Privacy

HIPAA Basics

What HIPAA does, what it doesn't, and how it applies inside the room.

10 min readUpdated March 22, 20262 topics

The structure of the law

HIPAA is best understood as two rules stitched together:

  • Privacy Rule (45 CFR Part 164 Subpart E) — when protected health information (PHI) can be used or disclosed.
  • Security Rule (45 CFR Part 164 Subpart C) — administrative, physical, and technical safeguards for electronic PHI.
  • Breach Notification Rule (45 CFR Part 164 Subpart D) — reporting obligations.
  • Enforcement Rule (45 CFR Part 160 Subparts C–E) — penalties.

The 2013 Omnibus Rule extended direct liability to business associates.

The three safeguard families

FamilyExamples of required or addressable controls
AdministrativeRisk analysis, workforce training, contingency plan, BA agreements
PhysicalFacility access control, device disposal, workstation location
TechnicalAccess control, audit logs, integrity, transmission security

NIST SP 800-66r2 (2024) maps every Security Rule specification to concrete controls in NIST SP 800-53.

In the room

Any device in the patient room that captures identifiable information — a monitor, a camera, an ambient microphone, a wearable — is potentially in scope, regardless of whether it integrates with the EHR. The safest posture is to treat every connected device as PHI-bearing unless proven otherwise, and to demand a Business Associate Agreement (BAA) for any external service that touches the data.

Storing "just metadata" is a compliance trap. If the metadata can be tied to a person and a care episode, it is PHI.

Related frameworks

  • NIST SP 800-66r2 — Implementing the HIPAA Security Rule.
  • HITRUST CSF — commonly used third-party certification.
  • OCR audit protocol — how enforcement actually looks.
  • State laws — many are stricter than HIPAA (e.g. CA CMIA, TX HB 300).

References & further reading

  1. 145 CFR Parts 160 and 164 — HIPAA Administrative Simplification
  2. 2NIST SP 800-66r2 Implementing the HIPAA Security Rule (2024)
  3. 3HHS Office for Civil Rights — HIPAA audit protocol
  4. 4HITRUST CSF v11

Help us improve

Spotted something wrong, outdated, or unclear? Let the editors know.