Praeferre/Frameworks/HIPAA
Security, Resilience & Assurance · United States

Health Insurance Portability and Accountability Act

The US federal law governing protected health information (PHI). Its Privacy and Security Rules set standards for how covered entities and their business associates use, disclose and safeguard health data.

REGULATORHHS Office for Civil Rights (OCR) REGIONUnited States EFFECTIVEPrivacy Rule 2003; Security Rule 2005, with ongoing updates

Who it applies to

  • Healthcare providers, health plans and healthcare clearinghouses (“covered entities”)
  • Business associates handling PHI on behalf of covered entities
  • Technology vendors processing health data under a Business Associate Agreement

Key requirements

  • Administrative, physical and technical safeguards for electronic PHI
  • Signed Business Associate Agreements with all relevant vendors
  • Breach notification to affected individuals, HHS, and in some cases the media
  • Minimum necessary access to PHI for any given purpose
  • Regular risk analysis of systems handling PHI

Maximum penaltyTiered civil penalties up to roughly $2.1 million per violation category per year, plus potential criminal charges for wilful violations

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates HIPAA compliance

Continuous monitoring, evidence and reporting for HIPAA — alongside every other framework you need to satisfy.