home / frameworks / hipaa

// U.S. frameworks that reach Canada

HIPAA Security Rule (Health Insurance Portability and Accountability Act)

The HIPAA Security Rule requires U.S. health organizations and their business associates to protect electronic protected health information with administrative, physical, and technical safeguards. A stricter update proposed in January 2025 is not yet final.

United States

Overview

HIPAA is a 1996 U.S. law. Its Security Rule sets national standards for protecting electronic protected health information (ePHI), meaning health information that identifies a person and is held or sent in electronic form. Regulated entities must protect its confidentiality, integrity, and availability, guard against reasonably anticipated threats, and train their workforce. The rule is flexible by design. Some implementation specifications are required, while others are addressable, meaning an organization can adopt a reasonable alternative if it documents why.

Vendors are covered too. Any company that creates, receives, maintains, or transmits PHI for a covered entity is a business associate, and so is its subcontractor that does the same. Covered entities must have a business associate agreement in place, and business associates are directly liable for meeting the Security Rule. The Breach Notification Rule adds duties to report breaches of unsecured PHI to individuals without unreasonable delay and within 60 days of discovery, and to HHS and, for breaches affecting more than 500 residents of a state, to the media.

HHS proposed a major update on January 6, 2025. It would remove the distinction between required and addressable specifications, require multi-factor authentication and encryption with limited exceptions, and add a technology asset inventory, network map, annual compliance audit, and restoration of certain systems within 72 hours. Comments closed on March 7, 2025. In its most recent Unified Agenda entry, HHS moved the rule to long-term actions with final action targeted for July 2027. Until a final rule is published, the current Security Rule applies.

Who it applies to in Canada

U.S. health plans, health care clearinghouses, and health care providers that bill electronically (covered entities), plus business associates and their subcontractors that create, receive, maintain, or transmit protected health information for them.

Canadian software, cloud, billing, transcription, and telehealth vendors that handle U.S. patient data become business associates and must sign business associate agreements that bind them to the Security Rule. Those contracts apply alongside Canadian privacy laws such as PIPEDA and provincial health privacy acts, which still govern the vendor in Canada.

Controls at a glance

The Security Rule is organized into standards in 45 CFR 164.308 to 164.316, each with required or addressable implementation specifications.

Administrative safeguards (164.308)

  • Conduct an accurate and thorough risk analysis
  • Manage risk to a reasonable and appropriate level
  • Name a security official responsible for the program
  • Control workforce access and apply sanctions
  • Provide security awareness and training
  • Handle security incidents and plan for contingencies
  • Evaluate the program periodically

Physical safeguards (164.310)

  • Control access to facilities housing ePHI systems
  • Set rules for workstation use and security
  • Control device and media disposal and reuse
  • Track movement of hardware and media

Technical safeguards (164.312)

  • Unique user IDs and access controls
  • Audit controls that record system activity
  • Protect ePHI from improper change or destruction
  • Authenticate people and entities seeking access
  • Protect ePHI sent over networks

Encryption is currently addressable. The 2025 proposal would make it required.

Organizational requirements (164.314)

  • Business associate agreements with required terms
  • Business associates flow terms down to subcontractors
  • Report security incidents and breaches to the covered entity
  • Group health plan safeguards for plan sponsors

Policies, procedures, and documentation (164.316)

  • Adopt written policies and procedures
  • Keep documentation for 6 years
  • Make documents available to those who use them
  • Review and update documentation periodically

Breach notification (164.400 to 164.414)

  • Notify affected individuals within 60 days of discovery
  • Notify HHS of breaches of unsecured PHI
  • Notify media for breaches over 500 residents of a state
  • Business associates notify the covered entity

Certification and assessment

No official HIPAA certification exists. Organizations show compliance through documented risk analyses, policies, and safeguards, and OCR can investigate, require corrective action plans, and impose civil money penalties. Customers often ask vendors for independent evidence, such as a SOC 2 report or HITRUST certification, as part of signing a business associate agreement.

Dates to know

2025-01-06
HHS publishes the proposed Security Rule update (90 FR 898)
2025-03-07
Comment period on the proposed update closes
2027-07
Target for final action on the proposed update in HHS's most recent Unified Agenda entry (not binding)

Resources

Official texts and free tools for HIPAA. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. 45 CFR part 164, subpart C, Electronic Code of Federal Regulations
  2. HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025), Federal Register via govinfo.gov
  3. Unified Agenda entry RIN 0945-AA22, Office of Information and Regulatory Affairs, reginfo.gov
  4. 45 CFR part 164, subpart D, Electronic Code of Federal Regulations