/
/

What Is HIPAA Compliance? Everything You Need to Know

by Lauren Ballejos, IT Editorial Expert
HIPAA Compliance: Everything You Need to Know blog banner image
HIPAA Compliance: Everything You Need to Know blog banner image

Key Points

  • HIPAA is a 1996 federal law that protects patients’ health information while ensuring the flow of data for quality care.
  • Covered entities and their business associates must both comply, backed by signed BAAs.
  • Four rules govern compliance: Privacy, Security, Enforcement, and Breach Notification.
  • A major Security Rule overhaul (MFA, encryption, annual risk assessments) has been proposed since 2025, but it still isn’t final.
  • Violations can cost up to millions of dollars per year, plus possible criminal penalties.

* Editor’s Note: This article has been updated to reflect updates to HIPAA compliance requirements as of mid-2026. For instance, HHS/OCR proposed significant Security Rule updates (published January 6, 2025), though these are not final. The current HIPAA rules still apply; there is no confirmed date for when, or whether, a final rule will be issued.

In this article, we discuss in depth everything you need to know about HIPAA compliance. HIPAA was introduced with two main objectives

  • to protect individuals’ health information while allowing the flow of health information needed to provide high-quality health care
  • to protect the public’s health and well-being.

What is HIPAA compliance?

HIPAA — the Health Insurance Portability and Accountability Act — is a federal law enacted in 1996 aimed at improving the efficiency and effectiveness of the healthcare system. HIPAA promotes the protection and confidential handling of protected health information (PHI). HIPAA compliance means adhering to the standards and provisions set by the act to safeguard PHI from unauthorized access and breaches.

NinjaOne strengthens endpoint management in healthcare settings.

→ See how NinjaOne simplifies healthcare IT.

What are the HIPAA compliance requirements?

To comply with HIPAA, your covered entity and business associates must adhere to specific rules and regulations designed to protect PHI:

Privacy Rule

The Privacy Rule establishes national standards for protecting PHI. It applies to all forms of individuals’ PHI, electronic, written, and oral. The main goals of the rule are as follows:

  • Limit the use and disclosure of PHI for specific purposes, such as treatment, payment, and healthcare operations, unless explicit authorization is obtained from the patient.
  • Ensure patient rights over health information, including
    • obtaining a copy of their records,
    • requesting corrections, and
    • being informed about how their information is used and disclosed.
  • Implement administrative, physical and technical safeguards to protect the privacy of PHI.

Recent and proposed HIPAA rule updates:

  • Reproductive health privacy: The Office for Civil Rights (OCR), the agency responsible for enforcing HIPAA, proposed a final rule in 2024 that strengthened reproductive health privacy. The rule prohibited using PHI to investigate or penalize lawful reproductive care unless a signed attestation was obtained. However, this was acated nationwide by a federal judge in the Northern District of Texas on June 18, 2025 (Purl v. HHS). Those enhanced protections and the attestation requirement are no longer in effect. The court did leave in place a narrower set of Notice of Privacy Practices (NPP) updates tied to substance-use-disorder (42 CFR Part 2) records, which carry a February 16, 2026, compliance date.
  • Access and coordination enhancements: A separate, long-pending 2020 proposal would clarify patient access timing, eliminate written acknowledgment of NPP receipt, allow caregiver disclosures, reduce barriers to treatment/payment/operations sharing, and update definitions like “electronic health record.” It has not been finalized.

Security Rule

The Security Rule complements the Privacy Rule by specifically addressing electronic PHI (ePHI). It establishes standards for the security of ePHI and mandates the implementation of security measures to protect against threats to data integrity, confidentiality and availability. The Security Rule is divided into three categories of safeguards:

  • Administrative safeguards: Policies and procedures designed to manage the selection, development, implementation and maintenance of security measures to protect ePHI.
  • Physical safeguards: Measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion.
  • Technical safeguards: The technology and policies that protect ePHI and control access to it, including measures like encryption, access controls and audit controls.

Proposed HIPAA rule updates:

Status: proposed, not final, as of mid-2026

  • Mandatory multi-factor authentication (MFA): All regulated entities must implement MFA to enhance security and prevent unauthorized access to ePHII.
  • Encryption requirements: The encryption of ePHI at rest and in transit is now mandatory, rather than “addressable,” to strengthen data protection measures.
  • Annual security risk assessments: Entities must conduct a comprehensive security risk assessment at least once per year to identify security vulnerabilities.
  • Enhanced vendor oversight: Business associates must notify covered entities within 24 hours if they activate their contingency plans due to a security incident.
  • Technology asset inventories and network mapping: Organizations must maintain an up-to-date inventory of their technology assets and map ePHI data flows within their network.

Additional consideration: This proposal was published in the Federal Register on January 6, 2025, with the comment period closing March 7, 2025. OCR had targeted finalization for May 2026; that date has passed without a final rule, and a coalition of over 100 hospital and provider associations has asked HHS to withdraw the proposal outright, citing an estimated $9 billion first-year compliance cost. There is currently no confirmed date for finalization.

Enforcement Rule

The Enforcement Rule sets the standards for the enforcement of all the Administrative Simplification Rules, including the Privacy and Security Rules. This rule outlines the investigation process, penalties for non-compliance, and procedures for hearings and appeals. Penalties for non-compliance can be severe

As of the most recent inflation adjustment (effective January 28, 2026), civil monetary penalties are:

  • Tier 1 (no knowledge): $145–$73,011 per violation
  • Tier 2 (reasonable cause): $1,461–$73,011 per violation
  • Tier 3 (willful neglect, corrected within 30 days): $14,602–$73,011 per violation
  • Tier 4 (willful neglect, not corrected): $73,011–$2,190,294 per violation

Each tier carries a statutory annual cap of $2,190,294 for violations of an identical provision, though OCR’s 2019 Notice of Enforcement Discretion currently applies lower annual caps to Tiers 1–3 (roughly $36,506, $146,053, and $365,052, respectively) unless and until that policy is rescinded. These amounts are adjusted for inflation annually.

Criminal penalties can be imposed for the deliberate misuse of PHI and can result in fines of up to $250,000 and imprisonment for up to 10 years.

Proposed HIPAA rule updates:

  • Stricter penalty tiers: OCR has signaled interest in higher fines for repeated violations and willful neglect of HIPAA compliance as part of the broader Security Rule overhaul.
  • Increased investigative authority: Regulators have proposed authority to conduct audits and investigations, including unannounced compliance checks.
  • Greater individual rights enforcement: OCR continues to actively enforce patient right-of-access cases, with penalties for delays or failures to provide requested information.

Breach Notification Rule

The Breach Notification Rule requires that you notify affected individuals, the Secretary of HHS, and (in some cases) the media when there is a breach of unsecured PHI. The rule outlines specific requirements for breach notification:

  • Notification to individuals: Affected individuals must be notified without unreasonable delay and no later than 60 days following the discovery of a breach.
  • Notification to HHS: If a breach affects 500 or more individuals, the covered entity must notify HHS without unreasonable delay and no later than 60 days from discovery. For breaches affecting fewer than 500 individuals, the covered entity can notify HHS annually, no later than 60 days after the end of the calendar year in which the breach was discovered.
  • Notification to the media: If a breach affects more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the area.

Proposed and related HIPAA rule updates:

  • No shorter notification timeframes: The 60-day windows above remain unchanged. What has changed is a separate, proposed requirement under the Security Rule, where business associates would need to notify covered entities within 24 hours of activating a contingency plan following a security incident.
  • Mandatory notification of cybersecurity events: Under the proposed Security Rule update, more security incidents affecting ePHI would trigger internal notification obligations between business associates, subcontractors, and covered entities, even where the incident doesn’t rise to a reportable “breach.”
  • Additional state and local notification requirements: Some jurisdictions require notifications beyond federal requirements, and covered entities should track state law independently, as it can impose shorter deadlines than HIPAA’s. .

Who needs to be HIPAA compliant?

HIPAA compliance is required for two primary groups: covered entities and business associates.

Covered entities

Covered entities include:

  • Health plans, including health insurance companies, HMOs, company health plans, and certain government programs that pay for healthcare.
  • Healthcare clearinghouses that process nonstandard health information they receive from another entity into a standard format (or vice versa).
  • Healthcare providers, including doctors, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies and any other entity that provides healthcare services and transmits any health information in electronic form.

Business associates

Business associates are individuals or entities that perform functions or activities on behalf of or provide certain services to, a covered entity that involve the use or disclosure of PHI. Examples of business associates include:

  • Third-party billing companies
  • IT service providers
  • Consultants
  • Data storage companies

Business associates are also required to comply with HIPAA regulations and must sign a business associate agreement (BAA) with the covered entities they work with.

HIPAA compliance best practices

To achieve and maintain HIPAA compliance, you should follow several HIPAA compliance best practices:

Risk assessment and management

Regular risk assessments are necessary to identify potential vulnerabilities in the handling of PHI. A thorough risk assessment includes these steps:

  1. Identify and document potential risks and vulnerabilities: Examine all aspects of how PHI is created, received, maintained, and transmitted.
  2. Analyze the likelihood and impact of potential threats: This helps prioritize the risks and determine the necessary safeguards.
  3. Implement appropriate security measures: Based on the risk analysis, you should implement measures to mitigate identified risks.
  4. Regularly review and update the risk assessment: Continuous monitoring and updating of the risk assessment process verifies that new threats are identified and addressed promptly.

Employee training and awareness

Train employees on HIPAA regulations and the importance of protecting PHI. Effective training programs should do the following:

  • Cover HIPAA basics: Educate all employees to understand the key components of HIPAA and their responsibilities.
  • Include specific policies and procedures: Train employees on the specific policies and procedures to guarantee compliance.
  • Offer regular updates: Provide ongoing training to keep employees informed about changes in HIPAA regulations and emerging threats.
  • Encourage a culture of compliance: Foster an environment where employees feel responsible for protecting PHI and are encouraged to report potential breaches.

Data encryption and protection

Encrypting sensitive health information is a fundamental security measure so that if data is intercepted, it cannot be read without the encryption key. Best practices for data encryption include:

  • Encrypt data at rest and in transit: Protect PHI both when it is stored and when it is transmitted over networks.
  • Use strong encryption standards: Verify that encryption methods meet current industry standards and are regularly updated to address new threats.
  • Implement secure key management practices: Properly manage encryption keys to prevent unauthorized access.

NinjaOne provides several cloud-based software solutions to help organizations remain HIPAA compliant.

See how NinjaOne helps in your HIPAA compliance efforts.

Access control and authentication

Controlling access to PHI is an important part of preventing unauthorized access. Effective access control and authentication measures include:

  • Implement role-based access controls (RBAC): Limit access to PHI based on an individual’s role within the organization.
  • Use strong authentication methods: Implement MFA to add an extra layer of security.
  • Regularly review access controls: Periodically review and update access permissions so that only authorized individuals have access to PHI.

Audit trails and monitoring

Maintaining audit trails and monitoring access to PHI can help detect and respond to suspicious activities. Best practices for audit trails and monitoring include:

  • Implement logging mechanisms: Log all access to and activity involving PHI to create a record of who accessed what information and when.
  • Review audit records: Periodically review audit logs to identify unusual or unauthorized activity.
  • Use automated monitoring tools: Automatically detect and alert administrators to potential security incidents.

Consequences of non-compliance

Failure to comply with HIPAA regulations can lead to severe consequences, including

  • Financial penalties
  • Legal actions
  • Reputational damage
  • Significant operational disruptions.

The software you use in the healthcare industry or serving healthcare clients plays a role in helping you comply with HIPAA. Using the right software can help you meet HIPAA standards and relax your mental load.

NinjaOne provides several cloud-based software solutions to help IT service providers grow their business with product features that can help you with your compliance efforts. Let NinjaOne help your organization stay HIPAA compliant.

FAQs

HIPAA compliance means following federal regulations that protect the privacy and security of protected health information (PHI) and electronic PHI (ePHI). It requires covered entities and business associates to implement administrative, physical, and technical safeguards.

Covered entities (healthcare providers, health plans, and clearinghouses) and their business associates (IT vendors, billing services, consultants, and data storage companies) must comply with HIPAA and sign business associate agreements (BAAs).

The four primary HIPAA rules are:

  • Privacy Rule (standards for PHI use/disclosure)
  • Security Rule (safeguards for ePHI)
  • Enforcement Rule (penalties and investigation processes)
  • Breach Notification Rule (requirements to notify patients, HHS, and media about data breaches)

As of January 28, 2026, inflation-adjusted civil penalties range from $145 to $2,190,294 per violation, depending on the level of culpability, with an annual cap of $2,190,294 per violation category (OCR’s 2019 enforcement-discretion policy currently applies lower annual caps to less-severe tiers).

Criminal penalties can include fines up to $250,000 and imprisonment for up to 10 years.

Organizations must notify affected individuals and HHS of a breach of unsecured PHI without unreasonable delay and no later than 60 days after discovery. Media notification is also required for breaches affecting 500 or more residents in a state or jurisdiction. This 60-day window is not currently subject to any proposed change.

The most significant pending change is the proposed Security Rule overhaul, with mandatory MFA, encryption of ePHI in transit and at rest, annual risk assessments, 24-hour vendor breach notifications, and technology asset inventories, first proposed in January 2025.

As of mid-2026, it remains unfinalized, with no confirmed date for a final rule. Separately, a 2024 rule strengthening reproductive health privacy was vacated by a federal court in June 2025, though a narrower, related set of NPP updates tied to substance-use-disorder records took effect on February 16, 2026.

Best practices include conducting regular risk assessments, encrypting PHI, implementing MFA and role-based access controls, training employees on HIPAA policies, maintaining audit logs, and using secure IT management tools to support compliance efforts.

You might also like

Ready to simplify the hardest parts of IT?