Last month, a clinic manager in Ohio pulled me aside after a training session and said, "I just need something I can tape to the wall. One page. The stuff that actually matters." She'd been through three audits, managed a small breach, and survived — but she still couldn't rattle off the breach notification timeline without checking her notes. That conversation is why I built this HIPAA cheat sheet. Not a textbook summary. Not a legal treatise. A real-world, fast-reference breakdown of the rules that trip people up the most.
This post is designed to be your go-to reference. Bookmark it. Print it. Share it with your workforce. It covers the Privacy Rule, the Security Rule, breach notification deadlines, patient rights, and the penalties that land when things go wrong. If you need a single resource that captures what matters most, this is it.
What a HIPAA Cheat Sheet Actually Covers
HIPAA isn't one law — it's a framework of rules administered by the U.S. Department of Health and Human Services (HHS) through the Office for Civil Rights (OCR). A useful cheat sheet boils down five main components:
- The Privacy Rule — governs who can access, use, and disclose protected health information (PHI).
- The Security Rule — sets administrative, physical, and technical safeguards for electronic PHI (ePHI).
- The Breach Notification Rule — dictates exactly when and how you report a breach.
- The Enforcement Rule — defines investigation procedures and civil monetary penalties.
- The Omnibus Rule — extended most HIPAA obligations to business associates.
Every covered entity — health plans, healthcare clearinghouses, and providers who transmit claims electronically — must comply with all of them. So must their business associates.
The Privacy Rule in 60 Seconds
The Privacy Rule controls the flow of PHI. Here's the fast version.
Permitted Uses Without Patient Authorization
- Treatment, payment, and healthcare operations (TPO).
- Public health activities (disease reporting, FDA surveillance).
- Judicial and administrative proceedings with proper orders.
- Law enforcement purposes under specific conditions.
- Workers' compensation as authorized by state law.
When You Need Written Authorization
Marketing, most sales of PHI, psychotherapy notes, and any use that falls outside TPO or the specific exceptions listed in 45 CFR Part 164, Subpart E. When in doubt, get it in writing.
Minimum Necessary Standard
Only access, use, or disclose the minimum amount of PHI needed to accomplish the task. This one rule generates more violations than almost anything else I see in the field. Staff pull up full records when they only need a date of birth. Fax cover sheets include diagnosis codes that nobody on the receiving end needs. Train your workforce to ask: "Do I actually need all of this?"
The Security Rule: Safeguards That Actually Matter
The Security Rule applies to ePHI — any PHI created, stored, maintained, or transmitted electronically. It demands three categories of safeguards.
Administrative Safeguards
- Designate a Security Officer.
- Conduct a risk analysis (and document it — OCR checks for this first).
- Implement workforce training and sanction policies.
- Maintain contingency and disaster recovery plans.
Physical Safeguards
- Control facility access (locks, visitor logs, badge systems).
- Workstation security — screens positioned away from public view, automatic logoff enabled.
- Device and media disposal procedures (wipe or destroy before recycling).
Technical Safeguards
- Unique user IDs for every workforce member — no shared logins.
- Encryption for ePHI in transit and at rest.
- Audit controls that log who accessed what, and when.
- Automatic session timeouts.
If your organization hasn't completed a current risk analysis, stop reading and schedule one. OCR's Guidance on Risk Analysis is the starting point. Failing to conduct one is the single most cited deficiency in enforcement actions.
Breach Notification Timelines: The Numbers to Memorize
This section alone justifies calling this a HIPAA cheat sheet. I've seen organizations botch these deadlines and escalate a manageable incident into a six-figure penalty.
What Counts as a Breach?
An impermissible use or disclosure of PHI that compromises the security or privacy of the information. There's a presumption that every impermissible disclosure is a breach unless you can demonstrate through a four-factor risk assessment that there's a low probability the PHI was compromised.
The Deadlines
- Individual notification: Within 60 days of discovering the breach. Written notice to every affected individual.
- HHS notification (500+ individuals): Within 60 days. Filed through the HHS breach portal.
- HHS notification (fewer than 500): May be submitted annually, no later than 60 days after the end of the calendar year.
- Media notification (500+ in a single state): Within 60 days. Prominent media outlets in the affected state or jurisdiction.
- Business associate to covered entity: Within 60 days of discovery (or sooner if your BAA requires it).
The clock starts ticking the moment any member of your workforce becomes aware of the breach — not when leadership finds out, not when legal reviews it. That distinction has cost organizations dearly.
Patient Rights You Can't Afford to Ignore
Patients have teeth under HIPAA, and OCR backs them up. Here's your quick list.
- Right to access: Patients can request copies of their medical records. You have 30 days to respond (one 30-day extension permitted). The fee must be reasonable and cost-based.
- Right to amend: Patients can ask you to correct inaccurate PHI. You can deny with a written explanation, but you must act within 60 days.
- Right to an accounting of disclosures: Patients can request a log of who you've shared their PHI with outside of TPO.
- Right to request restrictions: Patients can ask you to limit certain uses of their PHI. You generally don't have to agree — except when a patient pays out of pocket in full and asks you not to share with their health plan. That one is mandatory.
- Right to receive confidential communications: Patients can ask you to contact them at a specific number or address.
In 2023, OCR settled with Banner Health for $1.25 million after a breach affecting nearly 3 million individuals exposed failures in access controls and risk analysis processes. Access-related complaints remain one of OCR's most active enforcement areas.
Penalties: What's Actually at Stake
HIPAA penalties follow a four-tier structure adjusted annually for inflation:
- Tier 1 — Did not know: $137 to $68,928 per violation.
- Tier 2 — Reasonable cause: $1,379 to $68,928 per violation.
- Tier 3 — Willful neglect, corrected: $13,785 to $68,928 per violation.
- Tier 4 — Willful neglect, not corrected: $68,928 to $2,067,813 per violation.
The annual cap per identical violation category is over $2 million. Criminal penalties — handled by the Department of Justice — can reach $250,000 and 10 years in prison for wrongful disclosure with intent to sell PHI.
These aren't theoretical. OCR has collected over $142 million in HIPAA settlements and penalties since the enforcement program began. Your organization is not too small to be investigated.
The Training Gap That Keeps Getting Organizations Fined
Here's what I tell every client: a cheat sheet is not a substitute for proper workforce training. It's a supplement. HIPAA requires that every workforce member — employees, volunteers, trainees, anyone under your direct control — receives training on policies and procedures relevant to their job function.
The problem I see constantly is organizations that train once during onboarding and never again. Policies change. Threats evolve. Staff forget. Annual refresher training isn't just best practice — it's your evidence of a culture of compliance when OCR comes knocking.
If your training program needs an overhaul, start with the HIPAA training catalog at HIPAACertify. It covers the Privacy Rule, Security Rule, breach notification, and role-specific modules — everything your workforce needs to stay current in 2026.
How to Use This HIPAA Cheat Sheet Day to Day
Print the key sections above and post them where decisions get made — nurses' stations, front desks, IT offices, billing departments. But don't stop there.
- Reference it during your annual risk analysis review.
- Use the breach notification deadlines as a checklist during incident response drills.
- Walk new hires through patient rights during their first week, then reinforce it through structured HIPAA training.
- Review penalty tiers with leadership to maintain executive buy-in for compliance spending.
HIPAA compliance isn't a one-time project — it's an operating system for how your organization handles health information. This HIPAA cheat sheet gives you the quick-hit reference points. The real work is building policies, training your people, and documenting everything.
Because when OCR asks for proof, "I thought we were covered" has never been an acceptable answer.