Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules
HIPAA
Health · Data security · Breach notification
The Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.
- Where
- Federal
- Citation
- 42 U.S.C. 1320d to 1320d-9; 45 CFR Parts 160 and 164
- Status
- In force
- In force since
- 2003-04-14
- Last amended
- 2024-06-25
- Enforced by
- HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations
- People can sue
- No
- Penalties
- Tiered civil money penalties by culpability, with a statutory top tier of $50,000 per violation and $1,500,000 per calendar year for identical violations (inflation-adjusted by HHS); criminal fines up to $250,000 and up to 10 years for wrongful disclosure with intent to sell or cause harm.
- Applies to
- Covered entities: health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions
- Business associates that create, receive, maintain, or transmit protected health information for covered entities
What a privacy notice must say
- Provide a Notice of Privacy Practices describing uses, disclosures, and individual rights; 2024 revisions (including Part 2 related content) apply from Feb. 16, 2026.45 CFR 164.520 · From 2026-02-16
Rights it gives people
- Honor rights to request amendment and to receive an accounting of disclosures.45 CFR 164.526, 164.528
- Give individuals access to their PHI in a designated record set, acting on requests within 30 days.45 CFR 164.524(b)(2)
Practices it requires
- Use or disclose protected health information only as the Privacy Rule permits or requires, or with a valid authorization; apply the minimum necessary standard.45 CFR 164.502(a)-(b), 164.508
Security duties
- Implement Security Rule administrative, physical, and technical safeguards for electronic PHI, including a risk analysis.45 CFR 164.306-164.316
Breach duties
- Notify HHS contemporaneously (and prominent media) for breaches affecting 500 or more individuals; log smaller breaches and report them to HHS annually.45 CFR 164.406, 164.408(b)-(c)
- Notify affected individuals of a breach of unsecured PHI without unreasonable delay and within 60 calendar days of discovery.45 CFR 164.404(b)
Other duties
- Obtain satisfactory assurances through business associate agreements before sharing PHI with business associates.45 CFR 164.502(e), 164.504(e)
Sources
- Official text
- 45 CFR Part 164 (eCFR)
- 45 CFR Part 160 (eCFR)
- 42 U.S.C. 1320d-5 (OLRC)
- 42 U.S.C. 1320d-6 (OLRC)
- Purl v. HHS, No. 2:24-cv-228-Z (N.D. Tex. June 18, 2025), Memorandum Opinion and Order (GovInfo)
- HHS, HIPAA Security Rule NPRM, 90 FR 898 (Jan. 6, 2025)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Current inflation-adjusted HIPAA civil money penalty amounts (45 CFR 102.3) were not checked | eCFR (as of 2026-09-20) still prints the vacated 2024 reproductive health provisions (e.g., 45 CFR 164.509); no HHS rule removing them was found | Sections 164.406, 164.508, 164.526, 164.528 were cited from the part structure without close reading
Research reference, not legal advice.