A small dermatology practice in Massachusetts lost an unencrypted thumb drive in 2019. It contained the ePHI of 2,200 patients. When HHS investigated, they didn't just find a missing device — they found a clinic that couldn't articulate the difference between the three foundational HIPAA regulations, let alone prove they'd followed them. The result was a corrective action plan that consumed the practice for two years. Understanding the HIPAA three rules isn't academic trivia. It's the architecture your entire compliance program sits on.
If you've ever been confused about where the Privacy Rule ends and the Security Rule begins — or wondered where the Breach Notification Rule fits in — this post lays it out plainly, with real enforcement examples and the specifics your workforce actually needs.
What Are the HIPAA Three Rules?
The HIPAA three rules are the Privacy Rule, the Security Rule, and the Breach Notification Rule. Together, they form the regulatory framework that governs how covered entities and business associates handle protected health information (PHI). Each rule addresses a different dimension of data protection — who can access PHI, how it must be safeguarded electronically, and what happens when something goes wrong.
HHS's Office for Civil Rights (OCR) enforces all three. Violations of any single rule can trigger investigations, corrective action plans, and civil monetary penalties ranging from thousands to millions of dollars. You can review the full regulatory text and guidance on the HHS HIPAA for Professionals page.
Rule #1: The Privacy Rule — Who Gets Access to PHI
The Privacy Rule establishes national standards for when and how PHI can be used or disclosed. It covers every format — paper charts, verbal conversations, digital records. If your front desk staff discusses a patient's diagnosis in a hallway loud enough for other patients to hear, that's a Privacy Rule issue.
The Minimum Necessary Standard
One of the most misunderstood provisions is the minimum necessary standard. It requires your organization to limit PHI access to only the information needed for a specific task. A billing clerk doesn't need to see psychiatric notes. A lab technician doesn't need a patient's home address.
I've seen organizations grant blanket EHR access to every employee because it's easier than configuring role-based permissions. That shortcut becomes a liability the moment OCR comes knocking.
Patient Rights Under the Privacy Rule
The Privacy Rule also grants patients specific rights: the right to access their own records, request amendments, and receive an accounting of disclosures. In 2023, OCR settled with Banner Health for $1.25 million partly over right-of-access failures. That case reinforced what OCR has made clear through its enforcement actions page — patient access isn't optional.
If your nurses and clinical staff handle records requests, they need role-specific training that covers these obligations. Our HIPAA training for nurses and clinical workflow walks through exactly these scenarios.
Rule #2: The Security Rule — How You Protect ePHI
While the Privacy Rule covers all PHI in any form, the Security Rule focuses specifically on electronic PHI (ePHI). It requires covered entities to implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI.
Three Categories of Safeguards
Administrative safeguards include your risk analysis, workforce training programs, and contingency plans. This is where most organizations fail first. OCR has cited the lack of a comprehensive risk analysis as the root cause in the majority of its enforcement actions.
Physical safeguards cover facility access controls, workstation security, and device disposal. That unlocked server closet in your back office? That's a physical safeguard gap.
Technical safeguards include access controls, audit logs, encryption, and transmission security. If your staff emails ePHI without encryption — even internally — you have a technical safeguard problem.
The Risk Analysis Requirement That Trips Up Everyone
I cannot overstate how many OCR settlements cite an inadequate or missing risk analysis. In 2018, Anthem Inc. paid $16 million to settle HIPAA violations after a massive breach. OCR's investigation found that Anthem had failed to conduct an enterprise-wide risk analysis prior to the breach. Sixteen million dollars. The risk analysis isn't a checkbox — it's the foundation the Security Rule is built on.
Pharmacy teams face unique Security Rule challenges because they handle ePHI across dispensing systems, insurance portals, and point-of-sale platforms simultaneously. Our HIPAA & HITECH training for pharmacy professionals addresses these specific technical environments.
Rule #3: The Breach Notification Rule — What Happens When PHI Is Compromised
The Breach Notification Rule, added by the HITECH Act in 2009, requires covered entities to notify affected individuals, HHS, and in some cases the media when unsecured PHI is breached. The notification timelines are strict: individual notice must go out within 60 days of discovering the breach.
What Counts as a Breach?
A breach is any impermissible use or disclosure of PHI that compromises its security or privacy. Under the rule, a breach is presumed unless you can demonstrate through a four-factor risk assessment that there's a low probability the PHI was actually compromised. Those four factors evaluate the nature of the PHI involved, who accessed it, whether it was actually acquired or viewed, and what mitigation steps were taken.
Sending a fax with patient lab results to the wrong number? That's a potential breach. A stolen laptop with unencrypted ePHI? That's almost certainly a reportable breach.
The 500-Person Threshold
Breaches affecting 500 or more individuals trigger additional obligations. You must notify prominent media outlets in the affected state and report to HHS simultaneously — not after. These breaches are posted publicly on OCR's Breach Portal, sometimes called the "Wall of Shame." Once your organization appears there, the reputational damage is immediate and lasting.
For breaches affecting fewer than 500 individuals, you still must notify HHS, but you can do so annually. Don't let the smaller reporting window trick you into treating small breaches casually. OCR aggregates patterns.
How the HIPAA Three Rules Work Together
Think of it this way: the Privacy Rule defines the boundaries. The Security Rule builds the walls. The Breach Notification Rule is the alarm system.
A compliance program that focuses on one rule while ignoring the others will fail. I've reviewed programs where an organization had immaculate security policies but no breach response plan. Others had detailed privacy notices but couldn't produce a risk analysis when OCR requested one. The HIPAA three rules function as an integrated system, and OCR evaluates them that way.
Mental Health Practices Face Heightened Stakes
Mental and behavioral health providers deal with uniquely sensitive PHI — psychotherapy notes, substance use disorder records, and information protected by additional federal regulations like 42 CFR Part 2. A breach in this setting doesn't just risk a fine; it can devastate a patient's life. If you work in behavioral health, role-specific training is essential. Our HIPAA training for mental and behavioral health covers the intersections that generic training misses entirely.
The $2.3 Million Mistake That Proves the Rules Aren't Suggestions
In 2018, Pagosa Springs Medical Center agreed to a $111,400 settlement — not a staggering amount, but the corrective action plan consumed staff resources for years. Larger organizations have faced far worse. The University of Texas MD Anderson Cancer Center fought OCR in court over a $4.3 million penalty related to unencrypted devices containing ePHI. An administrative law judge upheld the penalty in 2017, though it was later reduced on appeal. The lesson remained: the Security Rule's encryption provisions exist for a reason.
These aren't hypothetical scenarios. They're public records. You can search them yourself on the OCR enforcement highlights page.
Building a Program Around All Three Rules in 2026
If you're a compliance officer, practice manager, or privacy officer, here's what a solid program looks like in 2026:
- Conduct and document a comprehensive risk analysis — at least annually, and whenever you adopt new technology or workflows.
- Implement role-based workforce training — generic training slides from 2018 won't protect you. Staff need to understand how the three rules apply to their specific daily tasks.
- Develop a written breach response plan — including internal reporting chains, risk assessment templates, and notification letter drafts. Don't create these during a crisis.
- Audit access logs regularly — the Security Rule requires it, and it's one of the fastest ways to catch insider snooping before it becomes a breach.
- Review business associate agreements — your vendors handle ePHI too, and the Breach Notification Rule holds them accountable right alongside you.
Your compliance program is only as strong as its weakest rule. If you've invested heavily in technical safeguards but haven't updated your Notice of Privacy Practices since 2015, you've left a gap OCR will find.
Stop Treating Compliance as One Rule at a Time
The organizations that get into trouble almost always share one trait: they treated compliance as a series of isolated tasks instead of an integrated framework built around the HIPAA three rules. Privacy, Security, and Breach Notification aren't separate programs. They're three dimensions of the same obligation — protecting the people whose data you hold.
Start by assessing where your gaps are. Then build training, policies, and response plans that address all three rules together. Your patients trust you with their most sensitive information. These three rules are how you prove that trust is warranted.
Explore our full catalog of role-specific HIPAA training programs at hipaacertify.com/training to build workforce training that actually maps to what your staff does every day.