In 2018, a small insurance company called Anthem paid $16 million to the Office for Civil Rights — the largest HIPAA settlement in history at that time. The root cause? Failures that traced directly back to two foundational frameworks that every covered entity in America is required to follow. If you've ever searched what are the two main rules of HIPAA, you're asking the single most important question in healthcare compliance. And the answer shapes everything your organization does with patient information.
Those two rules are the HIPAA Privacy Rule and the HIPAA Security Rule. They sound similar, and people confuse them constantly. But they cover different territory, impose different obligations, and trip up organizations in very different ways. I've spent years watching practices, hospitals, and business associates stumble over one or both. Here's what you actually need to know.
The Two Main Rules of HIPAA: Privacy and Security
Let me give you the direct answer first, then we'll unpack each one.
The Privacy Rule governs who can access protected health information (PHI) and how it can be used and disclosed. The Security Rule governs how electronic PHI (ePHI) must be protected through administrative, physical, and technical safeguards. One is about permissions and rights. The other is about locks, encryption, and system controls.
Think of it this way: the Privacy Rule says "you can't share this patient's lab results with their employer." The Security Rule says "you must encrypt the server where those lab results are stored."
Both rules are enforced by the HHS Office for Civil Rights (OCR), and violations of either can lead to penalties ranging from $100 to over $2 million per violation category, per year.
The HIPAA Privacy Rule: Controlling Who Sees PHI
The Privacy Rule, codified at 45 CFR Part 164, Subpart E, went into effect in 2003. It applies to all forms of PHI — paper, oral, and electronic.
What the Privacy Rule Actually Requires
At its core, the Privacy Rule establishes the "minimum necessary" standard. Your organization should only access, use, or disclose the minimum amount of PHI needed for a specific purpose. I've seen medical offices where every front-desk employee had full access to every patient's chart. That's a Privacy Rule violation waiting to happen.
Here's what the Privacy Rule mandates:
- Notice of Privacy Practices (NPP): Every covered entity must give patients a clear written notice explaining how their PHI will be used.
- Patient rights: Patients have the right to access their records, request corrections, and receive an accounting of disclosures.
- Use and disclosure limitations: PHI can be used for treatment, payment, and healthcare operations without authorization — but most other uses require the patient's written consent.
- Business associate agreements: If you share PHI with a vendor, you need a signed BAA that holds them to the same standards.
- Workforce training: Staff must be trained on privacy policies. Not once. Regularly.
Where Organizations Get Caught on the Privacy Rule
In my experience, the most common Privacy Rule failures aren't dramatic hacks. They're human errors. A nurse discussing a patient's diagnosis in a hospital hallway. A billing clerk emailing a spreadsheet of patient names and Social Security numbers to the wrong address. A receptionist posting a photo of a whiteboard with patient names visible in the background.
In 2019, OCR settled with the University of Rochester Medical Center for $3 million after discovering that the organization failed to encrypt mobile devices and lost a flash drive containing PHI. The privacy failures compounded the security ones.
The HIPAA Security Rule: Protecting ePHI from Threats
The Security Rule, found at 45 CFR Part 164, Subpart C, went into effect in 2005. It applies exclusively to electronic PHI — data stored or transmitted digitally.
The Three Safeguard Categories
The Security Rule organizes its requirements into three categories of safeguards. Every covered entity and business associate must implement all three.
1. Administrative Safeguards
- Conduct a thorough risk analysis to identify vulnerabilities to ePHI.
- Designate a security officer responsible for developing and implementing security policies.
- Implement workforce training programs so every employee understands their role in protecting ePHI.
- Create contingency plans for data backup, disaster recovery, and emergency operations.
2. Physical Safeguards
- Control physical access to facilities where ePHI is stored — locked server rooms, badge access, visitor logs.
- Implement workstation security policies — screens that auto-lock, positioning monitors away from public view.
- Establish device and media controls for disposing of or reusing hardware that once contained ePHI.
3. Technical Safeguards
- Implement access controls — unique user IDs, automatic logoff, encryption.
- Deploy audit controls that record who accessed what ePHI and when.
- Use integrity controls to ensure ePHI hasn't been altered or destroyed improperly.
- Secure transmission of ePHI through encryption during transit — especially email and file transfers.
The Risk Analysis Failure That Costs Millions
Here's a pattern I've seen over and over: OCR investigates a breach and discovers the organization never conducted a comprehensive risk analysis. It's the single most cited deficiency in HIPAA enforcement actions.
Premera Blue Cross paid $6.85 million in 2020 after a breach affecting over 10.4 million people. OCR found that Premera had failed to conduct an enterprise-wide risk analysis — a core Security Rule requirement. The breach had gone undetected for nearly nine months.
If your organization hasn't completed a risk analysis this year, you're already out of compliance. It's not optional. It's not a one-time event. The Security Rule requires ongoing risk management.
How the Privacy Rule and Security Rule Work Together
These two rules aren't independent silos. They're designed to reinforce each other. The Privacy Rule tells you what to protect. The Security Rule tells you how to protect it — at least for electronic data.
A solid HIPAA compliance program addresses both simultaneously. Your policies should cover who has access (Privacy Rule) and how that access is technically controlled (Security Rule). Your workforce training should explain both why sharing PHI improperly is prohibited and how to use systems securely.
This is exactly why I recommend organizations invest in comprehensive training that covers both rules together. The HIPAA training catalog at HIPAACertify includes courses that address Privacy Rule obligations alongside Security Rule safeguards — because in practice, your staff needs to understand both at the same time.
What About the Breach Notification Rule?
You might be wondering: what about the Breach Notification Rule? It's a fair question. While the Privacy Rule and Security Rule are universally recognized as the two main rules of HIPAA, the Breach Notification Rule (added by the HITECH Act in 2009) is sometimes considered a third pillar.
The Breach Notification Rule requires covered entities to notify affected individuals, HHS, and sometimes the media when unsecured PHI is breached. It's critical — but it's essentially a consequence framework that kicks in when the Privacy Rule or Security Rule has already been violated.
So when someone asks what are the two main rules of HIPAA, the answer remains the Privacy Rule and the Security Rule. The Breach Notification Rule is important, but it's built on top of those two foundations.
Practical Steps to Comply with Both Rules in 2026
Knowing the rules matters. Acting on them matters more. Here's what I tell every organization I work with:
- Conduct a risk analysis now. Not last year's. A current one that reflects your current systems, devices, and workflows.
- Review your Notice of Privacy Practices. Make sure it reflects actual current data practices, especially if you've added telehealth, patient portals, or new vendors.
- Audit your business associate agreements. If a vendor touches PHI and you don't have a signed BAA, you're exposed.
- Train every member of your workforce. Not just clinicians — front desk, billing, IT, janitorial staff who access areas with PHI. Everyone. Explore role-based HIPAA training options that match your organization's size and specialty.
- Document everything. OCR doesn't just ask what you did — they ask you to prove it. Policies without documentation are policies that don't exist in an investigation.
The Bottom Line on HIPAA's Two Main Rules
The Privacy Rule protects PHI by controlling who can access it, use it, and share it. The Security Rule protects ePHI by requiring specific administrative, physical, and technical safeguards. Together, they form the backbone of HIPAA compliance for every covered entity and business associate in the United States.
I've watched organizations pay millions in penalties because they treated these rules as abstract concepts instead of operational requirements. Your compliance program doesn't need to be complicated — but it does need to be real. Train your staff. Run your risk analysis. Lock down your systems. And if you haven't reviewed your program recently, start with a structured HIPAA training program that brings your entire workforce up to speed.
Because OCR doesn't care what you intended to do. They care what you actually did.