Privacy Law Library

Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules

HIPAA

Health · Data security · Breach notification

The Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.

Where
Federal
Citation
42 U.S.C. 1320d to 1320d-9; 45 CFR Parts 160 and 164
Status
In force
In force since
2003-04-14
Last amended
2024-06-25
Enforced by
HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations
People can sue
No
Penalties
Tiered civil money penalties by culpability, with a statutory top tier of $50,000 per violation and $1,500,000 per calendar year for identical violations (inflation-adjusted by HHS); criminal fines up to $250,000 and up to 10 years for wrongful disclosure with intent to sell or cause harm.
Applies to
  • Covered entities: health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions
  • Business associates that create, receive, maintain, or transmit protected health information for covered entities

What a privacy notice must say

  • Provide a Notice of Privacy Practices describing uses, disclosures, and individual rights; 2024 revisions (including Part 2 related content) apply from Feb. 16, 2026.45 CFR 164.520 · From 2026-02-16

Rights it gives people

  • Honor rights to request amendment and to receive an accounting of disclosures.45 CFR 164.526, 164.528
  • Give individuals access to their PHI in a designated record set, acting on requests within 30 days.45 CFR 164.524(b)(2)

Practices it requires

  • Use or disclose protected health information only as the Privacy Rule permits or requires, or with a valid authorization; apply the minimum necessary standard.45 CFR 164.502(a)-(b), 164.508

Security duties

  • Implement Security Rule administrative, physical, and technical safeguards for electronic PHI, including a risk analysis.45 CFR 164.306-164.316

Breach duties

  • Notify HHS contemporaneously (and prominent media) for breaches affecting 500 or more individuals; log smaller breaches and report them to HHS annually.45 CFR 164.406, 164.408(b)-(c)
  • Notify affected individuals of a breach of unsecured PHI without unreasonable delay and within 60 calendar days of discovery.45 CFR 164.404(b)

Other duties

  • Obtain satisfactory assurances through business associate agreements before sharing PHI with business associates.45 CFR 164.502(e), 164.504(e)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Current inflation-adjusted HIPAA civil money penalty amounts (45 CFR 102.3) were not checked | eCFR (as of 2026-09-20) still prints the vacated 2024 reproductive health provisions (e.g., 45 CFR 164.509); no HHS rule removing them was found | Sections 164.406, 164.508, 164.526, 164.528 were cited from the part structure without close reading

Research reference, not legal advice.