HIPAA
HIPAA Security Rule Compliance in 2026: The Complete Guide
A senior-practitioner's HIPAA guide covering the Security Rule, Privacy Rule, Breach Notification Rule, 2026 NPRM changes, risk analysis, business associate agreements, and OCR enforcement realities.
Quick Answer
HIPAA (Health Insurance Portability and Accountability Act) compliance requires covered entities and business associates to implement administrative, physical, and technical safeguards protecting electronic Protected Health Information (ePHI). The HIPAA Security Rule (45 CFR Part 164 Subpart C) mandates a written risk analysis, documented policies, workforce training, and 18 standards with 42 implementation specifications enforced by HHS Office for Civil Rights (OCR).
Key Takeaways
- HIPAA has three core rules: Security (ePHI safeguards), Privacy (PHI use and disclosure), and Breach Notification (60-day patient notification for breaches of unsecured PHI).
- The 2024–2026 HIPAA Security Rule NPRM proposes mandatory encryption, MFA, network segmentation, and 72-hour vulnerability patching — removing much of the current 'addressable' flexibility.
- A current, written risk analysis is the #1 finding in every OCR investigation — no risk analysis, no HIPAA compliance, period.
- Business Associate Agreements (BAAs) are contractual, not technical — but OCR now investigates whether the BAA is operationally enforced, not just signed.
- OCR settlements in 2024–2025 ranged from $35K to $4.75M and increasingly target ransomware-driven breaches at small and mid-sized providers.
What HIPAA actually requires
HIPAA is a U.S. federal law enacted in 1996 and substantially expanded by the HITECH Act (2009) and the Omnibus Rule (2013). It regulates the protection of Protected Health Information (PHI) — any individually identifiable health information — held or transmitted by covered entities and their business associates.
Compliance is defined by three rules enforced by the HHS Office for Civil Rights (OCR): the Security Rule (ePHI safeguards), the Privacy Rule (PHI use and disclosure), and the Breach Notification Rule (patient and government notification when unsecured PHI is compromised).
Who must comply
Two populations are directly regulated:
Covered Entities — health plans, health-care clearinghouses, and health-care providers who transmit health information electronically in connection with standard transactions.
Business Associates — any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This now explicitly includes cloud infrastructure providers, SaaS vendors, medical billing services, and increasingly AI/ML vendors processing clinical data.
Subcontractors of business associates are also directly liable under HITECH — the chain extends downstream, and every hop requires a Business Associate Agreement.
The Security Rule in depth
The Security Rule (45 CFR §§ 164.302–318) organizes requirements into three categories of safeguards. Each standard has one or more implementation specifications, marked as either Required (must implement) or Addressable (implement, or document why an equivalent alternative is used):
| Safeguard category | Example standards | Examples of controls |
|---|---|---|
| Administrative (§164.308) | Security management process, workforce security, information access management, contingency plan, evaluation | Risk analysis, sanction policy, access authorization, workforce training, DR plan, periodic technical evaluation |
| Physical (§164.310) | Facility access controls, workstation security, device and media controls | Facility security plan, workstation-use policy, device disposal, media re-use, portable-device tracking |
| Technical (§164.312) | Access control, audit controls, integrity, person/entity authentication, transmission security | Unique user IDs, automatic logoff, encryption at rest/in transit, audit logs, MFA, hash-based integrity checks |
Privacy Rule essentials
The Privacy Rule governs the use and disclosure of PHI in any form — paper, electronic, or oral. It establishes patient rights (access, amendment, accounting of disclosures, restrictions), the minimum-necessary standard, and specific disclosure permissions (treatment, payment, health-care operations).
For most technology teams, the Privacy Rule surfaces as: notice of privacy practices, authorization forms for uses outside TPO, patient right-of-access requests within 30 days, and honoring restriction requests where legally required.
Breach Notification Rule
A breach is any acquisition, access, use, or disclosure of unsecured PHI in violation of the Privacy Rule that compromises its security or privacy. 'Unsecured' means not rendered unusable through encryption or destruction meeting HHS guidance.
Timeline obligations after breach discovery:
Breach notification obligations
- Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery.
- Notify HHS Secretary — within 60 days for breaches of 500+ individuals, annually for smaller breaches.
- Notify prominent media outlets in the affected state or jurisdiction for breaches of 500+ individuals.
- Business associates must notify the covered entity within 60 days of discovery (often contractually accelerated to 5–15 days).
2026 Security Rule NPRM changes
In December 2024, HHS OCR published a Notice of Proposed Rulemaking (NPRM) representing the most significant Security Rule update since 2013. Finalization is expected in 2026. The most consequential proposals:
Key 2026 Security Rule NPRM proposals
- Removal of the Addressable/Required distinction — most specifications become required.
- Mandatory encryption of ePHI at rest and in transit (with narrow exceptions).
- Mandatory multi-factor authentication for ePHI access.
- Mandatory network segmentation between ePHI systems and general IT.
- 72-hour patching window for known exploited vulnerabilities affecting ePHI systems.
- Annual technical inventory and network map of all ePHI systems.
- Business associates required to verify security controls annually and attest to the covered entity.
- Mandatory 24-hour notification from business associate to covered entity for breaches or ransomware.
The mandatory risk analysis
45 CFR §164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI. This is the single most cited failure in OCR settlements — organizations either had no written risk analysis, had one that was stale by years, or had one that did not cover all ePHI locations.
A defensible HIPAA risk analysis includes: complete ePHI inventory (systems, locations, flows), threat identification, vulnerability identification, current controls, likelihood and impact assessment, risk level determination, and a risk management plan documenting remediation. It is refreshed at least annually and after any significant change.
The OCR audit protocol assumes you have a current, written risk analysis. Not having one is not a technical finding — it is a categorical failure that transforms every downstream gap into a Willful Neglect determination with maximum penalties.
Business Associate Agreements
A BAA is a contract required whenever a covered entity discloses PHI to a business associate, and again whenever a business associate discloses PHI to a subcontractor. HHS provides a sample BAA, but production BAAs almost always add breach-notification timelines shorter than 60 days, indemnification, insurance requirements, and audit rights.
OCR increasingly probes whether the BAA is operationally enforced — do you actually monitor the BA's security posture? Are subcontractor BAAs in place? Is the BA notifying you of breaches in the contracted window? A signed-and-filed BAA with no operational follow-through is now a common enforcement finding.
OCR enforcement in practice
OCR investigations are driven primarily by breach reports (public HHS breach portal), patient complaints, and compliance reviews. Penalty tiers are tied to culpability:
| Tier | Culpability | 2026 penalty range (per violation) |
|---|---|---|
| 1 | No knowledge — could not have known with reasonable diligence | ~$137 – $34,464 |
| 2 | Reasonable cause — not willful neglect | ~$1,379 – $68,928 |
| 3 | Willful neglect — corrected within 30 days | ~$13,785 – $68,928 |
| 4 | Willful neglect — not corrected | ~$68,928 – $2,067,813 |
Build Trust. Reduce Risk. Achieve Compliance.
Talk to a senior GRC advisor
Free scoping call. Executive-grade guidance on your compliance roadmap.
Book a consultationFrequently Asked Questions
Is HIPAA required for SaaS companies?
Only if you handle PHI on behalf of a covered entity or another business associate — in which case you are a business associate and directly liable. Many SaaS companies that do not touch clinical data are not HIPAA-regulated even if their customers are hospitals; scope depends entirely on whether PHI flows through the product.
How is HIPAA different from SOC 2?
SOC 2 is a voluntary attestation issued by a CPA firm against AICPA Trust Services Criteria. HIPAA is federal law enforced by HHS OCR with civil monetary penalties. A SOC 2 report does not prove HIPAA compliance, though it can provide substantial evidence for many Security Rule technical safeguards. Health-tech companies frequently pursue both.
Do we need an annual HIPAA audit?
HIPAA does not require an annual third-party audit. It requires an ongoing risk analysis and periodic evaluation of security safeguards (§164.308(a)(8)). Most mature programs conduct an annual internal or external HIPAA assessment because it is the fastest way to catch the risk-analysis gaps OCR looks for.
Does encryption make PHI 'safe' from breach notification?
Encryption meeting HHS guidance renders PHI 'secured' — a breach of properly encrypted PHI (with keys not compromised) is not a reportable breach under the current rule. This is the single highest-leverage HIPAA control, and the 2026 NPRM effectively makes it mandatory.
How long do HIPAA records need to be retained?
HIPAA requires documentation (policies, procedures, risk analyses, workforce training records, BAAs, incident records) to be retained for six years from the date of creation or the date it was last in effect — whichever is later. State laws may require longer retention for medical records themselves.
Related Topics
