Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is HIPAA? The Plain-English Guide for Business Owners

July 14, 2026

When business owners ask what is HIPAA, they usually want to know exactly how this massive federal regulation impacts their daily operations, their IT budgets, and their legal liability. HIPAA stands for the Health Insurance Portability and Accountability Act, a 1996 US federal law. Its administrative simplification rules protect the privacy and security of protected health information (PHI) and are enforced by the HHS Office for Civil Rights (OCR).

The original purpose of HIPAA was right there in the name. The law was designed to improve the portability of health insurance coverage for workers between jobs. However, to make that digital transfer of medical records possible, the government needed a standardized way to keep that data secure. That requirement birthed the privacy and security framework we know today.

Over the years, the HIPAA law explained in government documents has evolved into the definitive security standard for the entire United States healthcare industry.

The scope is broad. For a medical practice, a dental office, or a specialized clinic operating in Chicagoland, HIPAA compliance requirements dictate how you handle patient data, how you configure your computers, and who you are allowed to hire as vendors. It is not a suggestion or a set of best practices. It is a strict regulatory framework.

LeadingIT has worked inside this framework for over a decade. We have helped Illinois practices meet these strict requirements since 2010, serving roughly 200 organizations from our offices in Woodstock and Manteno. We see firsthand that compliance is an ongoing state you maintain and can evidence.

There is no shortcut you can purchase. There is no official HIPAA certified status for a business or an IT vendor; the only federal health it certification program that exists certifies software for interoperability, not an organization’s overall HIPAA compliance. You cannot buy a certificate to make the liability go away. You have to build the right processes, implement the right technology, and document everything.

Key Takeaways

  • HIPAA (the Health Insurance Portability and Accountability Act) is a 1996 federal law enforced by the HHS Office for Civil Rights (OCR) that protects the privacy and security of protected health information (PHI).
  • There is no official “HIPAA certified” status for a business or an IT vendor. Compliance is an ongoing state you build, maintain, and document, not a one-time purchase.
  • The law rests on three pillars: the Privacy Rule, the Security Rule, and the Breach Notification Rule.
  • HIPAA applies to two kinds of organizations: covered entities (providers, health plans, clearinghouses) and business associates (vendors like IT providers, billing companies, and EHR vendors) that handle PHI on their behalf.
  • Risk analysis failures have been the common thread running through nearly every HIPAA settlement HHS OCR has announced in 2025.

What Does HIPAA Protect?

To understand the rules, you first need a clear protected health information PHI definition. PHI is individually identifiable health information held or transmitted in any form. When that data lives on a computer, a server, or in the cloud, it is called electronic PHI (ePHI). This includes electronic health record (EHR) data, patient emails, server backups, and digital file shares.

The law is very specific about what makes health data identifiable. The Department of Health and Human Services (HHS) recognizes 18 identifiers that link medical data to a specific person, including:

  • A patient name
  • A home address
  • Dates of treatment
  • Phone numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Biometric identifiers

If a practice removes all 18 of these identifiers from a dataset, they reach a safe harbor state. This de-identifies the data, meaning it is no longer considered PHI and is no longer restricted by HIPAA rules.

HIPAA protects specific health data held by specific organizations. Here is what the law reaches and what it does not.

Data TypeCovered by HIPAA?Governed By
Patient medical records at a doctor’s officeYesHIPAA Privacy Rule and Security Rule
Employment records including doctor notes for sick leaveNoEmployment law; specifically excluded from the PHI definition under 45 CFR 160.103
Student health records at a public schoolNoFERPA (Family Educational Rights and Privacy Act)
Consumer health app and fitness tracker dataNoFTC Health Breach Notification Rule, unless the app is a HIPAA business associate handling data on behalf of a covered entity
Life insurance health dataNoState insurance regulation, not HIPAA

The Three Rules That Matter

The actual text of the law is incredibly dense, but the operational reality for a clinic or a managed IT provider boils down to three primary sections. These are the three rules that matter for compliance work. Every policy you write, every software tool you buy, and every vendor you hire will tie back to one of these three pillars.

RuleWhat it CoversWho’s ResponsibleKey Requirement or Deadline
Privacy RuleHow PHI may be used and disclosed, and the patient’s rights to view, copy, and correct their own recordsEvery covered entity handling patient dataWritten patient authorization required for any use beyond treatment, payment, or healthcare operations
Security RuleAdministrative, physical, and technical safeguards for electronic PHI (ePHI)The organization’s formally named Security OfficerA documented, current risk analysis, the most-requested document during an OCR investigation
Breach Notification RuleWhat must happen when unsecured PHI is exposed, lost, or stolenThe covered entity or business associate that experienced the breachAffected individuals notified within 60 days; breaches of 500+ also reported to HHS and local media

The HIPAA Privacy Rule Overview

This rule dictates that a practice may only share patient data for treatment, payment, or healthcare operations unless they have explicit written authorization from the patient. It also establishes the fundamental rights of the patient to view, copy, and request corrections to their medical records.

For a business owner, complying with this rule means training your front desk staff on what they can say over the phone, ensuring doctors do not discuss cases in public waiting rooms, and having strict protocols for verifying the identity of anyone requesting a copy of medical records.

The HIPAA Security Rule Overview

Safeguard TypeRequirements
AdministrativeDocumented risk analysis, comprehensive security policies, workforce training, access management procedures, and a formally named Security Officer
PhysicalFacility access controls, device controls, secure workstation policies, and strict protocols for media disposal
TechnicalAccess controls with unique user IDs, encryption of ePHI at rest and in transit, detailed audit logging, user authentication, and transmission security

A documented, current risk analysis is the absolute foundation of this rule, and OCR investigators consistently ask to see it early in an investigation.

The HIPAA Breach Notification Rule

The Breach Notification Rule dictates exactly what must happen when unsecured PHI is exposed, lost, or stolen. Here is what that timeline looks like in practice:

There is a crucial technical exception built into this rule. Properly encrypted data whose decryption key was not compromised is generally not considered unsecured PHI. Therefore, if a clinician loses a laptop that is fully encrypted, that loss is usually not a reportable breach.

Who Does HIPAA Apply To?

A common misconception among business owners is that medical regulations only apply to doctors and hospitals. The reality of who does HIPAA apply to is much broader. The law creates a web of liability that extends far beyond the walls of a clinical practice. The government divides regulated businesses into two distinct categories, and both carry significant legal obligations.

The HIPAA Covered Entity Definition

The first category is the covered entity. A covered entity is defined as a healthcare provider, a health plan, or a healthcare clearinghouse that transmits any health information in electronic form in connection with a covered transaction.

  • Healthcare providers: doctors, clinics, psychologists, dentists, chiropractors, nursing homes, and pharmacies, if they bill Medicare or transmit claims electronically
  • Health plans: health insurance companies, HMOs, company health plans, and government programs like Medicare and Medicaid
  • Healthcare clearinghouses: entities that process nonstandard health information into a standard electronic format or vice versa

These organizations are the primary targets of the law. They are responsible for the data they collect. They must designate a Privacy Officer and a Security Officer. Existing staff members may hold these roles, but they must be formally named as the accountable owners of the compliance program. The covered entity is ultimately responsible for ensuring that patient rights are respected and that the data remains secure.

Business Associates and the Vendor Ecosystem

The second category catches thousands of small businesses completely by surprise. The law requires covered entities to protect their data, but modern medical practices cannot operate in a vacuum. They need it companies to manage their servers. They need billing companies to process claims. They need specialized software vendors to host their electronic health records.

This brings us to the business associate. A business associate is any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf. This category includes:

  • IT providers that manage the network for a dental or medical practice
  • Accounting firms with access to patient billing records
  • Billing companies, EHR vendors, and cloud hosting services
  • Commercial shredding services that destroy old paper charts

If your business falls into any of these categories, you are a business associate.

The BAA and the Chain of Liability

Under the law, business associates are directly liable under the Security and Breach Notification Rules. This means the federal government can fine an IT provider directly for failing to implement technical safeguards or for failing to report a breach. The liability does not stop at the clinic door.

To enforce this relationship, the law requires a specific legal contract. A Business Associate Agreement (BAA) is a contract required before a business associate may access PHI. It makes the vendor legally responsible for protecting the data and specifies permitted uses, required safeguards, breach reporting timelines, and subcontractor obligations. A missing or unsigned BAA is itself a regulatory violation and is a recurring finding in OCR enforcement actions.

The requirement for a BAA also creates a chain of liability. If a business associate hires a subcontractor to help them store or process the protected data, that subcontractor also needs to sign a BAA. This flow-down requirement ensures that the data remains legally protected no matter how many vendors are involved in the technology stack.

Covered Entity vs. Business Associate at a Glance

Covered EntityBusiness Associate
What it isA healthcare provider, health plan, or healthcare clearinghouse that transmits health information electronicallyA vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf
ExamplesDoctors, clinics, psychologists, dentists, chiropractors, nursing homes, pharmacies, health insurers, HMOs, clearinghousesIT providers, billing companies, accounting firms, EHR vendors, shredding services, cloud hosting services
Required compliance roleMust designate a Privacy Officer and a Security OfficerMust sign a Business Associate Agreement (BAA) before accessing PHI
Liability under the lawUltimately responsible for ensuring patient rights are respected and data remains secureDirectly liable under the Security and Breach Notification Rules, independent of the covered entity

Understanding this vendor ecosystem is critical for any practice owner. You cannot simply hand your data to a software company and assume your compliance obligations are met. You must vet your vendors, demand signed agreements, and ensure they understand their own regulatory liability.

For a closer look at how this vendor relationship works and how to determine your exact legal status, you can review our detailed guide on who must comply with HIPAA.

Chain of liability diagram showing a covered entity, its business associate, and any downstream subcontractors, each linked by a required signed Business Associate Agreement

Recognizing Protected Health Information in Your Network

While the law clearly defines what data is restricted, identifying that data across a modern computer network takes work. Electronic protected health information does not just live inside your formal electronic health record system. It lives in email attachments, calendar appointments, hidden spreadsheet columns, and temporary download folders.

If a front desk worker emails a specialist about a patient, that email contains regulated data. If you export a billing report to your local desktop, you just created a new location that requires strict security controls. To ensure your team knows exactly what to look for, you can review our detailed breakdown of the 18 HIPAA identifiers of PHI.

Removing these specific data points is the only way to achieve a safe harbor state where the information is fully de-identified and no longer subject to federal restrictions.

HIPAA Enforcement HHS OCR and the Cost of Non-Compliance

The government does not rely on the honor system. HIPAA enforcement HHS OCR activities are rigorous, highly documented, and increasingly focused on technical failures. The HHS Office for Civil Rights is the federal agency responsible for investigating violations and levying fines against both covered entities and business associates.

Investigations are typically triggered in one of three ways:

  1. OCR receives complaints from patients, disgruntled former employees, or competing businesses; federal regulation allows any person who believes a covered entity or business associate is out of compliance to file one.
  2. Any reported breach affecting 500 or more individuals automatically draws regulatory scrutiny.
  3. OCR conducts periodic audit programs where they select organizations for review regardless of their breach history.

When an investigator opens a case, they do not start by looking at your firewall. The audit process is mostly a massive documentation request. Investigators will demand to see:

  • Your current risk analysis
  • Your written security policies
  • Your employee training records
  • Your system access logs
  • Your signed Business Associate Agreements
  • Your incident response records

If you cannot produce this documentation, you will fail the audit.

Every single HIPAA settlement the government announced in the first eight months of 2025 (16 out of 16 cases) traced back to one fundamental failure: the organizations lacked a proper, documented risk analysis.

The financial consequences for failing these audits are severe. Federal civil penalties are tiered by culpability, ranging from a “did not know” standard all the way up to willful neglect, and are adjusted annually for inflation. They currently run from about $145 per violation at the low end up to more than $73,000 per violation.

The annual cap for willful-neglect violations can exceed $2.1 million per violation category. These figures are set by federal regulation and adjusted for inflation, so they represent an order of magnitude rather than a fixed quote.

Culpability LevelPer-Violation RangeAnnual CapNotes
Did Not Know~$145 to ~$73,000~$36,000 to ~$2.1 millionLowest tier; organization could not have reasonably known of the violation
Reasonable Cause~$145 to ~$73,000~$36,000 to ~$2.1 millionOrganization knew or should have known but did not act with willful neglect
Willful Neglect, Corrected~$14,500 to ~$73,000~$145,000 to ~$2.1 millionViolation corrected within 30 days of discovery
Willful Neglect, Not Corrected~$73,000+~$2.1 million+Highest tier; organization knowingly failed to comply and did not correct
NoteAll figures adjusted annually for inflation per the Federal Register. These represent an order of magnitude, not a fixed quote. See the cited Federal Register inflation adjustment notice for current amounts.

Furthermore, these civil penalties only cover negligence and administrative failures. Criminal penalties for the knowing misuse of patient data are handled entirely separately, under a distinct federal statute, 42 U.S.C. § 1320d-6, and are prosecuted by the Department of Justice rather than OCR.

The sheer scale of modern cyber threats makes these penalties highly relevant for every practice owner. For example, the 2024 Change Healthcare hack exposed the health data of 192.7 million people. This incident stands as the largest healthcare data breach in US history, finalized in reports to HHS OCR on July 31, 2025.

You must take the threat of a breach seriously. To understand exactly how these fines are applied during an investigation, you can read our guide on HIPAA violations and penalties.

What Compliance Actually Involves for a Small Practice

Many practice owners mistakenly believe that buying a specific software tool makes them compliant. As stated earlier, there is no official HIPAA certified status for a business or an IT vendor. Compliance is an ongoing state you maintain and can evidence. You cannot buy a certificate to make the liability disappear.

Meeting your HIPAA compliance requirements means building a culture of security. it requires a blend of administrative policies, physical office security, and rigorous technical controls. You must formally designate a Privacy Officer and a Security Officer to take accountable ownership of the program.

You must also train your workforce regularly, conduct a thorough risk analysis every year, and document exactly how you plan to fix the vulnerabilities you find.

On the technical side, the Security Rule splits these controls into required or addressable specifications, and OCR expects you to implement essentially all of them or document a reasonable, equally effective alternative:

  • Strict access controls with unique user IDs for every employee
  • Multi-factor authentication across your network
  • Encryption of ePHI both at rest on your servers and in transit across the internet
  • Detailed audit logging to track who accesses patient records
  • Tested backups to ensure you can recover patient data during a ransomware attack

This is where a specialized managed IT provider steps in. LeadingIT operates the technical half of HIPAA for our clients. We implement the required access controls, multi-factor authentication, encryption, logging, tested backups, and continuous network monitoring.

We sign Business Associate Agreements with our practice clients as a standard operational procedure. Most importantly, we help produce the exact technical documentation an auditor will ask for when they investigate your systems. You can explore how we handle this burden through LeadingIT’s HIPAA compliance services.

See Where You Stand

Free 2-minute HIPAA Risk-Check: 8 plain-English questions, your audit-readiness level and the gaps to fix. No sign-up to see your result. free HIPAA compliance checklist

Frequently Asked Questions

What exactly is a HIPAA violation?

A violation occurs when a covered entity or business associate fails to comply with the Privacy, Security, or Breach Notification Rules. Common examples include failing to conduct a risk analysis, allowing unauthorized access to patient records, or exposing unencrypted electronic health data. A missing Business Associate Agreement with an IT vendor is also a direct regulatory violation.

What are the three main rules of HIPAA?

The three main rules are the Privacy Rule, the Security Rule, and the Breach Notification Rule. The Privacy Rule governs how health data is used and disclosed while establishing patient rights. The Security Rule mandates administrative, physical, and technical safeguards for electronic data, and the Breach Notification Rule dictates how to report exposed data.

Why do we need HIPAA?

The law was originally created in 1996 to improve the portability of health insurance when workers change jobs. To make that digital transfer of medical records possible, the government needed a standardized way to keep the data secure. Today, we need these rules to protect sensitive patient data from cyberattacks, ransomware, and unauthorized disclosures.

Are abortions protected under HIPAA?

The Privacy Rule protects all individually identifiable health information, including records related to reproductive health care and abortions. Covered entities may disclose this information only for purposes the Privacy Rule already permits, such as treatment, payment, healthcare operations, patient authorization, or another recognized legal exception, the same rules that apply to any other protected health information. The HHS Office for Civil Rights enforces strict limitations on sharing reproductive health data for investigative purposes.

What are three common HIPAA violations?

Three of the most common enforcement findings involve a failure to conduct a comprehensive risk analysis, a failure to sign Business Associate Agreements with vendors, and the exposure of unencrypted electronic health records. In fact, every government settlement announced in the first eight months of 2025 traced back to lacking a proper risk analysis.

Is it a felony to violate HIPAA?

Most violations result in civil penalties ranging from roughly $100 to $50,000 per incident, which are handled by the HHS Office for Civil Rights. However, criminal penalties for the knowing misuse or theft of protected health information do exist. These severe cases can result in felony charges and are prosecuted separately by the Department of Justice.

What is an example of a HIPAA violation?

A classic example is a medical practice losing a laptop that contains unencrypted electronic health records. Because the data was not properly encrypted, the loss constitutes a breach of unsecured PHI. Other examples include an employee snooping on the medical records of a celebrity or a practice hiring an IT provider without signing a Business Associate Agreement.

What information can be shared without violating HIPAA?

Health information can be shared without patient authorization if it is used specifically for treatment, payment, or healthcare operations. Additionally, if a practice removes all 18 specific identifiers to reach a safe harbor state, the data is officially de-identified. De-identified data is no longer considered protected health information and falls outside these federal restrictions.

Ready to Secure Your Practice?

LeadingIT helps Illinois practices become and stay compliant by managing the complex technical controls required by federal law. We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno, delivering secure it you can actually rely on.

If you are ready to upgrade your security and protect your patient data, you can contact us online, book a call with our experts, or call us directly at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.