ISpectra Technologies
FoundationsGuideUpdated Jun 2026·9 min read

What Is HIPAA Compliance? A Complete Guide

HIPAA is the US law that protects patients’ health information. This guide explains, in plain English, what HIPAA compliance is, who it applies to, and how to achieve it.

Share

HIPAA is the US law that protects patients’ health information. This guide explains, in plain English, what HIPAA compliance is, who it applies to, and how to achieve it. Use it as your starting point, then dive deeper through the rest of the HIPAA compliance hub. Achieving HIPAA compliance is the goal this guide will help you work toward.

This guide is the foundation of our HIPAA Hub. Whether you run a clinic, build health-tech software, or provide services to a healthcare organization, the same fundamentals apply. We’ll cover what HIPAA is, who it applies to, what data it protects, the rules that make it up, and the practical steps to become — and stay — compliant.

What HIPAA stands for (and why it exists)

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress originally passed it to help workers keep their health insurance when they changed jobs — the “portability” part. But the law also recognized that moving health records into electronic systems created new privacy and security risks, so it added the “accountability” provisions that most people now associate with the HIPAA name.

Over the years, the U.S. Department of Health & Human Services (HHS) issued a series of regulations — the Privacy Rule, the Security Rule, the Breach Notification Rule, and others — that turned HIPAA into the foundation of health-data protection in the United States. Today, when people talk about “HIPAA compliance,” they almost always mean meeting the requirements of these rules to keep patient information private and secure.

The law did not arrive fully formed. The HIPAA timeline traces how it evolved from the original 1996 Act through the Privacy and Security Rules and later amendments, which helps explain why the framework looks the way it does today.

It also helps to understand what the law is actually for before diving into the mechanics. The HIPAA objectives and benefits set out the goals behind the rules — protecting patient privacy, securing electronic records, and giving individuals real rights over their own health information.

And someone has to enforce all of this. Our guide to who enforces HIPAA covers the HHS Office for Civil Rights (OCR), the body that investigates complaints, runs audits, and issues penalties when organizations fall short.

What ‘HIPAA compliance’ really means

HIPAA compliance is not a single certificate you earn once and frame on the wall. It is an ongoing HIPAA compliance program of policies, safeguards, training, and documentation that demonstrates your organization protects health information the way the law requires.

So what does “compliant” actually mean in practice? An organization meets the HIPAA requirements when it has implemented the administrative, physical, and technical safeguards, can prove it through documentation, and keeps that program current as its systems and risks change.

This is an important mindset shift. Many teams treat HIPAA as a one-time project, but the regulations expect continuous risk management, periodic reviews, and prompt updates whenever something material changes — a new system, a new vendor, or a new type of data. Compliance is a posture you maintain, not a milestone you pass.

Sustaining that posture is a discipline in itself. Learning to maintain HIPAA compliance — keeping policies, training, and evidence current long after the initial push — is what separates a durable program from one that quietly decays between audits.

The modern answer to that challenge is to make compliance a steady state rather than an annual scramble. HIPAA continuous compliance keeps your safeguards and documentation continuously up to date, so you are always ready to demonstrate your posture rather than rebuilding it each year.

Who must comply with HIPAA

HIPAA applies to two categories of organizations. The first is covered entities: healthcare providers who transmit health information electronically, health plans (including insurers and most employer-sponsored plans), and healthcare clearinghouses. These are the organizations at the center of the healthcare system that create and hold patient records directly.

The second — and the one most often overlooked — is business associates. A business associate is any vendor that creates, receives, maintains, or transmits protected health information on a covered entity’s behalf: SaaS platforms, cloud hosting providers, billing companies, analytics firms, and IT service providers. If you build software that touches patient data, you are almost certainly one.

This was not always the case. Since the 2013 HIPAA omnibus rule, business associates are directly liable under HIPAA rather than merely contractually bound, which fundamentally raised the stakes for every vendor in the healthcare supply chain.

Those relationships also have to be papered properly. Each covered-entity-to-vendor arrangement must be governed by a business associate agreement, and the same terms then have to flow down to any subcontractors that also touch the data.

The distinction between the two roles trips people up constantly. Our guide on covered entity vs business associate breaks down exactly which role you play, and why that choice changes your obligations.

If you are still unsure whether HIPAA reaches you at all, start with the scope. Our overview of who must comply with HIPAA walks through both categories and the edge cases that catch people out.

Free resource

HIPAA Compliance Kit

A practical checklist + policy starter pack to fast-track your program.

What is PHI (and ePHI)?

At the heart of HIPAA is protected health information (PHI). PHI is any individually identifiable health information held or transmitted by a covered entity or business associate, in any form — paper, spoken, or electronic. It combines a health element (a diagnosis, treatment, or payment for care) with an identifier that ties it to a specific person, such as a name, address, date of birth, or medical record number.

When PHI is stored or transmitted electronically, it is called ePHI, and it falls under the more technical requirements of the Security Rule. Common examples include records in an electronic health record system, lab results in a patient portal, or appointment data in a scheduling app.

Everything starts with identifying the data itself. Understanding what counts as HIPAA PHI is the first practical step in any compliance effort, because you cannot protect — or scope — data you have not first identified.

Once you know what you hold, the law limits how you use it. The HIPAA minimum necessary standard requires you to use or disclose only the smallest amount of PHI needed for a given purpose, which shapes access controls and everyday workflows alike.

Sharing PHI with others carries its own rules. Patient HIPAA release forms (authorizations) govern when and how you may disclose information beyond treatment, payment, and operations, and getting them right keeps otherwise routine disclosures compliant.

The core HIPAA Rules

HIPAA is built from several interlocking rules, and understanding each one is the key to understanding your obligations:

  • The HIPAA Privacy Rule sets national standards for how PHI may be used and disclosed, and gives patients rights over their own information — to access it, request corrections, and learn who it has been shared with.
  • The HIPAA Security Rule requires administrative, physical, and technical safeguards specifically for ePHI, anchored by a documented risk analysis.
  • The HIPAA Breach Notification Rule requires organizations to notify affected individuals, HHS, and sometimes the media when unsecured PHI is breached.
  • The Omnibus Rule (2013) extended HIPAA directly to business associates and their subcontractors and strengthened enforcement under the HITECH Act.
  • The Enforcement Rule governs how the HHS Office for Civil Rights investigates complaints and imposes penalties.

For a fast tour of how these fit together, see our overview of the HIPAA rules, which summarizes each rule and shows how they interlock into a single compliance obligation.

The rules are strict, but not absolute. There are narrow HIPAA exceptions where PHI may be used or disclosed without patient authorization — for treatment, public-health reporting, and certain legal requirements — and knowing them prevents both over- and under-sharing.

The three types of safeguards

The Security Rule organizes its requirements into three families of HIPAA safeguards, and a compliant program addresses all three:

  • Administrative safeguards are the policies and processes that govern your security program — risk analysis, workforce training, access management, named officer roles, and a sanctions policy for violations. These are the largest category and the backbone of compliance.
  • Physical safeguards protect the physical systems and facilities where ePHI lives — facility access controls, workstation security, secure HIPAA data backup, and rules for the disposal and reuse of devices and media.
  • Technical safeguards are the technology controls that protect ePHI directly — unique user IDs, access controls, audit logging, integrity protections, and HIPAA encryption requirements for data in transit and at rest.

Notably, HIPAA labels some requirements “required” and others “addressable.” Addressable does not mean optional — it means you must implement the safeguard, or document a reasonable, equivalent alternative and why you chose it. Encryption is the classic addressable example.

Within the administrative layer, people are the highest-leverage control. Regular HIPAA training ensures your workforce actually understands their obligations, because even strong technical safeguards fail if staff mishandle PHI or fall for a phishing email.

Someone also has to own the program day to day. Appointing a HIPAA officer — a named Privacy and/or Security Officer — gives you a single point of accountability for policies, incidents, and ongoing compliance decisions.

And all of it has to be written down to count. A complete set of HIPAA policies and procedures turns your intentions into documented, auditable practice, which is exactly what an investigator asks to see first.

How to become HIPAA compliant

While every organization is different, the path to compliance follows a consistent shape. It begins by mapping your PHI — identifying every system, vendor, and workflow that touches health information — because you can only protect what you can see.

With the data mapped, you turn to threats. A HIPAA risk assessment, which the Security Rule explicitly requires, identifies the risks to that data and helps you decide how to treat each one — it is the single most scrutinized document in any OCR investigation.

Next you measure yourself against the standard. A HIPAA gap analysis compares your current controls to what the rules demand and produces a concrete list of what is missing, which becomes your remediation plan.

Before an auditor or investigator ever arrives, it pays to pressure-test yourself. Checking your HIPAA audit readiness confirms whether your safeguards and paperwork would actually hold up under external scrutiny, while there is still time to fix gaps.

From there you remediate: implement the safeguards, write the required policies, and execute Business Associate Agreements with every vendor that handles PHI. Throughout, thorough HIPAA documentation is what proves the work was done — under HIPAA, an undocumented control is effectively no control at all.

Finally, you pull the whole sequence together and keep it running. Our step-by-step guide on how to become HIPAA compliant walks through each stage in order, from first scoping decision to ongoing maintenance.

If you prefer to work from a single actionable list, we have one ready. The free HIPAA checklist turns the whole program into tickable tasks, so nothing important slips through as you move from readiness to a defensible, operating program.

HIPAA violations and penalties

HIPAA has real teeth. The Office for Civil Rights (OCR) enforces the law and can impose tiered civil HIPAA penalties based on the level of culpability — from modest fines for unknowing violations to substantial penalties for willful neglect that is not corrected, up to an annual cap per identical provision. In serious cases involving the knowing misuse of PHI, criminal penalties are also possible.

If OCR does come knocking, how you respond matters enormously. Knowing the process for responding to OCR investigations — what to produce, what to say, and how quickly — can be the difference between a manageable resolution and an escalating penalty.

Beyond fines, a breach carries reputational damage and the loss of hard-won trust. It also usually triggers a mandatory HIPAA corrective action plan, a formal, monitored remediation program that can consume your team for months after the incident itself.

The best defense against that outcome is preparation. A tested HIPAA incident response plan means that when something does go wrong, you contain it, notify the right parties on time, and demonstrate that you acted responsibly rather than froze.

Most enforcement, though, traces back to a handful of avoidable mistakes. Common HIPAA violations include lost or stolen unencrypted devices, improper disclosures, missing risk analyses, and the absence of Business Associate Agreements — nearly all of which a sound program prevents outright.

Is there a HIPAA ‘certification’?

This is one of the most common points of confusion. There is no official, government-issued HIPAA certification. No federal body reviews your organization and stamps it “HIPAA certified.” Any vendor claiming to make you “HIPAA certified” in a permanent sense is overstating what is possible under the law.

That said, third parties can attest to your compliance at a point in time, which is increasingly important for business associates that need to prove their posture to win deals. Many organizations pursue an independent HIPAA audit for exactly this reason — an external review that gives customers documented confidence in your program.

Such an audit goes far more smoothly with preparation. A HIPAA audit documentation review checks that your policies, risk analysis, and records are complete and consistent before an assessor ever sees them, heading off the most common findings.

It also helps to rehearse the real thing. Running a HIPAA internal audit against your own controls surfaces weaknesses while they are still cheap to fix, and builds the muscle memory your team needs for the external review.

Whatever the audit, it stands or falls on proof. Strong HIPAA evidence — logs, tickets, training records, and screenshots — is what demonstrates each safeguard is genuinely operating rather than merely written into a policy.

Finally, be careful about the language you use. Our guide on HIPAA certification and attestation explains what is genuinely available — there is no official government “HIPAA certified” stamp — and how to present your compliance credibly without overstating it.

HIPAA alongside other frameworks

HIPAA rarely lives alone. Many health-tech companies also pursue SOC 2 to satisfy enterprise security reviews, and because the two share so many underlying controls, our guide on HIPAA and SOC 2 shows how to build once and satisfy both.

Others reach for HITRUST, a certifiable framework that incorporates HIPAA requirements into a formal, assessable certification. Our comparison of HIPAA vs HITRUST explains when the extra rigor is worth it and when plain HIPAA compliance is enough.

Whichever route you take, the efficiency comes from the overlap. These frameworks share a large common core — access management, encryption, risk assessment, and vendor oversight — so sequencing them together is usually far cheaper than tackling each in isolation.

If your customers are asking for both a HIPAA attestation and a SOC 2 report, sequencing the work so shared controls are built once can substantially reduce total cost and effort. A specialist partner like ISpectra can map the overlap and bundle the engagements.

Getting started with HIPAA

If you are just beginning, resist the urge to buy tools or write policies first. Start by confirming whether you are a covered entity or business associate, then map where PHI lives and conduct an honest risk analysis. Those two steps anchor everything that follows and stop you spending money in the wrong places.

Your context shapes the plan from there. If you are an early-stage company, our guide to HIPAA for startups shows how to build a right-sized program without the overhead a hospital would carry.

Software vendors have their own considerations. HIPAA for SaaS covers the architecture, access, and Business Associate Agreement questions that come up when your product itself processes customer PHI.

Budget is usually the next question. Our HIPAA compliance cost guide breaks down where the money actually goes — tooling, remediation, training, and any external assessment — so you can plan realistically.

It also helps to know how often to revisit everything. Our guide to HIPAA review frequency explains which activities are annual, which are triggered by change, and how to keep the program from drifting out of date.

To run all of this efficiently, tooling matters. Purpose-built HIPAA compliance software centralizes your policies, risk analysis, and evidence in one place instead of scattering them across spreadsheets and inboxes.

Much of the repetitive work can be handled for you. HIPAA automation takes over routine evidence collection and control checks, cutting the manual effort that causes programs to lapse between reviews.

Where automation lives is its own choice. A dedicated HIPAA automation platform ties those automated checks to your policies and controls, giving you a single system of record for compliance rather than a patchwork.

You also need to know the moment something slips. Continuous HIPAA monitoring watches your safeguards in real time and alerts you to drift — an expired access review, an unencrypted device — before it becomes a breach.

Everyday tools have to be compliant too. Using HIPAA compliant email ensures that PHI sent to patients or partners is protected in transit and at rest, closing one of the most common leakage points.

The same applies to how you measure your product. HIPAA compliant analytics lets you understand user behavior without exposing PHI to third-party trackers that would put you out of compliance.

Finally, go in with your eyes open. Knowing the common HIPAA challenges in advance — from vendor sprawl to under-resourced ownership — keeps the project on track. Explore the rest of the hub for deep dives, or talk to our team for a free readiness assessment to map your fastest path to a defensible program.

Free consultation

Need help with HIPAA?

Talk to our certified compliance team — we’ve supported 200+ audits.

Book free assessment
FAQ

What Is HIPAA — Frequently Asked Questions

HIPAA is a US federal law, not a certification. There is no official government-issued HIPAA certificate. Compliance is an ongoing program of safeguards, policies, training, and documentation that you maintain over time.
If your software creates, receives, maintains, or transmits protected health information on behalf of a covered entity, you are a business associate and HIPAA applies to you directly. Most health-tech SaaS platforms and cloud vendors fall into this category.
PHI is any individually identifiable health information in any form. ePHI is PHI that is stored or transmitted electronically. ePHI is specifically governed by the HIPAA Security Rule, which requires technical safeguards like access controls and encryption.
The core rules are the Privacy Rule (use and disclosure of PHI), the Security Rule (safeguards for ePHI), the Breach Notification Rule (what to do after a breach), and the Enforcement Rule (penalties). The 2013 Omnibus Rule updated several of these.
Map where PHI lives, conduct a risk analysis, run a gap analysis, remediate by implementing safeguards and policies, sign Business Associate Agreements, train your workforce, and then maintain the program with ongoing reviews. It is a continuous effort, not a one-time project.
The Office for Civil Rights can impose tiered civil penalties based on culpability, ranging from modest fines to substantial penalties for willful neglect, with criminal penalties possible in serious cases. Violations also bring corrective action plans and reputational harm.
Ready to take the next step?

Get your free HIPAA readiness assessment

A 30-minute call with our certified team. We’ll review your current state and map a realistic path to a defensible HIPAA program — no pitch.

Book free assessment