In 2018, a Texas cancer center paid $4.3 million to HHS after two unencrypted devices containing ePHI went missing. The root cause wasn't a sophisticated cyberattack. It was a fundamental failure to follow one of the three core rules that make up the backbone of HIPAA. I've watched organizations spend thousands on flashy security tools while ignoring the regulatory framework those tools are supposed to support. If you don't understand the 3 rules of HIPAA — really understand them, not just recognize their names — your compliance program is built on sand.
This post breaks down each rule with the specificity your organization needs. No fluff, no legalese you can't use. Just the operational reality of what these rules demand and what happens when you ignore them.
What Are the 3 Rules of HIPAA?
The 3 rules of HIPAA are the Privacy Rule, the Security Rule, and the Breach Notification Rule. Together, they form the regulatory framework that governs how covered entities and business associates handle protected health information (PHI). Each rule addresses a different dimension of protection — who can access PHI, how ePHI must be safeguarded, and what happens when something goes wrong.
Think of them as three legs of a stool. Remove one, and your entire compliance posture collapses. The Office for Civil Rights (OCR) at HHS enforces all three, and they don't grade on a curve.
Rule #1: The Privacy Rule — Who Gets Access and Why
The HIPAA Privacy Rule, codified at 45 CFR Part 164, Subpart E, establishes national standards for when and how PHI can be used and disclosed. It applies to PHI in any form — paper, electronic, or verbal. Yes, that hallway conversation your staff had about a patient's diagnosis is covered.
The Minimum Necessary Standard
This is where most violations start. The Privacy Rule requires that your organization limit PHI access to the minimum amount necessary to accomplish a given task. A billing clerk doesn't need to see therapy notes. A front-desk coordinator doesn't need access to lab results.
I've audited practices where every employee had full access to every patient record. When I ask why, the answer is almost always "it's just easier that way." Easier, sure — until OCR comes knocking.
Patient Rights Under the Privacy Rule
The Privacy Rule also grants patients specific rights over their health information. These include the right to access their records, request corrections, and receive an accounting of disclosures. In 2019, Cignet Health paid $4.3 million in civil monetary penalties — the first penalty of its kind — after refusing 41 patients access to their medical records.
Your Notice of Privacy Practices (NPP) is the document that communicates these rights to patients. If yours is a dusty template from 2013, it's time for a rewrite.
Training Is Not Optional
The Privacy Rule explicitly requires workforce training on your organization's privacy policies and procedures. Every member of your workforce — not just clinical staff — must receive training. That includes volunteers, trainees, and anyone else under your operational control. Our HIPAA training catalog covers the Privacy Rule requirements that your entire team needs to understand.
Rule #2: The Security Rule — The Technical Backbone
If the Privacy Rule tells you what to protect, the Security Rule tells you how. Found at 45 CFR Part 164, Subpart C, the HIPAA Security Rule focuses exclusively on electronic protected health information (ePHI). It requires covered entities and business associates to implement three categories of safeguards.
Administrative Safeguards
These are the policies, procedures, and people you put in place to manage ePHI protection. You need a designated Security Officer. You need a risk analysis — not a one-time checkbox, but an ongoing process. You need sanctions for workforce members who violate your policies.
The risk analysis requirement trips up more organizations than any other provision. When OCR investigates a breach, the first thing they ask for is your most recent risk analysis. If you don't have one, the conversation gets expensive fast.
Physical Safeguards
Physical safeguards control who can physically access the spaces and devices where ePHI lives. Server rooms need locks. Workstations need positioning that prevents unauthorized viewing. Mobile devices need policies governing their movement in and out of your facility.
I once walked into a medical office where the server sat in an unlocked closet next to the break room. Anyone — patients, delivery drivers, cleaning staff — could have walked right in. That's not a hypothetical risk. That's an invitation.
Technical Safeguards
Encryption, access controls, audit logs, integrity controls, transmission security — these are the technical mechanisms that protect ePHI from unauthorized access. The Security Rule doesn't prescribe specific technologies. Instead, it uses "addressable" and "required" implementation specifications.
Here's what catches people: "addressable" doesn't mean "optional." It means you must implement the specification, implement an equivalent alternative, or document why neither is reasonable and appropriate. Skipping it without documentation is a violation.
The $1.5 Million Lesson from Lack of Encryption
In 2017, Children's Medical Center of Dallas agreed to a $3.2 million settlement with OCR after multiple breaches involving unencrypted devices. OCR found that the organization had been aware of the risk for years but failed to act. The Security Rule doesn't technically require encryption in all cases — but when your risk analysis identifies it as necessary and you still don't implement it, you're handing OCR their case on a silver platter.
Rule #3: The Breach Notification Rule — When Things Go Wrong
The Breach Notification Rule, added by the HITECH Act in 2009, dictates exactly what a covered entity must do when a breach of unsecured PHI occurs. It's found at 45 CFR Part 164, Subpart D. And its timelines are unforgiving.
The 60-Day Clock
Once you discover a breach — or reasonably should have discovered it — you have 60 calendar days to notify affected individuals. If the breach affects 500 or more people, you must also notify OCR and prominent media outlets in that same window. Breaches affecting fewer than 500 individuals can be reported to OCR annually, but individual notification still runs on the 60-day clock.
"Discovery" is the key word. OCR doesn't care when your IT team got around to telling the compliance officer. If an employee knew about the breach on Day 1, the clock started on Day 1.
The Four-Factor Risk Assessment
Not every impermissible use or disclosure qualifies as a breach. The Breach Notification Rule provides a four-factor risk assessment to determine whether a breach has occurred:
- The nature and extent of the PHI involved
- The unauthorized person who used or received the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
You must demonstrate — through documentation — that there is a low probability the PHI was compromised. If you can't, you treat it as a breach. Period.
What Notification Must Include
Your breach notification letters aren't just a courtesy. They must include a description of the breach, the types of PHI involved, steps individuals should take to protect themselves, what your organization is doing in response, and contact information for follow-up. Vague, boilerplate letters don't meet the standard.
How the 3 Rules of HIPAA Work Together
Here's what I tell every client: these three rules aren't separate compliance projects. They're interconnected systems. Your Privacy Rule policies define what PHI can be used and how. Your Security Rule safeguards enforce those limits technically. Your Breach Notification Rule procedures kick in when the first two fail.
An organization with a strong Privacy Rule program but weak security controls will still suffer breaches. An organization with rock-solid encryption but no breach response plan will botch the aftermath. You need all three working in concert.
This is exactly why comprehensive HIPAA workforce training matters so much. Your staff can't follow rules they don't know exist. And OCR has made it clear — through enforcement action after enforcement action — that ignorance is not a defense.
What OCR Actually Looks for During an Investigation
When OCR opens an investigation — whether from a complaint or a reported breach — they follow a predictable pattern. I've seen it play out dozens of times:
- They request your risk analysis and risk management plan.
- They ask for evidence of workforce training.
- They examine your policies and procedures for all three rules.
- They check whether you've implemented the safeguards your own risk analysis identified.
- They look at your breach notification documentation.
The organizations that get hit hardest aren't necessarily the ones with the worst breaches. They're the ones with the weakest documentation. If you can't prove you did the work, OCR assumes you didn't.
Where to Start If You're Behind
If reading this made your stomach drop, you're not alone. Most organizations I work with have gaps in at least one of these three areas. Here's my advice: start with your risk analysis. It's the single document that ties all three rules together. It identifies threats to ePHI (Security Rule), informs your policies about PHI access (Privacy Rule), and shapes your incident response procedures (Breach Notification Rule).
Then get your workforce trained. Not once. Not annually with a quiz they can click through in four minutes. Trained in a way that changes behavior. Browse our full HIPAA training catalog to find courses that match your organization's size and risk profile.
The 3 rules of HIPAA aren't aspirational. They're enforceable. OCR has the authority, the budget, and — increasingly — the willingness to pursue organizations that treat compliance as optional. The question isn't whether you'll face scrutiny. It's whether you'll be ready when you do.