HIPAA compliance

HIPAA Compliance Requirements: The Complete List of What the Law Actually Requires

HIPAA never publishes its requirements as a single list, which is why most organizations discover them one audit finding at a time. This guide assembles the complete set in one place: who must comply, what the Privacy, Security, and Breach Notification Rules each demand, the business associate agreement and documentation duties that investigators check first, and the order in which to build a program that satisfies all of it.

July 19, 2026

Who must comply and where the requirements live

Search for HIPAA compliance requirements and you will mostly find two kinds of pages: explainers that describe one rule in depth, and vendor checklists that skip the law entirely. Neither answers the question people are actually asking, which is what, exactly, does HIPAA require of my organization, in full, with nothing left out. Part of the difficulty is that the law itself never publishes such a list. The requirements are spread across three regulations codified in 45 CFR Parts 160, 162, and 164, written at different times, aimed at different problems, and enforced by the same agency. An organization can memorize the Privacy Rule and still fail an investigation over a missing risk analysis, or run flawless security and still get penalized for ignoring a patient's records request. This guide assembles the complete requirement set in one place, organized the way the regulations organize it, with the citation for each duty so you can verify everything against the source text. It is written for the practice manager, compliance owner, or business associate executive who needs the whole map, not another tour of one neighborhood. Where a topic deserves a deeper treatment than a survey can give, we point to it, but every binding requirement category appears here, because the first rule of HIPAA compliance is that you cannot meet an obligation you never learned existed.

Start with who carries these obligations, because HIPAA binds organizations by category, not by industry. The Health Insurance Portability and Accountability Act of 1996 is the statute, but nearly every operational requirement comes from regulations the Department of Health and Human Services issued under it. Those regulations apply to covered entities, defined at 45 CFR 160.103 as healthcare providers who transmit health information electronically in connection with standard transactions such as claims and eligibility checks, health plans including insurers and employer group health plans, and healthcare clearinghouses that translate claim formats. They apply equally to business associates: any person or company that creates, receives, maintains, or transmits protected health information while performing a service for a covered entity, from billing firms and IT vendors to cloud hosts, shredding services, and consultants. Since the HITECH Act of 2009 and the 2013 Omnibus Rule, business associates are directly liable under the Security Rule, the Breach Notification Rule, and significant parts of the Privacy Rule, and their subcontractors inherit the same status down the chain. Two boundary facts prevent common confusion. Employers acting as employers are not covered entities, and employment records are expressly excluded from protected health information, so HIPAA does not govern what a manager may ask about sick leave. And a technology company with no covered entity relationship, like a consumer fitness app, sits outside HIPAA entirely, though other privacy laws may reach it.

Next, the map of the rules themselves, because knowing which regulation houses which requirement is half of compliance literacy. The Privacy Rule, at 45 CFR Part 164 Subpart E, governs uses and disclosures of protected health information in every form and creates patient rights over records. The Security Rule, Subpart C, requires administrative, physical, and technical safeguards for electronic protected health information. The Breach Notification Rule, Subpart D, dictates who must be told, and how fast, when unsecured PHI is compromised. Those are the three rules every workforce member touches, and our three rules of HIPAA guide walks their logic as a set. Completeness requires naming the rest of the family. The Enforcement Rule at Part 160 sets investigation procedures and the civil penalty structure. The Transactions and Code Sets standards and the identifier rules at Part 162 standardize electronic claims and assign identifiers like the NPI; providers meet them mostly through clearinghouses and billing software, but they are why the phrase five HIPAA rules appears in some trainings. Finally, HIPAA is a floor, not a ceiling. Under the preemption rules at 45 CFR 160.203, state laws that are more protective of privacy survive, which is why Texas HB 300 imposes training deadlines stricter than the federal ones and several states require faster breach notice. A complete compliance program checks state law after satisfying the federal baseline, never instead of it.

Privacy Rule requirements: uses, disclosures, and patient rights

The Privacy Rule's core requirement is a single mechanic with a long tail: protected health information may not be used or disclosed except as the rule permits or as the individual authorizes in writing. The permissions do the daily work. Treatment, payment, and healthcare operations, the trio shortened to TPO, lets clinicians hand off care, billers submit claims, and quality staff review charts without patient signatures. Disclosures to the individual are always permitted, and disclosures required by other law, for public health, or to avert serious threats occupy a defined list at 45 CFR 164.512. Everything outside the permissions needs a valid authorization under 45 CFR 164.508, with specific required elements, and marketing, most sales of PHI, and most psychotherapy notes disclosures need one even when other permissions might seem to apply. Some situations call for an informal middle ground: facility directories and disclosures to family involved in care run on an opportunity to agree or object under 45 CFR 164.510. Incidental disclosures, like a name overheard at a pharmacy counter, are not violations when reasonable safeguards were in place. Overlaying every permitted use is the minimum necessary standard at 45 CFR 164.502(b): use, request, and disclose only what the task requires, implemented through role-based access policies required by 45 CFR 164.514(d). Minimum necessary does not apply to treatment disclosures or to the patient's own access, a nuance that trips up front desk staff in both directions.

The Privacy Rule is also where patients hold enforceable rights, and these rights generate more enforcement actions against ordinary providers than any exotic security failure. The right of access at 45 CFR 164.524 entitles individuals to inspect and obtain copies of their records in the form and format they request, generally within 30 days, for no more than a reasonable cost-based fee. The Office for Civil Rights has run a dedicated Right of Access Initiative since 2019 and has settled dozens of cases against practices that stalled, overcharged, or simply never responded; it remains the cheapest violation to avoid and one of the most common to commit. Individuals may also request amendment of incorrect records under 45 CFR 164.526, receive an accounting of certain disclosures under 45 CFR 164.528, request restrictions on sharing under 45 CFR 164.522, including a restriction the provider must honor when the patient pays for a service in full out of pocket and asks that it not go to their health plan, and request confidential communications at an alternate address or number. Wrapping all of this is the Notice of Privacy Practices required by 45 CFR 164.520: a plain-language document describing uses, disclosures, and rights, distributed at first service, posted prominently, and acknowledged in writing where required. If your notice was last revised before your current EHR existed, that is a finding waiting to be written.

Beyond patient-facing duties, the Privacy Rule imposes administrative requirements at 45 CFR 164.530 that investigators check early because they are easy to verify. Every covered entity must designate a privacy official responsible for the program and a contact for complaints. Every covered entity must train all workforce members on its privacy policies as necessary for their functions, train new members within a reasonable period after joining, and retrain when material changes occur; training is not a suggestion, it is a named regulatory requirement, and the documentation of who completed it is what proves compliance. Organizations must maintain appropriate administrative, technical, and physical safeguards for PHI in all forms, which is how paper charts and hallway conversations stay regulated even though the Security Rule only reaches electronic data. They must provide a complaint process, apply and document sanctions against workforce members who violate policies, refrain from retaliating against anyone who exercises a right or files a complaint, and never require individuals to waive their rights as a condition of treatment or coverage. Then comes the requirement that quietly decides investigations: under 45 CFR 164.530(j), policies, notices, complaint dispositions, sanction records, and other required documentation must be retained for six years from creation or last effective date. In an OCR review, the safeguard you cannot document is treated as the safeguard you do not have.

Security Rule requirements: safeguards for electronic PHI

The Security Rule converts these principles into a system-building mandate for electronic PHI, and its administrative safeguards at 45 CFR 164.308 are where every program starts. The engine is the risk analysis required at 45 CFR 164.308(a)(1)(ii)(A): an accurate and thorough assessment of risks and vulnerabilities to all ePHI the organization creates, receives, maintains, or transmits, wherever it lives. A missing or stale risk analysis is the most cited failure in OCR's enforcement history, and its companion, risk management at 164.308(a)(1)(ii)(B), requires actually implementing measures that reduce the identified risks to a reasonable and appropriate level, a duty OCR has made an explicit enforcement priority. The remaining administrative standards form the program's skeleton: a designated security official at 164.308(a)(2); workforce security procedures at 164.308(a)(3), including authorization, supervision, and termination procedures so departed employees lose access the day they leave; information access management at 164.308(a)(4) aligning system permissions with job roles; a security awareness and training program for the entire workforce at 164.308(a)(5), covering reminders, malicious software, log-in monitoring, and password management; security incident procedures at 164.308(a)(6) to identify, respond to, and document incidents; a contingency plan at 164.308(a)(7) with data backup, disaster recovery, and emergency mode operation components; and periodic evaluation at 164.308(a)(8) whenever environment or operations change. Notice that training appears here a second time: HIPAA requires it twice, once for privacy and once for security.

The physical safeguards at 45 CFR 164.310 govern the tangible layer: facility access controls that limit who can physically reach systems holding ePHI, workstation use and workstation security policies that keep screens away from public view and sessions locked, and device and media controls that track hardware holding ePHI through its lifecycle. Disposal is the classic trap: drives, copiers, and phones must have ePHI rendered unrecoverable before leaving your control, with sanitization following NIST guidance or physical destruction, because retired copier hard drives full of patient scans are a recurring enforcement story. The technical safeguards at 45 CFR 164.312 govern the systems themselves: access control with unique user identification for every person, emergency access procedures, automatic logoff, and encryption of stored data; audit controls that record and examine activity in systems containing ePHI; integrity protections against improper alteration or destruction; person or entity authentication; and transmission security for data moving across networks. The regulation names no products and no protocols, but the practical bar rises with the threat landscape: multi-factor authentication and encryption at rest and in transit are now the de facto standard of care, demanded by OCR resolution agreements and cyber insurers alike, and a proposed Security Rule update published in January 2025 would make them explicitly mandatory. As of this writing no final rule has issued, but building toward that baseline now is both cheaper and more defensible than waiting.

Two structural features of the Security Rule decide how the safeguards apply to you, and both are widely misunderstood. First, implementation specifications come in two types. Required specifications must be implemented, full stop. Addressable specifications, encryption among them, must be implemented if reasonable and appropriate for your environment; if you conclude otherwise, 45 CFR 164.306(d) requires you to document the assessment and implement an equivalent alternative where reasonable. Addressable has never meant optional, and organizations that treated it that way have funded some of OCR's largest settlements after losing unencrypted laptops. The rule's flexibility provision at 164.306(b) works the same way: your size, complexity, and resources scale how much you must do, never whether you must do it. Second, the documentation requirements at 45 CFR 164.316 apply to everything above. Policies and procedures must exist in written form, be retained six years from creation or last effective date, be available to the people who must follow them, and be reviewed and updated as conditions change. Combined with the Privacy Rule's parallel six-year duty, this means HIPAA compliance is evidenced, not asserted: the risk analysis, the remediation plan, the training records, the access reviews, and the incident log are the compliance program as far as any investigator is concerned.

Breach notification, business associates, and penalties

The Breach Notification Rule at 45 CFR 164.400 through 164.414 supplies the requirements that activate when protection fails. An impermissible acquisition, access, use, or disclosure of unsecured PHI is presumed to be a reportable breach unless the organization demonstrates, through a documented risk assessment of at least the four factors in 45 CFR 164.402, that there is a low probability the information was compromised: what the data was, who received it, whether it was actually acquired or viewed, and how well the risk was mitigated. Unsecured is a defined term, and it creates the single most valuable safe harbor in HIPAA: PHI encrypted to the standards in HHS guidance is not unsecured, so a stolen laptop with intact full-disk encryption is not a reportable breach at all. When a breach is reportable, individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery, with specific required content. Breaches affecting 500 or more individuals must be reported to HHS contemporaneously and to prominent media outlets in the affected state, which is how organizations end up on the public HHS breach portal. Smaller breaches accumulate in an annual log submitted to HHS within 60 days of year end. Business associates must notify the covered entity under 45 CFR 164.410, and the contract should set that deadline well inside the 60-day clock, because the covered entity's timeline keeps running while the vendor drafts its letter.

Business associate agreements are a compliance requirement in their own right, not a formality attached to other duties. Before any PHI flows to a vendor performing a covered function, 45 CFR 164.502(e) and 164.308(b) require a written contract containing the elements listed at 45 CFR 164.504(e): the permitted uses and disclosures, the requirement to apply Security Rule safeguards, breach and incident reporting obligations, flow-down of the same terms to subcontractors, cooperation with individual rights requests, and return or destruction of PHI at termination where feasible. The requirement runs down the chain: a billing company's offshore transcription subcontractor needs a BAA with the billing company, and each party is directly liable for its own violations. The recurring failure mode is not a badly drafted agreement but a missing one: the IT firm with admin access to the EHR, the cloud storage account someone opened with a corporate card, the analytics vendor receiving appointment data. A narrow conduit exception covers entities that merely transport data without persistent access, like the postal service; it does not cover cloud hosts, and HHS has said so explicitly. An annual vendor inventory that asks who touches PHI, and matches each name to a signed agreement, is the control that catches this before an investigator does.

Enforcement is what gives every requirement above its weight, so the enforcement facts belong in the requirements list. OCR opens investigations from patient complaints, from the breach reports the notification rule forces you to file, and from its own compliance reviews, which means a breach is usually also an audit of everything else on this page. Civil penalties under 45 CFR 160.404 scale across four culpability tiers, from violations the organization could not reasonably have known about, through reasonable cause, to corrected willful neglect, to uncorrected willful neglect, with per-violation amounts and annual caps adjusted for inflation each year and the top tier reaching into seven figures per violation category. The structure rewards speed: correcting a violation within 30 days of knowing about it can keep a case in a lower tier, and for violations not involving willful neglect can support eliminating the penalty entirely, which is why a live remediation plan with named owners and dates is itself a de facto requirement. Knowing misuse of identifiable health information can also be referred to the Department of Justice for criminal prosecution, with penalties up to ten years imprisonment when PHI is used for commercial advantage or malicious harm, and state attorneys general hold parallel civil authority under HITECH. The pattern across recent enforcement is stable and instructive: right of access failures, missing risk analyses, and unmanaged vendors, all requirements that cost far less to meet than to violate.

Building a program that meets every requirement

Turning the full requirement set into a program is a sequencing problem, and the defensible order is consistent whether you are a two-provider practice or a national vendor. Designate the privacy official and security official first, because every later step needs an owner. Inventory where PHI lives and moves, in systems, on paper, and through vendors, because every subsequent control is scoped by that inventory. Run the risk analysis against it; our free HIPAA risk assessment tool walks the Security Rule standards as structured questions and produces a scored gap list you can work from. Convert the findings into a written remediation plan with owners, dates, and interim controls, ordered by risk. Write or refresh the policy set, covering privacy practices, security safeguards, sanctions, and incident response, and date every document. Execute business associate agreements for every vendor the inventory surfaced. Publish and distribute the Notice of Privacy Practices. Train the entire workforce and capture completion evidence per person. Build the breach playbook with the four-factor assessment template and notification deadlines pre-calculated, and test the backup and recovery plan before an incident tests it for you. Then schedule the loop: annual risk analysis refresh, annual training, periodic access and log reviews, and reevaluation whenever systems or operations change. Our HIPAA compliance checklist guide turns this sequence into a working document with owners and proof attached to each item.

Step back from the detail and the requirements compress into one sentence: know where PHI is, control who touches it, write down what you did, and tell the right people quickly when something goes wrong. Every citation in this guide is a variation on those four duties, and the requirement that makes the other three achievable is the one HIPAA states twice: train your workforce, and keep proof. Untrained staff are how permitted disclosures become violations, how phishing emails become breaches, and how patient requests age past their deadlines, which is why training records are among the first documents OCR requests in any investigation. If you own compliance for a team, our HIPAA certification course covers the Privacy Rule, the Security Rule, and breach response in the depth this guide surveys, takes about two hours, and issues verifiable certificates that satisfy the documentation requirement for every workforce member, with team management for assigning seats and tracking completion across a practice or company. If you want to gauge where you stand first, the free practice test takes ten minutes and shows you the gaps. The requirements are extensive, but they are finite, and an organization that works the list in order, keeps its evidence, and reruns the loop each year is not just compliant on paper. It is the organization an investigator closes the file on.


Recommended resources

Keep exploring the topic.

Use the related training, compliance, and documentation pages when you need the next practical step after this guide.

Related HIPAA guides

Related guides

Other HIPAA guides worth reading.

Stay on the same workflow thread with adjacent articles from the resource library.