policies and procedures as needed.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about HIPAA and HITECH compliance:

Who does the HIPAA Security Rule apply to?
The HIPAA Security Rule applies to covered entities and their business associates. Covered entities are health plans, health care clearinghouses, and health care providers that transmit health information in electronic form. Business associates are vendors and partners that handle electronic protected health information on a covered entity's behalf, and the HITECH Act of 2009 made them directly liable for complying with the Security Rule.
What is ePHI under the HIPAA Security Rule?
ePHI, or electronic protected health information, is protected health information that is maintained in or transmitted by electronic media. Protected health information is individually identifiable health information about a person's health condition, health care, or payment for health care. The Security Rule protects only ePHI, so unlike the Privacy and Breach Notification Rules, it does not apply to PHI kept on paper or communicated verbally.
Who is responsible for enforcing the HIPAA Security Rule?
The HHS Office for Civil Rights (OCR) enforces the HIPAA Security Rule. OCR has enforced the Privacy Rule since 2003 and took on Security Rule enforcement in 2009. The HITECH Act, signed in February 2009, strengthened enforcement by creating 4 categories of violations with increasing penalty tiers based on culpability, and by making business associates directly liable for Security Rule compliance.
Has the HIPAA Security Rule been updated recently?
Not in final form. HHS published a proposed rule on January 6, 2025 that would remove the distinction between required and addressable specifications, require encryption of ePHI at rest and in transit and multi-factor authentication with limited exceptions, require a technology asset inventory and network map, and require procedures to restore certain systems within 72 hours. As of October 2026, no final rule has been published, and HHS states that the current Security Rule remains in effect.
What documentation does the HIPAA Security Rule require?
Under 45 CFR 164.316, covered entities and business associates must keep their security policies and procedures in written form, which may be electronic, and keep written records of any action, activity or assessment the rule requires, such as the risk analysis. That documentation must be retained for 6 years from its creation or the date it was last in effect, whichever is later. You can use ComplianceForge's Cybersecurity Risk Assessment (CRA) Template and our editable Policies & Standards Templates to support this documentation.