HIPAA — NAXS Labs Framework Reference
Framework Reference

HIPAA

Health Insurance Portability and Accountability Act — federal law governing how protected health information is handled by covered entities and their business associates.

Issued by HHS / Office for Civil Rights (OCR) Enacted 1996 — Security Rule effective 2003 Applies to Covered entities and business associates Enforced by OCR under HHS

What HIPAA Is

HIPAA is federal law enacted in 1996 that governs how protected health information (PHI) is handled. It applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically — and their business associates: vendors and service providers that handle PHI on behalf of a covered entity.

HITECH (Health Information Technology for Economic and Clinical Health Act), enacted in 2009, strengthened HIPAA enforcement, extended direct liability to business associates, and established the federal breach notification requirements that are now codified in the HIPAA Breach Notification Rule. Before HITECH, only covered entities were directly liable under HIPAA. Business associates are now directly subject to the Security Rule and its penalties.

The Three Rules

Privacy Rule

Governs how PHI can be used and disclosed. Covers all forms of PHI — oral, written, and electronic. Patients have the following rights:

  • Access their records
  • Request amendments to inaccurate or incomplete records
  • Request restrictions on use and disclosure
  • Receive an accounting of disclosures
  • Receive a Notice of Privacy Practices

Security Rule

Governs how electronic PHI (ePHI) must be protected. Applies to covered entities and, since HITECH, directly to business associates. Controls are classified as either required (mandatory, no exceptions) or addressable (must implement or document a justified equivalent alternative — addressable does not mean optional).

Breach Notification Rule

Governs notification obligations following a breach of unsecured PHI. Covered in detail in the Breach Notification section below.

PHI Definition

Protected health information is any individually identifiable health information. HIPAA defines 18 identifiers that, when associated with health information, create PHI:

CategoryIdentifiers
DemographicName, address, dates (except year), phone numbers, fax numbers, email addresses
Identity NumbersSSN, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers
Device & NetworkVehicle identifiers and serial numbers, device identifiers and serial numbers, web URLs, IP addresses
BiometricBiometric identifiers (fingerprints, voiceprints), full-face photographs and comparable images
OtherAny other unique identifying number, characteristic, or code

Some of these identifiers may look like general PII, but they become PHI when associated with health information. An IP address alone is PII. An IP address linked to a patient’s EHR access log is PHI.

The Three Safeguard Categories

Administrative Safeguards — §164.308

Policies, procedures, and management controls

  • Security Management Process (Required) — Risk analysis and risk management. The most commonly cited HIPAA violation in OCR enforcement actions. Must be conducted, documented, and updated regularly.
  • Assigned Security Responsibility (Required) — Designate a security official responsible for developing and implementing security policies.
  • Workforce Security (Addressable) — Authorization, supervision, and termination procedures for workforce members with access to ePHI.
  • Information Access Management (Addressable) — Role-based access aligned to the minimum necessary standard.
  • Security Awareness and Training (Addressable) — Training all members on security policies. Sanctions for violations must be documented and enforced.
  • Security Incident Procedures (Required) — Documented incident response and reporting procedures.
  • Contingency Plan (Addressable) — Data backup, disaster recovery, emergency mode operations, and testing procedures.
  • Evaluation (Required) — Periodic assessment of how well security policies meet Security Rule requirements.
  • Business Associate Agreements (Required) — BAAs with every vendor that creates, receives, maintains, or transmits ePHI.
Physical Safeguards — §164.310

Physical access to facilities and devices

  • Facility Access and Controls (Addressable) — Limit physical access to systems containing ePHI. For cloud-hosted systems, this is covered by cloud providers through SOC 2 or ISO 27001 compliance reports — but a BAA must be in place.
  • Workstation Use (Required) — Policies for proper use of workstations that access ePHI, including physical surroundings.
  • Workstation Security (Required) — Physical safeguards for workstations accessing ePHI — screen positioning, privacy screens, physical locks where appropriate.
  • Device and Media Controls (Required) — Policies governing receipt, removal, disposal, and re-use of hardware and media containing ePHI. Includes documented procedures for wiping or destroying media.
Technical Safeguards — §164.312

Technology controls protecting ePHI

  • Access Controls (Required) — Unique user IDs, emergency access procedures, automatic logoff, and encryption/decryption mechanisms.
  • Audit Controls (Required) — Mechanisms to record and examine access and other activity in systems that use ePHI.
  • Integrity Controls (Addressable) — Electronic mechanisms to confirm ePHI has not been improperly altered or destroyed.
  • Transmission Security (Addressable) — Encryption in transit for ePHI transmitted over electronic communications networks. In practice, TLS is the standard implementation.

Business Associate Agreements

A BAA is a required contract between a covered entity and any business associate that handles PHI. It is also required between a business associate and any subcontractor that handles PHI on its behalf — the obligation flows downstream through the entire chain.

A CSP that processes or stores encrypted ePHI on behalf of a business associate is itself a business associate, even if it lacks the encryption key. Lacking the encryption key does not exempt a CSP from business associate status and obligations.

At minimum, a BAA must specify:

  • Parties involved and the permitted uses and disclosures of PHI
  • Applicability and scope of the agreement
  • Required safeguards the business associate must maintain
  • Breach notification obligations and timelines
  • Agents and subcontractors — downstream BAA requirements
  • Access to records for compliance review
  • Return or destruction of PHI at contract termination — if destruction is not feasible due to backup systems, the BAA must extend privacy protections for the life of the backup
  • Termination terms and interpretation provisions

Breach Notification

A breach is the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy. Any such incident is presumed to be a reportable breach unless a low probability of compromise can be demonstrated through a 4-factor risk assessment.

The 4-Factor Risk Assessment

FactorWhat it evaluates
1. Nature and extent of PHISensitivity of the data (financial, clinical, SSNs) and likelihood of re-identification
2. Who received or used the PHIThe unauthorized person’s capacity to cause harm. Disclosure to another HIPAA-covered entity is less risky than to an unknown party.
3. Whether PHI was actually acquired or viewedA lost encrypted laptop that was never accessed poses lower risk than a stolen unencrypted device
4. Extent to which risk has been mitigatedActions taken to reduce harm — remote wiping a device, receiving credible assurances the data was destroyed

Notification Requirements

  • Notify affected individuals within 60 days of discovery — all breaches regardless of size
  • Notify HHS/OCR within 60 days of discovery for breaches affecting 500 or more individuals
  • For breaches affecting fewer than 500 individuals: report to HHS/OCR within 60 days of the end of the calendar year in which the breach was discovered
  • If the breach affects 500 or more individuals in a state: notify prominent media outlets within 60 days of discovery — the report also appears on the OCR public breach portal (the Wall of Shame)
  • The clock starts at discovery, not when the breach occurred
Unsecured PHI

PHI that has not been rendered unusable, unreadable, or indecipherable through encryption (AES-256) or by destroying the media. If encrypted data is breached but the encryption key is not compromised, it is not a reportable breach. This is why device encryption is not optional hygiene for a covered entity — it is the difference between a reportable breach and a non-event.

Individual Rights Under the Privacy Rule

1

Right to Be Informed

Individuals must receive a Notice of Privacy Practices explaining how their PHI is used and disclosed.

2

Right of Access

Individuals can request a copy of their PHI. Covered entities generally must provide access within 30 days.

3

Right to Amend

Individuals can request corrections to inaccurate or incomplete PHI.

4

Right to Restrict

Individuals can request restrictions on how their PHI is used or disclosed. Covered entities may deny requests in some cases.

5

Right to Accounting of Disclosures

Individuals can request a record of non-routine disclosures of their PHI for the past six years.

6

Right to Confidential Communications

Individuals can request that covered entities communicate with them by alternative means or at alternative locations.

HITECH

The Health Information Technology for Economic and Clinical Health Act, enacted in 2009, made four significant changes to HIPAA:

  • Increased penalties — Four tiers based on culpability, up to $1.9 million per violation category per year
  • Mandatory enforcement for willful neglect — OCR must investigate and penalize willful neglect violations. Previously discretionary.
  • Direct liability for business associates — Business associates are now directly subject to the HIPAA Security Rule, not just through their BAA. OCR can investigate and fine them directly.
  • Breach notification — HITECH created the federal breach notification requirements that are now codified in the HIPAA Breach Notification Rule. No federal breach notification requirement existed for health data before HITECH.

Penalties and Enforcement

Civil Penalties

Four-tier structure

Fines range from $100 to $50,000 per violation, up to $1.9 million per violation category per year. Tier based on culpability:

  • Did not know — $100–$50,000
  • Reasonable cause — $1,000–$50,000
  • Willful neglect, corrected — $10,000–$50,000
  • Willful neglect, not corrected — $50,000
Criminal Penalties

For knowingly obtaining or disclosing PHI

  • Up to $50,000 and one year imprisonment
  • Up to $100,000 and five years imprisonment if under false pretenses
  • Up to $250,000 and ten years imprisonment if for commercial advantage, personal gain, or malicious harm
Most cited violation

Risk analysis is the most commonly cited HIPAA violation in OCR enforcement actions. Not encryption, not access controls — the risk analysis. Without it, an organization cannot demonstrate that its safeguard decisions were grounded in anything other than guesswork. OCR will ask for the risk analysis as the first document in any investigation.

Official Sources

NAXS Labs
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart