Identity Security and PAM Blog for CISOs and IT Security Pros

What Are the Three Rules of HIPAA? | HIPAA Explained

Written by John Martinez | Jul 3, 2022, 12:00:00 PM

What is the purpose of HIPAA rules? 

The Health Insurance Portability and Accountability Act (HIPAA) was originally introduced in 1996 to protect health insurance coverage for employees who lost or changed jobs. Today, HIPAA also includes mandates and standards governing how healthcare providers and other covered organizations transmit and protect sensitive patient health information. 

HIPAA rules benefit both patients and providers by establishing standards for the privacy, security and handling of protected health information (PHI). They help healthcare organizations securely and efficiently store and share patient data while protecting it from unauthorized use and access. Failure to comply can result in significant penalties and other negative consequences, making it important for organizations to understand how HIPAA works and the key areas it covers. 

HIPAA rules require that: 

  • PHI is only accessed by authorized parties.
  • patients have access to copies of their personal records upon request.
  • covered entities safeguard PHI through reasonable physical, administrative, and technical measures.
  • covered entities promptly report and resolve any breach of security.  

What are three major things addressed in the HIPAA law?

HIPAA rule 1: the Privacy Rule

The HIPAA Privacy Rule outlines standards to protect all individually identifiable health information handled by covered entities or their business associates. This protected health information (PHI) includes a wide range of sensitive data, such as social security numbers, credit card information, and medical history, including prescriptions, procedures, conditions, and diagnoses. 

PHI has long been a target of identity theft, so establishing strong privacy rules governing its use, access, and security is one of the most important parts of protecting patient data. The Privacy Rule addresses this risk by:

  • giving patients more control over their health information, including the right to review and obtain copies of their records.
  • setting boundaries on the use and release of health records. 
  • requiring standard safeguards that covered entities must implement to protect PHI from unauthorized use or access. 

The Privacy Rule also includes limiting the release of PHI to the minimum required for disclosure (aka the Minimum Necessary Rule). In other words, under the Privacy Rule, information isn’t disclosed beyond what is reasonably necessary to protect patient privacy.

To ensure patient records and information are kept private, the Privacy Rule outlines:

  • which organizations must follow the HIPAA rules (aka covered entities).
  • how covered entities can use and share PHI.
  • permitted uses and disclosures of health information.

What is a covered entity?

Organizations subject to HIPAA rules are called covered entities. 

Covered entities include any organization or third party that handles or manages protected patient data, for example:

  • Health plans. These are health insurance companies, HMOs, and government programs like Medicare and Medicaid.
  • Health care providers. Providers that conduct business electronically, such as most doctors, hospitals, clinics, nursing homes and pharmacies.
  • Health care clearinghouses. These are entities that process or facilitate the processing of nonstandard health information data elements into standard data elements.

Additionally, business associates of covered entities must comply with parts of HIPAA rules. 

Business associates are third-party organizations that need and have access to health information when working with a covered entity. Business associates can include contractors and subcontractors, companies that help doctors bill and process claims, lawyers and accountants, IT specialists and companies that store or dispose of medical data.

When can covered entities use or disclose PHI?

A covered entity cannot use or disclose PHI unless permitted under the Privacy Rule or by written authorization from the subject of the information.

Covered entities must disclose PHI to the individual upon request or to HHS for compliance investigations or enforcement.  

Permitted uses and disclosures 

Covered entities may use or disclose PHI without prior patient authorization for their own treatment, payment and health care operations. They are always allowed to share PHI with the individual. The Privacy Rule also makes exceptions for disclosure in the public interest, such as when required by law or for public health. 

HIPAA rule 2: the Security Rule

The HIPAA Security Rule establishes standards for protecting the electronic PHI (ePHI) that a covered entity creates, uses, receives or maintains. While the Privacy Rule governs the privacy and confidentiality of all PHI, including oral, paper and electronic forms, the Security Rule focuses on guidelines for securing electronic data. 

A key goal of the Security Rule is to protect individuals’ private health information while still allowing covered entities to adopt new technologies that improve the quality and efficiency of patient care.

The Security Rule considers flexibility, scalability and technological neutrality. This means there are no specific requirements for the types of technology covered entities must use. Instead, covered entities can use any security measures that allow them to implement the standards appropriately. It is up to the covered entity to decide which security measures and technologies are best for its organization.

Under the Security Rule, covered entities must: 

  • protect the confidentiality, integrity, and availability of the ePHI they receive, maintain, create or transmit.
  • identify and protect against threats to the security or integrity of the information.
  • reasonably protect against impermissible uses or disclosures.
  • enforce compliance by their workforce.

The Security Rule covers three main areas of security: administrative, physical and technical. 

Administrative safeguards

Administrative safeguards are administrative actions, policies and procedures that develop and manage security measures that protect ePHI.

Administrative safeguards make up more than half of the Security Rule regulations and lay the foundation for compliance. 

Covered entities must implement the following administrative safeguards:  

  • Conduct thorough security management and risk analysis.
  • Assign a privacy officer.
  • Manage workforce security.
  • Manage information access.
  • Conduct HIPAA security training.
  • Establish security incident procedures.
  • Develop contingency plans.
  • Obtain proper contract agreements with business associates.
  • Evaluate security safeguards regularly.

Physical safeguards

HIPAA physical safeguards are any physical measures, policies and procedures used to protect a covered entity’s electronic information systems from damage or unauthorized intrusion. This includes the protection of buildings and equipment.

In other words, HIPAA rules require covered entities to consider and apply safeguards to protect physical access to ePHI. 

HIPAA physical safeguard requirements include: 

  • Facility access controls. Limit facility access to authorized users by implementing contingency operations, facility security plans, access control and validation procedures, and maintenance records. This might include controlling building access with photo ID cards and locking offices or storage areas containing ePHI.   
  • Workstation use and security. Implement policies and procedures to standardize the functions performed and the physical setup to protect ePHI. This includes setting parameters on access and storage for ePHI on mobile devices, properly arranging the physical workspace (e.g., can unauthorized people see information on the screen?), and limiting what information is stored on station devices.
  • Devices and media controls. Establish policies for receiving and handling devices that store ePHI, and for moving these items within the facility. This includes procedures for proper disposal of data, as well as backup and storage policies.

Technical safeguards

Under the Security Rule, technical safeguards apply to the technology itself, as well as the policies and procedures that govern its use, protect its electronic protected health information and control access to it. 

Technical safeguards include:

  • Access control. Grant access only to those with permission.  
  • Audit controls. Implement a system to monitor, record and review all activity.  
  • Integrity. Protect ePHI from being altered or improperly destroyed. 
  • Person or entity authentication. Confirm user identity before granting access. 
  • Transmission security. Protect access to ePHI through encryption. 

Together, these safeguards help covered entities provide comprehensive, standardized security for all ePHI they handle. 

HIPAA rule 3: the Breach Notification Rule

The HIPAA Breach Notification Rule requires covered entities and business associates to provide notification of a breach involving unsecured PHI. A breach is any impermissible use or disclosure of PHI under the Privacy and Security Rules. 

If a potential breach occurs, the organization must conduct a risk assessment to determine the scope and impact of the incident and confirm whether it falls under the notification requirement. 

The risk assessment should be based on the following factors

  • The nature and extent of the PHI involved
  • The unauthorized person who used the PHI or to whom the disclosure was made
  • Whether the PHI was actually obtained or viewed
  • The extent to which the risk to the PHI has been mitigated

A covered entity is required to make a notification unless it can demonstrate a low probability that PHI was compromised. Breach notifications include individual notice, media notice, and notice to the secretary.

Individual notice

Following a breach, the organization must notify all impacted individuals. The notice must include a description of the breach and the types of information involved, what steps individuals should take to protect themselves from potential harm and what the covered entity is doing to investigate and address the breach.

Media notice

Covered entities must also notify the media (typically through a press release to local or regional outlets) if the breach affects 500 or more residents of a state or jurisdiction. The notice must include the same information as the notice to individuals and must be issued promptly, no later than 60 days following the discovery of the breach.

Notice to the Secretary 

Covered entities are required to notify the Secretary of Health and Human Services whenever a breach occurs. If the breach affects fewer than 500 individuals, the covered entity must notify the Secretary within 60 days of the end of the calendar year in which the breach was discovered. 

If the breach affects 500 or more individuals, the covered entity must notify the Secretary within 60 days of the discovery of the breach. 

How Delinea helps with HIPAA rules

The three rules of HIPAA are cornerstones of regulation that protect the healthcare industry and consumers from fraud, identity theft and violations of privacy. 

Through privacy, security, and notification standards, HIPAA regulations:

  • improve standardization and efficiency across the industry. 
  • strengthen data security among covered entities. 
  • deliver better access control across networks.
  • provide greater transparency and accountability to patients. 

Failure to comply with HIPAA regulations can lead to costly penalties and even criminal liability. Access control runs underneath all three rules and this is where the Delinea Platform succeeds by securing the privileged accounts that can reach ePHI. 

Delinea's audit and compliance solution gathers the access evidence auditors ask for across HIPAA, SOC 2, SOX and ISO 27001. 

You can grant least privilege access to servers, databases and cloud infrastructure based on roles, attributes or just-in-time approval and then record the sessions. That leaves you a reviewable account of who touched ePHI and what they did with it, which is the evidence a HIPAA audit turns on.