Key Points
- HIPAA is a 1996 federal law that protects patients’ health information while ensuring the flow of data for quality care.
- Covered entities and their business associates must both comply, backed by signed BAAs.
- Four rules govern compliance: Privacy, Security, Enforcement, and Breach Notification.
- A major Security Rule overhaul (MFA, encryption, annual risk assessments) has been proposed since 2025, but it still isn’t final.
- Violations can cost up to millions of dollars per year, plus possible criminal penalties.
* Editor’s Note: This article has been updated to reflect updates to HIPAA compliance requirements as of mid-2026. For instance, HHS/OCR proposed significant Security Rule updates (published January 6, 2025), though these are not final. The current HIPAA rules still apply; there is no confirmed date for when, or whether, a final rule will be issued.
In this article, we discuss in depth everything you need to know about HIPAA compliance. HIPAA was introduced with two main objectives
- to protect individuals’ health information while allowing the flow of health information needed to provide high-quality health care
- to protect the public’s health and well-being.
What is HIPAA compliance?
HIPAA — the Health Insurance Portability and Accountability Act — is a federal law enacted in 1996 aimed at improving the efficiency and effectiveness of the healthcare system. HIPAA promotes the protection and confidential handling of protected health information (PHI). HIPAA compliance means adhering to the standards and provisions set by the act to safeguard PHI from unauthorized access and breaches.
NinjaOne strengthens endpoint management in healthcare settings.
What are the HIPAA compliance requirements?
To comply with HIPAA, your covered entity and business associates must adhere to specific rules and regulations designed to protect PHI:
Privacy Rule
The Privacy Rule establishes national standards for protecting PHI. It applies to all forms of individuals’ PHI, electronic, written, and oral. The main goals of the rule are as follows:
- Limit the use and disclosure of PHI for specific purposes, such as treatment, payment, and healthcare operations, unless explicit authorization is obtained from the patient.
- Ensure patient rights over health information, including
- obtaining a copy of their records,
- requesting corrections, and
- being informed about how their information is used and disclosed.
- Implement administrative, physical and technical safeguards to protect the privacy of PHI.
Recent and proposed HIPAA rule updates:
- Reproductive health privacy: The Office for Civil Rights (OCR), the agency responsible for enforcing HIPAA, proposed a final rule in 2024 that strengthened reproductive health privacy. The rule prohibited using PHI to investigate or penalize lawful reproductive care unless a signed attestation was obtained. However, this was acated nationwide by a federal judge in the Northern District of Texas on June 18, 2025 (Purl v. HHS). Those enhanced protections and the attestation requirement are no longer in effect. The court did leave in place a narrower set of Notice of Privacy Practices (NPP) updates tied to substance-use-disorder (42 CFR Part 2) records, which carry a February 16, 2026, compliance date.
- Access and coordination enhancements: A separate, long-pending 2020 proposal would clarify patient access timing, eliminate written acknowledgment of NPP receipt, allow caregiver disclosures, reduce barriers to treatment/payment/operations sharing, and update definitions like “electronic health record.” It has not been finalized.
Security Rule
The Security Rule complements the Privacy Rule by specifically addressing electronic PHI (ePHI). It establishes standards for the security of ePHI and mandates the implementation of security measures to protect against threats to data integrity, confidentiality and availability. The Security Rule is divided into three categories of safeguards:
- Administrative safeguards: Policies and procedures designed to manage the selection, development, implementation and maintenance of security measures to protect ePHI.
- Physical safeguards: Measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion.
- Technical safeguards: The technology and policies that protect ePHI and control access to it, including measures like encryption, access controls and audit controls.
Proposed HIPAA rule updates:
Status: proposed, not final, as of mid-2026
- Mandatory multi-factor authentication (MFA): All regulated entities must implement MFA to enhance security and prevent unauthorized access to ePHII.
- Encryption requirements: The encryption of ePHI at rest and in transit is now mandatory, rather than “addressable,” to strengthen data protection measures.
- Annual security risk assessments: Entities must conduct a comprehensive security risk assessment at least once per year to identify security vulnerabilities.
- Enhanced vendor oversight: Business associates must notify covered entities within 24 hours if they activate their contingency plans due to a security incident.
- Technology asset inventories and network mapping: Organizations must maintain an up-to-date inventory of their technology assets and map ePHI data flows within their network.
Additional consideration: This proposal was published in the Federal Register on January 6, 2025, with the comment period closing March 7, 2025. OCR had targeted finalization for May 2026; that date has passed without a final rule, and a coalition of over 100 hospital and provider associations has asked HHS to withdraw the proposal outright, citing an estimated $9 billion first-year compliance cost. There is currently no confirmed date for finalization.
Enforcement Rule
The Enforcement Rule sets the standards for the enforcement of all the Administrative Simplification Rules, including the Privacy and Security Rules. This rule outlines the investigation process, penalties for non-compliance, and procedures for hearings and appeals. Penalties for non-compliance can be severe
As of the most recent inflation adjustment (effective January 28, 2026), civil monetary penalties are:
- Tier 1 (no knowledge): $145–$73,011 per violation
- Tier 2 (reasonable cause): $1,461–$73,011 per violation
- Tier 3 (willful neglect, corrected within 30 days): $14,602–$73,011 per violation
- Tier 4 (willful neglect, not corrected): $73,011–$2,190,294 per violation
Each tier carries a statutory annual cap of $2,190,294 for violations of an identical provision, though OCR’s 2019 Notice of Enforcement Discretion currently applies lower annual caps to Tiers 1–3 (roughly $36,506, $146,053, and $365,052, respectively) unless and until that policy is rescinded. These amounts are adjusted for inflation annually.
Criminal penalties can be imposed for the deliberate misuse of PHI and can result in fines of up to $250,000 and imprisonment for up to 10 years.
Proposed HIPAA rule updates:
- Stricter penalty tiers: OCR has signaled interest in higher fines for repeated violations and willful neglect of HIPAA compliance as part of the broader Security Rule overhaul.
- Increased investigative authority: Regulators have proposed authority to conduct audits and investigations, including unannounced compliance checks.
- Greater individual rights enforcement: OCR continues to actively enforce patient right-of-access cases, with penalties for delays or failures to provide requested information.
Breach Notification Rule
The Breach Notification Rule requires that you notify affected individuals, the Secretary of HHS, and (in some cases) the media when there is a breach of unsecured PHI. The rule outlines specific requirements for breach notification:
- Notification to individuals: Affected individuals must be notified without unreasonable delay and no later than 60 days following the discovery of a breach.
- Notification to HHS: If a breach affects 500 or more individuals, the covered entity must notify HHS without unreasonable delay and no later than 60 days from discovery. For breaches affecting fewer than 500 individuals, the covered entity can notify HHS annually, no later than 60 days after the end of the calendar year in which the breach was discovered.
- Notification to the media: If a breach affects more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the area.
Proposed and related HIPAA rule updates:
- No shorter notification timeframes: The 60-day windows above remain unchanged. What has changed is a separate, proposed requirement under the Security Rule, where business associates would need to notify covered entities within 24 hours of activating a contingency plan following a security incident.
- Mandatory notification of cybersecurity events: Under the proposed Security Rule update, more security incidents affecting ePHI would trigger internal notification obligations between business associates, subcontractors, and covered entities, even where the incident doesn’t rise to a reportable “breach.”
- Additional state and local notification requirements: Some jurisdictions require notifications beyond federal requirements, and covered entities should track state law independently, as it can impose shorter deadlines than HIPAA’s. .
Who needs to be HIPAA compliant?
HIPAA compliance is required for two primary groups: covered entities and business associates.
Covered entities
Covered entities include:
- Health plans, including health insurance companies, HMOs, company health plans, and certain government programs that pay for healthcare.
- Healthcare clearinghouses that process nonstandard health information they receive from another entity into a standard format (or vice versa).
- Healthcare providers, including doctors, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies and any other entity that provides healthcare services and transmits any health information in electronic form.
Business associates
Business associates are individuals or entities that perform functions or activities on behalf of or provide certain services to, a covered entity that involve the use or disclosure of PHI. Examples of business associates include:
- Third-party billing companies
- IT service providers
- Consultants
- Data storage companies
Business associates are also required to comply with HIPAA regulations and must sign a business associate agreement (BAA) with the covered entities they work with.
HIPAA compliance best practices
To achieve and maintain HIPAA compliance, you should follow several HIPAA compliance best practices:
Risk assessment and management
Regular risk assessments are necessary to identify potential vulnerabilities in the handling of PHI. A thorough risk assessment includes these steps:
- Identify and document potential risks and vulnerabilities: Examine all aspects of how PHI is created, received, maintained, and transmitted.
- Analyze the likelihood and impact of potential threats: This helps prioritize the risks and determine the necessary safeguards.
- Implement appropriate security measures: Based on the risk analysis, you should implement measures to mitigate identified risks.
- Regularly review and update the risk assessment: Continuous monitoring and updating of the risk assessment process verifies that new threats are identified and addressed promptly.
Employee training and awareness
Train employees on HIPAA regulations and the importance of protecting PHI. Effective training programs should do the following:
- Cover HIPAA basics: Educate all employees to understand the key components of HIPAA and their responsibilities.
- Include specific policies and procedures: Train employees on the specific policies and procedures to guarantee compliance.
- Offer regular updates: Provide ongoing training to keep employees informed about changes in HIPAA regulations and emerging threats.
- Encourage a culture of compliance: Foster an environment where employees feel responsible for protecting PHI and are encouraged to report potential breaches.
Data encryption and protection
Encrypting sensitive health information is a fundamental security measure so that if data is intercepted, it cannot be read without the encryption key. Best practices for data encryption include:
- Encrypt data at rest and in transit: Protect PHI both when it is stored and when it is transmitted over networks.
- Use strong encryption standards: Verify that encryption methods meet current industry standards and are regularly updated to address new threats.
- Implement secure key management practices: Properly manage encryption keys to prevent unauthorized access.
NinjaOne provides several cloud-based software solutions to help organizations remain HIPAA compliant.
Access control and authentication
Controlling access to PHI is an important part of preventing unauthorized access. Effective access control and authentication measures include:
- Implement role-based access controls (RBAC): Limit access to PHI based on an individual’s role within the organization.
- Use strong authentication methods: Implement MFA to add an extra layer of security.
- Regularly review access controls: Periodically review and update access permissions so that only authorized individuals have access to PHI.
Audit trails and monitoring
Maintaining audit trails and monitoring access to PHI can help detect and respond to suspicious activities. Best practices for audit trails and monitoring include:
- Implement logging mechanisms: Log all access to and activity involving PHI to create a record of who accessed what information and when.
- Review audit records: Periodically review audit logs to identify unusual or unauthorized activity.
- Use automated monitoring tools: Automatically detect and alert administrators to potential security incidents.
Consequences of non-compliance
Failure to comply with HIPAA regulations can lead to severe consequences, including
- Financial penalties
- Legal actions
- Reputational damage
- Significant operational disruptions.
The software you use in the healthcare industry or serving healthcare clients plays a role in helping you comply with HIPAA. Using the right software can help you meet HIPAA standards and relax your mental load.
NinjaOne provides several cloud-based software solutions to help IT service providers grow their business with product features that can help you with your compliance efforts. Let NinjaOne help your organization stay HIPAA compliant.

