A dermatology practice in New England paid $150,000 to the Office for Civil Rights because a single employee left a spreadsheet of patient names and diagnoses on an unsecured server. The practice owner told investigators he thought HIPAA only applied to hospitals. That misunderstanding cost him six figures and a corrective action plan that consumed two years of his professional life. If you've ever typed "what are HIPPA laws" into a search bar — first, you're not alone (the double-P misspelling is the most common version of this query). Second, this post is exactly what you need.
HIPAA stands for the Health Insurance Portability and Accountability Act. Congress passed it in 1996. But the law you're really asking about — the one that gets practices fined and executives fired — has evolved dramatically since then. Let me walk you through what it actually means for your organization in 2026.
What Are HIPAA Laws, Really?
HIPAA is a federal law that protects patients' health information from being shared, stolen, or mishandled. It applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically — and their business associates, meaning vendors and contractors who handle protected health information (PHI) on their behalf.
The law is enforced by the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS). Penalties range from $100 per violation to over $2 million per violation category per year, depending on the level of negligence.
But calling HIPAA a single law is misleading. It's actually a framework built from several interconnected rules. Here's how the pieces fit together.
The Five Rules That Make Up HIPAA
1. The Privacy Rule
This is the rule most people mean when they ask about HIPAA. It governs how covered entities use and disclose PHI — everything from a patient's name and diagnosis to their Social Security number and insurance ID. The Privacy Rule gives patients rights: the right to access their own records, request corrections, and know who has seen their information.
In my experience, Privacy Rule violations are the most common because they're the easiest to commit. A nurse texts a patient's lab result to the wrong number. A front desk staffer confirms an appointment to an unauthorized caller. These small moments create real liability.
2. The Security Rule
The Security Rule focuses specifically on electronic protected health information (ePHI). It requires covered entities to implement administrative, physical, and technical safeguards. Think access controls, encryption, audit logs, and disaster recovery plans.
This is where I've seen small practices struggle the most. They assume a password on a laptop is enough. OCR disagrees. In 2018, Filefax, Inc. paid $100,000 for leaving medical records in an unlocked vehicle accessible to the public. Safeguards have to be comprehensive, documented, and tested.
3. The Breach Notification Rule
When PHI is compromised, you can't just fix the problem quietly. The Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media, within 60 days of discovering a breach. For breaches affecting 500 or more individuals, HHS publishes the incident on its public breach portal — sometimes called the "Wall of Shame."
I've watched organizations burn through weeks trying to decide whether an incident counts as a breach instead of activating their response protocol. That delay itself can become a violation. If your team doesn't have a tested incident response plan, our First 60 Minutes: Incident Response course walks through exactly what to do when a breach hits.
4. The Enforcement Rule
This rule gives OCR the authority to investigate complaints, conduct audits, and impose civil monetary penalties. It also establishes the tiered penalty structure — from "did not know" to "willful neglect uncorrected" — that determines how much a violation costs.
The Enforcement Rule is the reason HIPAA has real teeth. Without it, the Privacy and Security Rules would be suggestions.
5. The Omnibus Rule (2013)
The HITECH Act of 2009 and the 2013 Omnibus Rule modernized HIPAA for the digital age. The Omnibus Rule extended direct liability to business associates, tightened breach notification standards, and expanded patient rights. If your compliance program hasn't been updated since 2012, you're operating under an outdated version of the law.
Who Has to Follow HIPAA? It's More People Than You Think
Covered entities include hospitals, physician practices, dental offices, pharmacies, health insurance companies, and clearinghouses. But the law doesn't stop there.
Business associates — IT companies, billing services, cloud storage vendors, shredding companies, even law firms that handle PHI — are directly liable under HIPAA. Every business associate must sign a Business Associate Agreement (BAA) with the covered entity. No BAA, no legal basis for sharing PHI.
I've seen organizations assume that because they aren't a doctor's office, HIPAA doesn't apply to them. If you touch PHI in any form, you're in scope. Period.
The $4.75 Million Question: What Happens When You Violate HIPAA?
In 2017, Memorial Healthcare System paid $5.5 million to settle HIPAA violations after employees accessed the ePHI of 115,143 individuals without authorization. The investigation revealed that the organization failed to review audit logs and allowed former employees to retain access credentials.
OCR publishes all resolution agreements and civil money penalties on its enforcement actions page. I recommend reading through at least a dozen of them. The patterns are strikingly consistent: no risk analysis, no workforce training, no access controls, no incident response plan.
Penalties fall into four tiers:
- Tier 1: $100–$50,000 per violation (did not know)
- Tier 2: $1,000–$50,000 per violation (reasonable cause)
- Tier 3: $10,000–$50,000 per violation (willful neglect, corrected)
- Tier 4: $50,000 per violation (willful neglect, not corrected)
Annual caps apply per violation category. Criminal penalties — up to 10 years in prison — are handled by the Department of Justice for cases involving intent to sell or misuse PHI.
The Biggest Compliance Mistake I See Every Year
Organizations treat HIPAA as a one-time checkbox. They do a training session during onboarding, have employees sign an acknowledgment form, and never revisit it. That's not compliance. That's a paper trail waiting to fail an OCR investigation.
HIPAA requires ongoing workforce training, annual risk assessments, regular policy reviews, and documented evidence of all of it. The word "ongoing" appears throughout HHS guidance for a reason.
Your workforce is your largest attack surface. Every staff member who handles PHI needs to understand what they can share, who they can share it with, and what to do when something goes wrong. Our HIPAA Introduction Training 2026 covers all of this in a format designed for busy healthcare teams.
State Laws Add Another Layer
HIPAA sets the federal floor, but many states impose stricter requirements. Texas, for example, enforces the Texas Medical Records Privacy Act (HB 300), which requires specific employee training, applies to a broader range of entities than HIPAA, and carries its own penalty structure.
If your organization operates in Texas, you need training that addresses both federal and state requirements. Our Texas Medical Records Privacy Act (HB 300) Training is built specifically for that purpose.
California, New York, and several other states have their own enhanced privacy laws too. You should always check whether your state imposes obligations beyond what HIPAA requires.
How to Start Getting HIPAA Right Today
If you're reading this because you Googled what HIPAA laws are, here's your starting checklist:
- Conduct a risk analysis. Identify every place PHI lives in your organization — on paper, in email, on servers, in the cloud.
- Train your entire workforce. Not just clinicians. Front desk staff, billing teams, IT vendors — everyone who touches PHI.
- Document everything. Policies, training records, risk assessments, incident reports. If it's not written down, it didn't happen.
- Sign BAAs with every vendor that handles PHI on your behalf.
- Build an incident response plan. Know who does what in the first 60 minutes of a suspected breach.
- Review and update annually. HIPAA compliance isn't a project. It's an ongoing program.
HIPAA laws exist to protect patients. But they also protect your organization — from lawsuits, from regulatory penalties, and from the reputational damage that follows a preventable breach. The organizations that get this right aren't the ones with the biggest budgets. They're the ones that take the rules seriously every single day.