HIPAA (Health Insurance Portability and Accountability Act)

CG

Chad Griffith, Founder & CEO

FileFlo: AI compliance document intelligence for DOT, OSHA, and EPA regulated businesses. LinkedIn · About

Last reviewed · By Chad Griffith

HIPAA, the Health Insurance Portability and Accountability Act of 1996, is the US federal law that establishes national standards for protected health information (PHI). Implementing regulations are in 45 CFR Parts 160, 162, and 164. The Privacy Rule (Part 164 Subpart E) governs use and disclosure of PHI; the Security Rule (Subpart C) requires administrative, physical, and technical safeguards for electronic PHI; the Breach Notification Rule (Subpart D) requires notification of unauthorized disclosures. HIPAA applies to 'covered entities' (health plans, healthcare clearinghouses, and most healthcare providers) and 'business associates' (vendors handling PHI). Civil penalties range from $145 to $2,190,294 per violation at the amounts in 45 CFR 102.3 (2025 column, read on eCFR 2026-09-09).

Frequently Asked Questions

Who must comply with HIPAA?

Per 45 CFR 160.103, HIPAA covers: (1) health plans (insurers, HMOs, ERISA group plans, government programs); (2) healthcare clearinghouses (billing services, repricing companies); (3) healthcare providers who transmit health information electronically in connection with covered transactions. Business associates (vendors handling PHI on behalf of covered entities) are also directly liable under HIPAA, including subcontractors.

What are the four HIPAA rules?

(1) Privacy Rule (45 CFR 164 Subpart E), governs use and disclosure of PHI; (2) Security Rule (Subpart C), administrative, physical, and technical safeguards for ePHI; (3) Breach Notification Rule (Subpart D), notification requirements for unauthorized PHI disclosures; (4) Enforcement Rule (45 CFR 160 Subparts C, D, E), investigation procedures and civil money penalty schedules.

What documents prove HIPAA compliance?

Required documentation: written policies and procedures (Privacy and Security), risk analysis under 164.308(a)(1)(ii)(A), risk management plan, security incident response plan, business associate agreements (BAAs) with all vendors, training records, sanction policy and applied sanctions, accounting of disclosures, and breach incident logs. Records must be retained for 6 years from creation or last effective date (45 CFR 164.530(j)).

What are 2026 HIPAA penalty amounts?

Civil money penalties under 45 CFR 160.404 are tiered by culpability, at the amounts in 45 CFR 102.3, 2025 column, read on eCFR 2026-09-09: Tier 1 (did not know) $145 to $73,011 per violation; Tier 2 (reasonable cause, not willful neglect) $1,461 to $73,011 per violation; Tier 3 (willful neglect, corrected within 30 days) $14,602 to $73,011 per violation; Tier 4 (willful neglect, not corrected) $73,011 to $2,190,294 per violation. Calendar-year cap for violations of an identical provision: $2,190,294.

Authoritative sources

Related terms

FileFlo classifies and tracks compliance documents against rule packs that map directly to the regulators referenced above. Run a free CFR-cited audit →