Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The HIPAA Privacy Rule Explained: What Your Business Must Protect and Why

July 13, 2026

The HIPAA privacy rule governs how protected health information may be used and disclosed and gives patients rights over their medical records. Enforced by the HHS Office for Civil Rights (OCR), this rule dictates exactly who can see patient data, how it can be shared, and under what circumstances a business must keep it private.

It applies to protected health information in any form, whether written on paper, spoken aloud, or stored electronically.

HIPAA is the Health Insurance Portability and Accountability Act, a 1996 US federal law. Its administrative simplification rules were designed to protect the privacy and security of health data while allowing the necessary flow of information to provide high quality healthcare.

For business owners and practice managers, understanding what is the HIPAA privacy rule is the foundation of a compliant operation. Many practice owners conflate this specific rule with the entirety of HIPAA, but it is just one piece of a larger regulatory framework.

Many practices struggle to translate these legal requirements into daily workflows. A brief HIPAA privacy rule summary is helpful, but you must know how to apply it. This guide breaks down what the rule requires, how it differs from other regulations, and what your practice must do to protect patient data while running an efficient business.

Privacy Rule vs. Security Rule Distinctions

Business owners often confuse the different parts of the regulation. When you look at the HIPAA privacy and security rule, the distinction is straightforward. The rules that matter for compliance work are the Privacy Rule, the Security Rule, and the Breach Notification Rule. Here is how they compare at a glance.

RuleWhat it GovernsKey Requirement
Privacy RuleHow PHI may be used and disclosed, in all forms: paper records in filing cabinets, oral conversations at the front desk, and digital files on your serverSets the legal boundaries on who is allowed to look at patient data and gives patients rights over their records
Security RuleSafeguards specifically for electronic PHI (ePHI)Requires three safeguard categories: administrative, physical, and technical
Breach Notification RuleWhat must happen when unsecured PHI is exposedAffected individuals must be notified without unreasonable delay and no later than 60 days after discovery

The Security Rule is where your IT provider does most of the hands-on work, so its three safeguard categories are worth spelling out:

  • Administrative safeguards include a documented risk analysis, written policies, workforce training, access management, and naming a Security Officer.
  • Physical safeguards include facility access controls, device controls, workstation security, and proper media disposal.
  • Technical safeguards require access controls with unique user IDs, encryption of ePHI at rest and in transit, audit logging, authentication, and transmission security.

If you want to dive deeper into the technical side, read the HIPAA Security Rule explained.

A few Breach Notification details matter beyond that 60 day deadline. Breaches affecting 500 or more individuals must also be reported to HHS and prominent media outlets in the affected area within that 60 day window. Smaller breaches are reported to HHS annually. Properly encrypted data whose key was not compromised is generally not considered unsecured PHI, so its loss is usually not a reportable breach.

What Constitutes Protected Health Information

Before you can protect data, you need to know what qualifies. Protected health information (PHI) is individually identifiable health information held or transmitted in any form. Electronic PHI (ePHI) is simply the electronic subset of this data. This electronic subset includes electronic health record data, email communications, server backups, and network file shares.

HHS recognizes 18 identifiers that can make health information identifiable. Use this list as a quick check against the data sitting in your own systems:

  • Names
  • Geographic addresses smaller than a state
  • All dates directly related to an individual
  • Phone numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Biometric identifiers

If you need to understand exactly what to look for in your systems, review the 18 HIPAA identifiers of PHI.

Removing all 18 identifiers is known as the safe harbor method, which successfully de-identifies the data. Once data is properly de-identified, it is no longer restricted by the privacy regulations. This is often done when practices want to use historical data for broad statistical analysis without risking patient privacy.

Permitted Uses and Disclosures

The core of the regulation revolves around PHI use and disclosure rules. A covered entity may not use or disclose PHI except as the rule permits or requires. The primary goal is to protect patient privacy without interfering with the delivery of quality healthcare.

The most common HIPAA permissible disclosures fall under treatment payment healthcare operations TPO. This means a practice can share patient data to treat the patient, bill for services, or run standard healthcare operations without needing special patient authorization.

  1. Treatment: This covers the provision, coordination, or management of healthcare. A primary care physician can share a patient medical history with a specialist to coordinate care, or send diagnostic reports and lab results to another provider involved in the patient’s treatment.
  2. Payment: This encompasses the activities of healthcare providers to obtain reimbursement for their services. A clinic can send diagnostic codes to a health insurance provider to process claims and receive payment.
  3. Healthcare Operations: This includes administrative, financial, legal, and quality improvement activities. A hospital can use patient data for internal quality assessment, staff training, and business planning.

Whenever you share data for these purposes, you must follow the minimum necessary standard HIPAA dictates. You cannot send a patient’s entire medical history if the recipient only needs a single test result to complete their job.

How the minimum necessary standard works in practice: your billing staff needs access to billing codes, but they do not need access to the physician’s detailed clinical notes. The standard requires you to evaluate your workflows and limit unnecessary access to PHI at every point where it changes hands.

Exceptions and Disclosures Without Authorization

For PHI disclosure without authorization outside of standard operations, the rule outlines specific public interest exceptions. These HIPAA privacy rule exceptions allow entities to balance individual privacy with the broader needs of society. Information can be shared without patient authorization in these situations:

  • Public health reporting, such as tracking infectious diseases or reporting adverse events to the FDA.
  • Law enforcement requests for specific data under certain legal conditions, such as identifying a suspect or reporting a crime on the premises.
  • Specific research purposes, provided an institutional review board approves the data use and ensures privacy protections are in place.

Understanding these exceptions is vital for your administrative staff. When a request for records comes in from outside your standard treatment network, your team must know exactly when they are legally permitted to release the data and when they must require written patient authorization.

PHI Disclosure Decision Guide

Use the following decision flow when your staff needs to determine whether protected health information may be shared:

QuestionAction
Is this for treatment, payment, or healthcare operations?Share with the minimum necessary data. No patient authorization needed.
If not TPO: do you have written patient authorization?Share per the authorization scope.
If no authorization: does a public-interest exception apply? (public health, law enforcement, IRB-approved research)Share with the minimum necessary data.
If none of the above appliesDo not disclose.

When the Privacy Rule Does NOT Apply

The Privacy Rule governs most health information, but there are three specific cases where it does not apply at all. These are distinct from the permitted disclosures above: the rule simply does not reach these categories:

  1. Properly de-identified data. Health information that has had all 18 identifiers removed using the safe harbor method or an expert determination is no longer PHI and falls outside the rule entirely.
  2. Employment records. When a covered entity holds health information in its role as an employer (for example, records related to an employee’s sick leave, workers’ compensation, or fitness-for-duty evaluations), those records are governed by employment law, not the Privacy Rule.
  3. Education records covered by FERPA. Health records maintained by an educational institution that are subject to the Family Educational Rights and Privacy Act are exempt from the Privacy Rule, even if the institution is otherwise a covered entity.

Patient Rights Under the Rule

The regulation is not just about locking data away in secure servers. It grants specific patient rights under HIPAA that every practice must honor and facilitate. Each right carries a matching operational duty for your team.

Patient RightWhat Your Practice Must Do
Access their own medical recordsProvide requested records in a timely manner. You can charge a reasonable fee for copying and mailing the records, but you cannot charge for the effort of searching for the data.
Request corrections or amendmentsKeep a documented process for reviewing and responding to these requests, such as fixing an incorrect diagnosis or a wrong date of birth in a chart.
Request an accounting of disclosuresProduce a record showing exactly who else has viewed or received their information outside of standard treatment, payment, and operations.
Receive a notice of privacy practicesProvide the notice on the first visit, ask patients to acknowledge receipt, and make it available upon request or on your website.

The accounting of disclosures right has a direct it implication: your systems must be capable of tracking and logging every time a record is exported or shared externally. The notice of privacy practices carries weight too. This document explains how the practice uses medical information, the patient rights regarding that data, and the practice’s legal duties to protect it.

Who Must Comply With the HIPAA Privacy Rule

You must know exactly who the HIPAA privacy rule applies to. The law applies to covered entities and their business associates.

A HIPAA privacy rule covered entity includes healthcare providers, health plans, and healthcare clearinghouses. If you are a doctor, dentist, chiropractor, or pharmacy transmitting health information electronically for standard transactions, you are a covered entity.

business associate, covered entity, subcontractor HIPAA privacy rule who must comply

Business Associates and the BAA Chain

Covered entities cannot operate alone. They rely on vendors to manage their technology, handle their billing, and store their files. Any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf is a business associate. This includes IT providers, billing companies, EHR vendors, shredding services, and cloud services. Business associates are directly liable under the Security and Breach Notification Rules.

What a Business Associate Agreement does: a BAA is a contract required before a business associate may access PHI. It makes the vendor legally responsible for protecting the data and specifies permitted uses, safeguards, breach reporting, and subcontractor obligations. A missing or unsigned BAA is itself a violation and a frequent focus of OCR enforcement actions.

Subcontractors of business associates also need BAAs, a requirement known as flow-down. If your EHR vendor hires a cloud hosting provider, that provider must sign a BAA too, and the chain of compliance extends all the way down.

The BAA Chain: Who Answers to Which Rules

These three tiers define the compliance relationship and which rules each party is directly liable under:

RoleExamplesDirectly Liable Under
Covered EntityHealthcare provider, health plan, healthcare clearinghousePrivacy Rule, Security Rule, Breach Notification Rule
Business AssociateIT provider, billing company, EHR vendor, cloud serviceSecurity Rule, Breach Notification Rule
SubcontractorHosting provider, shredding vendor, backup service (subcontracted by a business associate)Security Rule, Breach Notification Rule

Each arrow in the chain requires a signed BAA. A covered entity signs a BAA with its business associate, who must flow down a BAA to any subcontractor that touches PHI. A missing BAA at any tier is itself a violation.

Operational Meaning for Your Practice and IT Vendors

Your it architecture must respect the boundaries set by the privacy regulations. If the rule says only certain staff can view specific records, your IT provider must configure the technical safeguards to enforce those rules.

Access controls and audit logging are non-negotiable. Every employee must have a unique user ID: shared logins are strictly prohibited. Your systems must employ audit logging to track exactly who accesses what data and when. Your email systems must be encrypted to ensure that when you send PHI to another provider, it cannot be intercepted. HIPAA requires formally designating a Privacy Officer and a Security Officer. Existing staff may hold these roles, but they must be the named accountable owners of the compliance program. They are responsible for ensuring your policies match your actual practices and that your staff receives regular training.

How OCR investigations work. OCR investigations are typically triggered by a complaint filed by any person who believes a covered entity or business associate is not complying with HIPAA. They can also be triggered by a reported breach.

Breaches affecting 500 or more individuals draw scrutiny automatically. The government also selects organizations under the OCR audit program. The audit process is mostly a documentation request, so treat this list as your audit readiness checklist. Auditors will ask for each item:

  • Your risk analysis
  • Written policies
  • Training records
  • Access logs
  • BAAs
  • Incident records

A documented, current risk analysis is the foundation of your compliance program and one of the first things OCR asks for in an investigation. The consequences of ignoring this are severe. Most HIPAA settlements the government announced in 2025 traced back to one common failure: having no proper risk analysis.

Data breaches are also escalating in scale and impact. The 2024 Change Healthcare hack exposed the health data of 192.7 million people, making it the largest healthcare data breach in US history.

Federal civil penalties run roughly $100 to $50,000 per individual violation, with an annual cap that reaches about $1.5 million per violation category for willful neglect. These penalties are tiered by culpability, ranging from “did not know” through willful neglect. The figures are set by federal regulation and adjusted for inflation, so treat them as the order of magnitude, not a fixed quote. Knowing misuse can also trigger separate criminal penalties, including fines and imprisonment, under federal law.

Remember that there is no official HIPAA certified status for a business or an IT vendor. Compliance is an ongoing state you maintain and can evidence, not a certificate you buy. You must continuously monitor your systems, train your staff, and update your risk analysis to protect your patients and your business.

See Where You Stand

Get a free 2 minute HIPAA Risk Check featuring 9 plain English questions that reveal your audit readiness level and the gaps you need to fix. There is no sign up required to see your result. free 2-minute HIPAA risk assessment

Frequently Asked Questions

What are the three main rules of HIPAA?

The three rules that matter for compliance work are the Privacy Rule, the Security Rule, and the Breach Notification Rule. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule governs safeguards for electronic data, while the Breach Notification Rule dictates what happens when unsecured data is exposed.

What is a HIPAA violation?

A HIPAA violation occurs when a covered entity or business associate fails to comply with any standard of the Privacy, Security, or Breach Notification rules. Common examples include unauthorized disclosures of patient data, failing to conduct a proper risk analysis, or failing to sign a Business Associate Agreement with a vendor. Penalties for violations can reach about $1.5 million per violation category annually for willful neglect.

What is PHI under the HIPAA privacy rule?

Protected health information (PHI) is individually identifiable health information held or transmitted in any form, including written, oral, and electronic records. HHS recognizes 18 specific identifiers that make health information identifiable, such as names, dates, phone numbers, and biometric identifiers. Removing all 18 identifiers successfully de-identifies the data.

What information can be shared without violating HIPAA?

A practice can share patient data without special authorization for treatment, payment, and healthcare operations. The rule also includes public interest exceptions for law enforcement requests, public health reporting, and specific research purposes. In all cases, you must adhere to the minimum necessary standard by only sharing the exact data needed for the task.

What is an example of a HIPAA violation?

A very common example is failing to perform a documented risk analysis, which is the foundation of a compliance program. In fact, every HIPAA settlement the government announced in the first eight months of 2025 traced back to a missing or improper risk analysis. Another frequent violation involves failing to report a breach within the required 60 days.

Protect Your Practice and Patient Data

LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois practices meet HIPAA since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno.

We operate the technical half of compliance: access controls, multifactor authentication, encryption, and tested backups. We sign BAAs with our practice clients as standard and help produce the documentation an auditor asks for.

If you need help managing these requirements, explore LeadingIT’s HIPAA compliance services, contact us with your questions, or book a call at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.