A hospital employee in Texas looks up her ex-husband's medical records after a bitter custody dispute. A small clinic in Georgia stores patient files on an unencrypted laptop that gets stolen from the back seat of a car. A dental office emails a treatment plan to the wrong patient. Three completely different scenarios — and every single one of them is a HIPAA violation. If you've ever asked what are the HIPAA rules, you're really asking one question: what are the boundaries around using, sharing, and protecting patient information?
I've spent years helping covered entities understand these rules, and I'll tell you — most people get lost because they treat HIPAA like one big regulation. It's not. It's a set of interconnected rules, each with its own requirements, each with real enforcement teeth. Let's break them down.
What Are the HIPAA Rules, Exactly?
HIPAA — the Health Insurance Portability and Accountability Act of 1996 — is federal law. But the rules most people reference when they say "HIPAA" are actually a series of regulations published by the U.S. Department of Health and Human Services (HHS). There are three major rules that every covered entity and business associate needs to know:
- The Privacy Rule
- The Security Rule
- The Breach Notification Rule
Each rule has a distinct purpose, and each one carries its own compliance requirements. Failing on any one of them can lead to civil monetary penalties, corrective action plans, and in extreme cases, criminal charges. Let's walk through them one at a time.
The Privacy Rule: Who Can See What — and When
The Privacy Rule, finalized in 2003, governs the use and disclosure of protected health information (PHI). PHI is any individually identifiable health information — a name tied to a diagnosis, a Social Security number tied to a treatment plan, a phone number tied to a prescription record.
Here's where most organizations trip up: the Privacy Rule doesn't say "never share PHI." It says you can share PHI under specific circumstances — for treatment, payment, and healthcare operations — and it limits disclosures beyond that. You need to apply the minimum necessary standard, meaning you only share the minimum amount of PHI required to accomplish the task.
Patient Rights Under the Privacy Rule
Patients have real, enforceable rights under this rule. They can request access to their own medical records. They can ask for corrections. They can request an accounting of disclosures — a log of who accessed their PHI and why. And your organization has to respond within specific timeframes.
The Office for Civil Rights (OCR), the enforcement arm of HHS, has made it clear that denying patients access to their records is a top enforcement priority. In 2023, OCR settled with Optum Medical Care for $160,000 after the organization failed to provide a patient timely access to their records. These aren't theoretical penalties. They're real.
You can read more about OCR's enforcement actions on the HHS enforcement page.
The Security Rule: Locking Down ePHI
The Privacy Rule tells you what to protect. The Security Rule tells you how to protect electronic protected health information (ePHI). Published in 2003 and enforced since 2005, the Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards.
Administrative Safeguards
This is where workforce training lives. You must designate a security officer. You must conduct a risk analysis. You must train every member of your workforce on your security policies. If you haven't completed a comprehensive risk analysis, you're already out of compliance — and that's the single most-cited deficiency in OCR investigations.
Building a workforce that understands these obligations starts with structured training. The HIPAA training catalog at HIPAACertify covers the Security Rule requirements in detail and can help your team close gaps before OCR comes knocking.
Physical Safeguards
Think beyond cybersecurity. Physical safeguards mean controlling who can walk into your server room, locking filing cabinets that contain PHI, and positioning computer screens so visitors can't read patient data in your lobby. I've seen clinics invest heavily in firewalls while leaving paper charts on an open counter. Both vectors matter.
Technical Safeguards
Encryption, access controls, audit logs, and automatic logoff. The Security Rule doesn't mandate specific technologies, but it requires you to evaluate threats and implement reasonable and appropriate measures. If you store ePHI on a laptop and don't encrypt it, you'll have a very hard time defending a breach.
For the full regulatory text on the Security Rule, visit 45 CFR Part 164, Subpart C on Cornell Law.
The Breach Notification Rule: What Happens When Things Go Wrong
The Breach Notification Rule, added by the HITECH Act in 2009, requires covered entities to notify affected individuals, HHS, and in some cases the media, when unsecured PHI is breached. A breach is defined as an impermissible use or disclosure that compromises the security or privacy of PHI.
The 60-Day Clock
Once you discover a breach, the clock starts. You have 60 days to notify affected individuals. If the breach involves 500 or more individuals, you must also notify OCR and prominent media outlets in the affected state. Breaches involving fewer than 500 individuals get reported to OCR annually.
Many organizations don't realize they also need to document breaches that don't trigger notification — because if OCR audits you, they'll want to see your breach log and your risk assessment explaining why notification wasn't required.
What Makes a Breach "Unsecured"?
If PHI was encrypted to NIST standards at the time of the incident, it's considered "secured" and notification isn't required. That's a powerful incentive to encrypt everything. I've seen organizations save themselves from multi-million-dollar headaches simply because they encrypted a stolen laptop's hard drive.
The $4.75 Million Lesson from Memorial Healthcare System
If you want to understand why these rules matter in practice, look at Memorial Healthcare System. In 2017, OCR announced a $5.5 million settlement after employees accessed PHI of over 115,000 individuals without authorization. The investigation revealed inadequate audit controls and a failure to regularly review system activity — both Security Rule requirements.
That's not a one-off. Banner Health paid $1.25 million in 2023 for a breach affecting nearly 3 million people. In every major enforcement action, the root cause traces back to a failure in one of the three core HIPAA rules.
Who Has to Follow the HIPAA Rules?
The HIPAA rules apply to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. They also apply to business associates: any vendor, contractor, or partner that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
If you're a billing company, an IT service provider, a cloud hosting vendor, or even a shredding company that handles documents containing PHI, you're a business associate. You need a business associate agreement (BAA) in place, and you're directly liable under the HIPAA rules.
How Do the HIPAA Rules Get Enforced?
OCR enforces the HIPAA rules through complaint investigations, compliance reviews, and audits. Penalties range from $141 per violation (for unknowing violations) up to nearly $2.1 million per violation category per year, adjusted for inflation. Criminal penalties — including fines up to $250,000 and imprisonment — are handled by the Department of Justice.
OCR doesn't just go after large health systems. Small practices, solo practitioners, and business associates have all faced enforcement. In my experience, the organizations that get hit hardest are the ones that never completed a risk analysis and never trained their workforce.
Your First Step: Train Every Member of Your Workforce
The HIPAA rules require workforce training. Not optional. Not "when we get around to it." Every employee, volunteer, trainee, and contractor with access to PHI must understand the Privacy Rule, the Security Rule, and the Breach Notification Rule.
If your team hasn't been through training recently — or if you're relying on a one-time orientation from three years ago — that's a compliance gap. Explore the HIPAA training options at HIPAACertify to bring your organization current.
Understanding what are the HIPAA rules isn't just an academic exercise. It's the foundation of every compliance program. Get the rules right, train your people, document everything, and you won't be the next cautionary tale on the HHS wall of shame.