HomeFrameworksInformation Security & PrivacyHIPAA

Framework  Information Security & Privacy

HIPAA

HIPAA's Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164) set the federal floor for protecting health information in the United States.

The Security Rule requires covered entities and their business associates to protect electronic protected health information through administrative, physical and technical safeguards, starting with an accurate and thorough risk analysis.

The Privacy Rule governs uses and disclosures and individual rights; the Breach Notification Rule requires notice to individuals, HHS and sometimes the media after a breach of unsecured PHI.

HHS proposed a major Security Rule update on January 6, 2025 (comments closed March 7, 2025); the final rule has not been issued and the regulatory agenda now targets July 2027, so the current rule remains in force.

HIPAA is a documentation regulation. Organizations must keep written policies and procedures for every standard, retain them and related records for six years, document the risk analysis and risk management plan, sign business associate agreements, train the workforce and keep records, designate privacy and security officials, apply sanctions and record them, and keep incident and breach logs.

OCR enforcement actions in 2025 centered on missing or inadequate risk analyses.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPrivacy policy v7by name, on record
164.316 Handledwith AllyMatter
Cover the Entity the Modern WayEvery HIPAA policy, read and acknowledged by the workforce
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every nurse, clerk and vendor on record
Acknowledgments that survive turnover
03
Open the binder before OCR asks
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Covered entities (health plans, health care clearinghouses, and health care providers that transmit standard electronic transactions) and business associates that create, receive, maintain or transmit PHI on their behalf, including subcontractors. Applies regardless of size.

What you have to write

Documents on this site that HIPAA requires or expects, each with who must have it, the review cycle and the obligations that cite it.

What the assessor asks to see

Designation of privacy and security officials; risk analysis and risk management plan; written policies and procedures for each Security and Privacy Rule standard; asset and ePHI system inventory; access authorization and termination records; workforce training records; sanction policy and records; business associate agreements; contingency and backup plans with test results; audit log review records; incident and breach logs and notification letters; notice of privacy practices; patient access request logs.

Where the requirement sits: 164.316(a)-(b) policies, documentation, 6-year retention, review; 164.308(a)(5) security awareness and training; 164.530(b) privacy training records; 164.530(e) sanctions; 164.530(i)-(j). Not covered: 164.308(a)(1)(ii)(A) risk analysis content

Proposed Security Rule update

The January 2025 proposed rule would remove the addressable and required distinction, require a written asset inventory and network map, mandatory MFA and encryption, annual compliance audits, vulnerability scans every six months, annual penetration tests, and 72-hour restoration capability.

As of September 2026 it is still a proposal with final action listed for July 2027; verify the status before treating any of these as current obligations.

What AllyMatter does here

Writes, approves, versions and proves workforce acknowledgment of HIPAA policies, with the 164.316 documentation trail.

AllyMatter publishes this site.

Assessors

Who assesses HIPAA

Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary.

No firm has claimed a HIPAA assessor listing yet. Claim yours →

Consultants

Who helps with HIPAA

A large ecosystem: HIPAA compliance consultancies, healthcare security firms, law firms and compliance software vendors. They run risk analyses, write policy sets, deliver training, draft BAAs and prepare for OCR investigations. Engagements range from a one-time risk analysis to annual managed compliance programs.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a HIPAA consultant listing yet. Claim yours →

Related reading

  1. HIPAA Security Rule resolves to hit the gym and bulk upLaw firm analysis of the January 2025 proposed rule, including the end of addressable specifications and the new written documentation duties.Davis Wright Tremaine
  2. Changes proposed by HHS to strengthen the HIPAA Security RuleA section by section read of the proposed policies, asset inventory, risk analysis and business associate verification requirements.Maynard Nexsen
  3. Architecting for HIPAA security and compliance on AWSShows how the business associate agreement and shared responsibility work in practice when ePHI sits in a cloud account.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for HIPAA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of HIPAA in AllyMatter

Approve the policies HIPAA asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.