Framework Information Security & Privacy
HIPAA
HIPAA's Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164) set the federal floor for protecting health information in the United States.
The Security Rule requires covered entities and their business associates to protect electronic protected health information through administrative, physical and technical safeguards, starting with an accurate and thorough risk analysis.
The Privacy Rule governs uses and disclosures and individual rights; the Breach Notification Rule requires notice to individuals, HHS and sometimes the media after a breach of unsecured PHI.
HHS proposed a major Security Rule update on January 6, 2025 (comments closed March 7, 2025); the final rule has not been issued and the regulatory agenda now targets July 2027, so the current rule remains in force.
HIPAA is a documentation regulation. Organizations must keep written policies and procedures for every standard, retain them and related records for six years, document the risk analysis and risk management plan, sign business associate agreements, train the workforce and keep records, designate privacy and security officials, apply sanctions and record them, and keep incident and breach logs.
OCR enforcement actions in 2025 centered on missing or inadequate risk analyses.
Who has to comply
Covered entities (health plans, health care clearinghouses, and health care providers that transmit standard electronic transactions) and business associates that create, receive, maintain or transmit PHI on their behalf, including subcontractors. Applies regardless of size.
What you have to write
Documents on this site that HIPAA requires or expects, each with who must have it, the review cycle and the obligations that cite it.
- HIPAA Privacy Policies and Procedures Healthcare
- HIPAA Security Policies and Procedures Information security
- Notice of Privacy Practices Healthcare
- Health Care Compliance Program Policies and Code of Conduct Healthcare
What the assessor asks to see
Designation of privacy and security officials; risk analysis and risk management plan; written policies and procedures for each Security and Privacy Rule standard; asset and ePHI system inventory; access authorization and termination records; workforce training records; sanction policy and records; business associate agreements; contingency and backup plans with test results; audit log review records; incident and breach logs and notification letters; notice of privacy practices; patient access request logs.
Where the requirement sits: 164.316(a)-(b) policies, documentation, 6-year retention, review; 164.308(a)(5) security awareness and training; 164.530(b) privacy training records; 164.530(e) sanctions; 164.530(i)-(j). Not covered: 164.308(a)(1)(ii)(A) risk analysis content
Proposed Security Rule update
The January 2025 proposed rule would remove the addressable and required distinction, require a written asset inventory and network map, mandatory MFA and encryption, annual compliance audits, vulnerability scans every six months, annual penetration tests, and 72-hour restoration capability.
As of September 2026 it is still a proposal with final action listed for July 2027; verify the status before treating any of these as current obligations.
What AllyMatter does here
Writes, approves, versions and proves workforce acknowledgment of HIPAA policies, with the 164.316 documentation trail.
AllyMatter publishes this site.
Assessors
Who assesses HIPAA
Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary.
No firm has claimed a HIPAA assessor listing yet. Claim yours →
Consultants
Who helps with HIPAA
A large ecosystem: HIPAA compliance consultancies, healthcare security firms, law firms and compliance software vendors. They run risk analyses, write policy sets, deliver training, draft BAAs and prepare for OCR investigations. Engagements range from a one-time risk analysis to annual managed compliance programs.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a HIPAA consultant listing yet. Claim yours →
Software
Tools for HIPAA
Tools that name this framework in their own material.
Related reading
- HIPAA Security Rule resolves to hit the gym and bulk upLaw firm analysis of the January 2025 proposed rule, including the end of addressable specifications and the new written documentation duties.Davis Wright Tremaine
- Changes proposed by HHS to strengthen the HIPAA Security RuleA section by section read of the proposed policies, asset inventory, risk analysis and business associate verification requirements.Maynard Nexsen
- Architecting for HIPAA security and compliance on AWSShows how the business associate agreement and shared responsibility work in practice when ePHI sits in a cloud account.Amazon Web Services
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for HIPAA
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of HIPAA in AllyMatter
Approve the policies HIPAA asks for, keep every version, and record a named acknowledgment from each person who has to read them.