Overview
HIPAA is a 1996 U.S. law. Its Security Rule sets national standards for protecting electronic protected health information (ePHI), meaning health information that identifies a person and is held or sent in electronic form. Regulated entities must protect its confidentiality, integrity, and availability, guard against reasonably anticipated threats, and train their workforce. The rule is flexible by design. Some implementation specifications are required, while others are addressable, meaning an organization can adopt a reasonable alternative if it documents why.
Vendors are covered too. Any company that creates, receives, maintains, or transmits PHI for a covered entity is a business associate, and so is its subcontractor that does the same. Covered entities must have a business associate agreement in place, and business associates are directly liable for meeting the Security Rule. The Breach Notification Rule adds duties to report breaches of unsecured PHI to individuals without unreasonable delay and within 60 days of discovery, and to HHS and, for breaches affecting more than 500 residents of a state, to the media.
HHS proposed a major update on January 6, 2025. It would remove the distinction between required and addressable specifications, require multi-factor authentication and encryption with limited exceptions, and add a technology asset inventory, network map, annual compliance audit, and restoration of certain systems within 72 hours. Comments closed on March 7, 2025. In its most recent Unified Agenda entry, HHS moved the rule to long-term actions with final action targeted for July 2027. Until a final rule is published, the current Security Rule applies.
Who it applies to in Canada
U.S. health plans, health care clearinghouses, and health care providers that bill electronically (covered entities), plus business associates and their subcontractors that create, receive, maintain, or transmit protected health information for them.
Canadian software, cloud, billing, transcription, and telehealth vendors that handle U.S. patient data become business associates and must sign business associate agreements that bind them to the Security Rule. Those contracts apply alongside Canadian privacy laws such as PIPEDA and provincial health privacy acts, which still govern the vendor in Canada.
Controls at a glance
The Security Rule is organized into standards in 45 CFR 164.308 to 164.316, each with required or addressable implementation specifications.
Administrative safeguards (164.308)
- Conduct an accurate and thorough risk analysis
- Manage risk to a reasonable and appropriate level
- Name a security official responsible for the program
- Control workforce access and apply sanctions
- Provide security awareness and training
- Handle security incidents and plan for contingencies
- Evaluate the program periodically
Physical safeguards (164.310)
- Control access to facilities housing ePHI systems
- Set rules for workstation use and security
- Control device and media disposal and reuse
- Track movement of hardware and media
Technical safeguards (164.312)
- Unique user IDs and access controls
- Audit controls that record system activity
- Protect ePHI from improper change or destruction
- Authenticate people and entities seeking access
- Protect ePHI sent over networks
Encryption is currently addressable. The 2025 proposal would make it required.
Organizational requirements (164.314)
- Business associate agreements with required terms
- Business associates flow terms down to subcontractors
- Report security incidents and breaches to the covered entity
- Group health plan safeguards for plan sponsors
Policies, procedures, and documentation (164.316)
- Adopt written policies and procedures
- Keep documentation for 6 years
- Make documents available to those who use them
- Review and update documentation periodically
Breach notification (164.400 to 164.414)
- Notify affected individuals within 60 days of discovery
- Notify HHS of breaches of unsecured PHI
- Notify media for breaches over 500 residents of a state
- Business associates notify the covered entity
Certification and assessment
No official HIPAA certification exists. Organizations show compliance through documented risk analyses, policies, and safeguards, and OCR can investigate, require corrective action plans, and impose civil money penalties. Customers often ask vendors for independent evidence, such as a SOC 2 report or HITRUST certification, as part of signing a business associate agreement.
Dates to know
- 2025-01-06
- HHS publishes the proposed Security Rule update (90 FR 898)
- 2025-03-07
- Comment period on the proposed update closes
- 2027-07
- Target for final action on the proposed update in HHS's most recent Unified Agenda entry (not binding)
Resources
Official texts and free tools for HIPAA. Links open the publisher’s site.
- 45 CFR part 164, subpart C, Security Standards for the Protection of ePHI, Electronic Code of Federal Regulations
- 45 CFR part 164, subpart D, Notification in the Case of Breach of Unsecured PHI, Electronic Code of Federal Regulations
- 45 CFR 160.103 definitions, including business associate, Electronic Code of Federal Regulations
- HIPAA Security Rule to Strengthen the Cybersecurity of ePHI (proposed rule, 90 FR 898), Federal Register via govinfo.gov
- NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule, NISTguidance
- Security Risk Assessment Tool, HealthIT.gov, U.S. Department of Health and Human Servicestool
Need help? Browse the directory or read the guides.
References
- 45 CFR part 164, subpart C, Electronic Code of Federal Regulations
- HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025), Federal Register via govinfo.gov
- Unified Agenda entry RIN 0945-AA22, Office of Information and Regulatory Affairs, reginfo.gov
- 45 CFR part 164, subpart D, Electronic Code of Federal Regulations
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.