BlogHIPAA
August 20, 2026

The guide to HIPAA regulations and rules for healthcare companies and their vendors

Written by
Vanta
Reviewed by
No items found.

Accelerating security solutions for small businesses 
‍

Tagore offers strategic services to small businesses. 

A partnership that can scale 
‍

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors
‍

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

HIPAA regulations are a fixture of American healthcare. They reach almost every organization that handles health data, from large hospital networks to small startups. The name is familiar to patients and providers alike, even if the details behind it rarely are. Few rules in the industry are as widely recognized or as easy to underestimate.

‍

If your company works in healthcare or handles data for someone who does, HIPAA isn't optional, and getting it wrong carries real financial and reputational cost. The rules are also a moving target right now, with the largest security update in over a decade working its way toward a final rule. This guide covers the HIPAA rules, who has to follow them, what protected health information includes, how the law is enforced, the penalties for noncompliance, and what's changing in 2026.

‍

What are HIPAA regulations and what do they protect?

The HIPAA regulations are the federal rules that spell out how organizations must protect health information and what they're allowed to do with it. Congress passed the Health Insurance Portability and Accountability Act (HIPAA) in 1996 to solve a practical problem. People who changed or lost their jobs were often losing their health insurance too, and the law's first job was to keep that coverage portable. The privacy and security obligations most people associate with HIPAA today came later, through rules the Department of Health and Human Services added under a part of the law called Administrative Simplification.

‍

At the center of those rules sits protected health information, or PHI. PHI is any health information that can be tied to a specific person, and it counts whether it lives in a database, on paper, or in a spoken conversation. When that information is electronic, the rules call it ePHI, and a dedicated rule governs how you secure it. The point of all of it is to keep this information private, keep it accurate, and keep it available to the people who are allowed to see it.

‍

Two facts are worth pinning down early. The Department of Health and Human Services, usually shortened to HHS, writes the rules. Its Office for Civil Rights, or OCR, investigates complaints and issues penalties. State attorneys general can bring action in some cases too. 

‍

The five rules of HIPAA 

Most of HIPAA's privacy and security weight lives in a short list of named rules, and you'll see different counts of them in different places. Some sources list five rules and fold in the older standards for transactions and identifiers, which set the formats for electronic claims and the numbers that identify providers and health plans. Others count only the rules that govern privacy and security directly. The five HIPAA rules that come up most often for the companies we talk to are the following.

‍

The Privacy Rule

The Privacy Rule sets the national standard for how you can use and share PHI. It gives people the right to see and get copies of their own records, the right to ask for corrections, and a say in who else can access their information. It also sets the minimum necessary standard, which says you should use or share only the information a task actually requires. The rule binds covered entities directly, and its obligations reach the vendors they work with through contracts.

‍

The Security Rule

The Security Rule covers the electronic side of the same information. It requires you to protect ePHI with three kinds of safeguards, administrative, physical, and technical, which we break down further below. Historically the rule let organizations treat some safeguards as addressable, meaning you could document why a given control wasn't reasonable for you and take another path. That flexibility is exactly the part regulators are now moving to tighten.

‍

The Breach Notification Rule

The Breach Notification Rule decides what happens after PHI is exposed. It requires you to notify affected people without unreasonable delay and no later than 60 days after you discover a breach. You also have to notify HHS, and for breaches affecting 500 or more people, you have to alert the media and report to HHS right away rather than in the yearly summary that smaller breaches allow. Business associates owe their covered entity prompt notice too.

‍

The Enforcement Rule

The Enforcement Rule is the one with teeth. It gives OCR the authority to investigate complaints, and it sets the tiered penalty structure that scales with how culpable an organization was. Penalties run from the case where you genuinely didn't know about a violation up to willful neglect you never bothered to fix. We lay out the current tiers and dollar figures later in this guide.

‍

The Omnibus Rule

The Omnibus Rule, finalized in 2013, pulled vendors fully into HIPAA's scope. Before it, business associates sat at arm's length. After it, they became directly liable for protecting PHI, and so did their subcontractors. The rule also tightened the breach standard and strengthened patient rights. If you run a software company that touches health data, this is the rule that put you on the hook.

‍

Who has to comply with HIPAA regulations

HIPAA doesn't apply to everyone who handles health information. It applies to two main groups, plus the people and vendors connected to them. Sorting out which one you fall into is the first practical question, and for a lot of software companies the answer is surprising.

‍

Covered entities are the organizations at the front line of care and payment. They include healthcare providers who send health data electronically, health plans, and healthcare clearinghouses that process claims. If you bill electronically, run an insurance plan, or sit in the middle of those transactions, you're almost certainly a covered entity.

‍

Business associates are the vendors that handle PHI on a covered entity's behalf, and this is the category most technology companies land in. A cloud host, an analytics tool, a billing service, or a scheduling app that stores or processes PHI for a clinic or a health plan is a business associate, even if no person at the vendor ever opens a patient record. The obligation holds even when you have no ability to view the underlying information.

‍

The chain doesn't stop there. A vendor that a business associate hires to help with that work becomes a subcontractor, and it inherits the same Security and Breach Notification obligations. Before PHI changes hands in any of these relationships, the parties have to sign a business associate agreement, a contract that spells out who protects what. Your own employees are on the hook too, since covered entities have to discipline workforce members who break the rules.

‍

Here's a quick way to place yourself.

‍

Your situation Your likely status What you owe
You’re a provider, health plan, or clearinghouse handling PHI electronically Covered entity All applicable rules, including Privacy, Security, and Breach Notification
You’re a vendor that creates, receives, stores, or transmits PHI for a covered entity Business associate The Security and Breach Notification Rules, plus your agreement terms
You work for a business associate handling PHI downstream Subcontractor The same safeguards as a business associate, under an agreement
You never touch PHI in any form Out of scope No HIPAA obligations, though state privacy laws may still apply

‍

What protected health information includes

Protected health information is broader than medical charts. It's any information that connects to a person's health, their care, or payment for that care, and that could identify them. That covers the obvious things like diagnoses, test results, and prescriptions, along with the less obvious things like an appointment date, a phone number, or a license plate when they're tied to someone's care.

‍

HHS spells out 18 specific identifiers that turn health data into PHI. Strip all 18, and the data no longer counts as protected under the Privacy Rule's safe harbor method. Here's the full list.

‍

  • Names
  • Geographic data smaller than a state, such as street address, city, county, and ZIP code
  • Dates tied to an individual, including birth, admission, discharge, and death dates
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate and license numbers
  • Vehicle identifiers and serial numbers, including license plates
  • Device identifiers and serial numbers
  • Web addresses
  • IP addresses
  • Biometric identifiers, including fingerprints and voiceprints
  • Full face photographs and similar images
  • Any other unique identifying number, characteristic, or code

‍

When any of this lives in electronic form, it becomes ePHI, and the Security Rule sets the bar for protecting it.

‍

The safeguards the Security Rule requires

The Security Rule organizes its requirements into three groups of safeguards. Together they cover the policies you write, the spaces and devices you control, and the systems that hold ePHI. None of them work in isolation, and an audit will look at all three.

‍

Administrative safeguards are the policies and people side. They include running a risk analysis to find where your ePHI is exposed, training your workforce, naming someone accountable for security, and keeping a sanctions policy for people who break the rules. The risk analysis matters most here, because a missing or stale one is the single most cited problem in OCR investigations.

‍

Physical safeguards cover your facilities and hardware. Think facility access controls, workstation security, and rules for how devices and media get used, moved, and disposed of.

‍

Technical safeguards cover the systems themselves. They include access controls that limit who can reach ePHI, audit controls that log activity, and encryption that protects the data if it's intercepted or a device goes missing.

‍

One detail is worth holding onto. Several of these controls have long been addressable rather than strictly required, which let organizations justify another approach. That distinction sits at the heart of the changes coming in 2026.

‍

Safeguard type What it covers Examples
Administrative Policies and people Risk analysis, workforce training, sanctions policy
Physical Facilities and devices Facility access controls, workstation and device controls
Technical Systems and data Access controls, audit logging, encryption of ePHI

‍

Who enforces HIPAA regulations

The Office for Civil Rights, a part of HHS, is the main enforcer of the HIPAA regulations. It investigates complaints from patients and the public, opens compliance reviews that often follow a reported breach, and can require corrective action or impose civil monetary penalties. In practice, OCR resolves most cases by making an organization fix the problem rather than by handing down the largest possible fine, and it tends to go easier on the ones that cooperate and remediate quickly. Its recent attention has centered on two recurring problems, weak or missing risk analyses and slow responses when patients ask for copies of their own records.

‍

OCR isn't the only one who can act. Under the HITECH Act, state attorneys general can bring their own civil cases for violations affecting their residents, and they often pursue these under state privacy or consumer protection laws that carry separate penalties of their own. Criminal cases are different again. The Department of Justice prosecutes people who knowingly misuse PHI, and those cases can reach $250,000 in fines and prison time in the worst instances. The practical point is that a single breach can draw scrutiny from several directions at once, which is part of why the stakes run higher than the civil fine alone suggests.

‍

What HIPAA penalties look like

HIPAA penalties scale with how much an organization knew and how it responded. Civil penalties fall into four tiers, from an honest mistake you couldn't have known about up to willful neglect you left uncorrected. Each tier carries a range per violation, and there's a separate cap on what OCR can collect in a year for repeated violations of the same requirement.

‍

The figures adjust for inflation every year. The most recent change came through the HHS annual civil monetary penalties inflation adjustment, published on January 28, 2026, and the amounts below reflect it. One wrinkle is worth knowing. The official statutory cap reaches $2,190,294 per identical provision per year, but OCR has operated since 2019 under the HHS Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, which applies lower annual caps for the first three tiers. 

‍

Tier Culpability Penalty per violation Annual cap OCR currently applies
Tier 1 You didn’t know and couldn’t reasonably have known $145 to $73,011 $25,000
Tier 2 Reasonable cause, not willful neglect $1,461 to $73,011 $100,000
Tier 3 Willful neglect, corrected within 30 days $14,602 to $73,011 $250,000
Tier 4 Willful neglect, not corrected $73,011 to $2,190,294 $1,500,000

‍

Civil money isn't the only exposure. The Department of Justice handles criminal penalties for knowingly misusing PHI, and those can reach $250,000 and prison time in the most serious cases. State attorneys general can also bring their own actions for violations affecting their residents, often under state privacy laws that carry separate penalties. And the fine is frequently the smaller cost. The reputational damage and the HIPAA violations that erode patient trust tend to outlast the check you write to OCR.

‍

How to comply with HIPAA regulations

Knowing the rules is one thing. Putting them into practice is where most of the work lives. If you're a covered entity or a business associate getting started, the path looks roughly the same. These six steps cover it.

‍

Run a risk analysis

Start by finding where PHI lives in your systems and where it's exposed. A documented risk analysis is the foundation of the Security Rule, and a missing or outdated one is the most common reason organizations end up in trouble with OCR. Revisit it as your systems change.

‍

Put the safeguards in place

Use what the risk analysis tells you to close gaps with administrative, physical, and technical controls. Encryption, access controls, and audit logging tend to be the highest priorities, and they line up with where the rules are heading in the future.

‍

Write policies and train your people

Document how your organization meets each requirement, and train your workforce on those policies at least once a year. Keep records of who was trained and when, since you have to retain that documentation for six years and produce it if OCR asks.

‍

Sign business associate agreements

Before PHI moves between you and any vendor or customer, put a signed business associate agreement in place. These run in both directions, with the companies you serve and the vendors you rely on, and they define who is responsible for what.

‍

Build a breach response plan

Decide in advance who does what if PHI is exposed, and build your process around the notification clock. You have 60 days from discovery to notify affected people, so a plan you can run quickly is worth having before you need it.

‍

Monitor your controls continuously

HIPAA isn't a project you finish. Controls drift, your environment changes, and the stricter technical rules coming in 2026 raise the bar for proving your safeguards actually work. Automated HIPAA compliance closes that gap by checking your controls against the rules around the clock instead of once a year. That's where a platform like Vanta helps, collecting the evidence and flagging issues as they happen so you stay ready for an audit instead of scrambling before one. It handles HITRUST in the same place, which many healthcare companies pursue alongside HIPAA.

‍

How HIPAA fits with SOC 2, HITRUST, and ISO 27001

HIPAA rarely stands alone. Most companies that handle health data are working toward two or three frameworks at once, and the good news is that the security work overlaps a lot. A control you build to satisfy the Security Rule often counts toward SOC 2, ISO 27001, or HITRUST as well.

‍

One thing to keep in mind is that HIPAA is a law, not a certification. There's no certificate that proves you're compliant, which is why many companies turn to HITRUST. A HITRUST certification gives you an auditable way to show customers and partners that your HIPAA program holds up. SOC 2 reports serve a similar trust purpose for a wider set of buyers, and ISO 27001 carries weight if you operate internationally.

‍

Because the controls overlap, mapping one control to several frameworks at once saves real work. Platforms like Vanta map shared controls across frameworks, so the evidence you collect for HIPAA does double duty for the others rather than running each program from scratch.

‍

Where to go from here

HIPAA isn't a certificate you earn once and file away. It's a standing obligation, and the changes coming in 2026 will ask more of you on the security side. Whether you run a hospital or a health tech startup, the path forward is the same. Figure out whether you're a covered entity or a business associate, document a risk analysis, put the right safeguards in place, and keep proving they work between audits.

‍

That last part is where most programs stumble. Controls drift, evidence goes stale, and the yearly scramble to prove compliance only gets harder as the technical requirements tighten. Staying ready for an audit means treating HIPAA as something you monitor continuously, not a box you check before a deadline.

‍

This is the problem Vanta was built to solve. The platform automates the evidence collection behind HIPAA, monitors your controls around the clock, and maps your HIPAA work to frameworks like SOC 2 and HITRUST so you aren't running each program from scratch. It gives healthcare companies a single place to get compliant, stay that way as the rules change, and show customers their data is protected. See how much of your HIPAA program Vanta can run for you by booking a demo today.

‍

A note from Vanta: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.

‍

{{cta_simple18="/cta-blocks"}}

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.