The HIPAA Security Rule applies to covered entities (healthcare providers, health plans, clearinghouses) and to all business associates who handle electronic protected health information.
If you provide services to healthcare organizations or handle patient data directly, you are covered. HIPAA compliance is not optional. It is a baseline legal requirement that HHS OCR enforces with substantial penalties for violations.
Covered entities include healthcare providers, health plans, and clearinghouses.
A covered entity is any healthcare provider (physician, dentist, hospital, clinic, mental health provider) that transmits PHI electronically in connection with a standard transaction.
Health plans (commercial insurers, Medicare, Medicaid) and health clearinghouses are also covered.
Business associates are vendors or contractors who handle PHI on behalf of covered entities.
This includes managed IT providers, cybersecurity firms, cloud vendors, EHR software providers, and any organization that accesses, processes, stores, or transmits PHI.
The HIPAA Security Rule applies to all of you. There is no opt-out. If you handle ePHI, you must implement and maintain the required safeguards.
The Security Rule's three categories of safeguards are mandatory and interconnected.
Administrative safeguards set the policies and procedures your workforce must follow: access controls, training, security officer designation, risk analysis, and contingency planning. These policies must be written and documented.
Physical safeguards control who can access the buildings, rooms, and equipment that hold ePHI. This includes facility access controls, visitor management, workstation security, and device controls.
Technical safeguards use technology to protect ePHI: encryption, access controls, audit logging, and integrity verification. All three categories work together.
Policies fail without technical enforcement, and technical controls are useless without the administrative structure and physical discipline to support them.
HHS OCR audits HIPAA compliance; enforcement includes substantial civil and criminal penalties.
The U. S. Department of Health and Human Services Office for Civil Rights (HHS OCR) enforces HIPAA. OCR conducts audits and investigates complaints. It brings enforcement actions against covered entities and business associates who fail to comply.
Civil penalties for HIPAA violations range from USD 100 to USD 50,000 per violation. Annual caps reach up to USD 1. 9 million per violation category. A single breach can trigger thousands of violations.
Criminal penalties for knowing misuse or disclosure of PHI include fines up to USD 250,000 and imprisonment up to 10 years.
Beyond fines, a data breach of patient information triggers reputational damage, contractual liability, and loss of patient trust. The compliance program exists to prevent the breach in the first place, not to minimize penalties after one occurs.
The Security Rule is addressable and scalable, not one prescriptive checklist.
The Security Rule divides its implementation specifications into required and addressable. Required specifications must be implemented as written. Addressable specifications are not optional.
You must implement the specification, or document why it is not reasonable and appropriate for your environment and put an equivalent alternative in place. Skipping an addressable item without that written analysis is a common audit finding.
The rule is also intentionally scalable. A solo practice and a regional hospital face the same standards but implement them in proportion to their size, complexity, and risk. That flexibility is why the annual Security Risk Analysis matters so much.
It is the record that justifies the safeguards you chose and the ones you decided were not needed.
Proposed updates to the Security Rule would tighten several of these areas, including encryption, multi-factor authentication, and mandatory verification that safeguards are actually working.
Cyber One Solutions tracks these developments and builds programs that already reflect strong technical controls. If the rule tightens, that is an adjustment rather than a rebuild.