HIPAAFluent

Check our work

Every claim in this course has a source you can open.

The course was drafted exclusively from primary sources: the HIPAA regulations at 45 CFR Parts 160, 162, and 164 (via the official eCFR), HHS's own summaries and guidance pages, and NIST SP 800-66. Key claims were verified against the live HHS pages, and the verification dates are recorded alongside the sources. When a source page changes, we re-verify the course against it.

ecfr.gov — 45 CFR 160 / 162 / 164 HHS.gov HIPAA guidance NIST SP 800-66r2

Honesty requires the other half too: this material was drafted with AI assistance from the sources below and has not yet been reviewed by an attorney or compliance professional. It is educational material, not legal advice — the disclaimer explains the scope. Read the disclaimer.

1 The Stakes: Why HIPAA Matters
2 Recognizing PHI
3 Who Must Protect It
4 Sharing PHI the Right Way
5 Patients and Their Rights
6 Securing Electronic PHI
  • 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information: § 164.302 compliance duty; § 164.304 definitions of confidentiality, integrity, availability; § 164.306 general rules, required/addressable framework, ongoing review; § 164.308 administrative safeguards including required risk analysis and risk management; § 164.310 physical safeguards including disposal and media re-use; § 164.312 technical safeguards including unique user identification, audit controls, authentication, transmission security; § 164.316 documentation and six-year retention) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C — full current text retrieved via the eCFR versioner API (point-in-time data current as of Aug 2026)
  • HHS, Summary of the HIPAA Security Rule (e-PHI scope, including the quoted statement that the Security Rule does not apply to PHI maintained or transmitted on paper or verbally; regulated entities; general rules; required/addressable framework) — https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright); the page states "Content last reviewed August 7, 2026."
  • 45 CFR 164.530(c) (Privacy Rule requirement of administrative, technical, and physical safeguards for PHI in any form, limiting incidental disclosures) — https://www.ecfr.gov/current/title-45/section-164.530 (via eCFR API)
  • HHS, Summary of the HIPAA Privacy Rule (safeguards and everyday-handling expectations corroborated) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
7 When Things Go Wrong
  • 45 CFR Part 164, Subpart D (Breach Notification Rule: § 164.402 breach definition, presumption, four-factor risk assessment, exclusions, "unsecured PHI"; § 164.404 individual notice content and 60-day deadline; § 164.406 media notice for more than 500 residents of a state or jurisdiction; § 164.408 notice to the Secretary — with individual notice for 500+, annually within 60 days of year end for smaller breaches; § 164.410 business associate notice within 60 days; discovery imputed when known, or when it would have been known with reasonable diligence, to any workforce member or agent) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D — retrieved via the eCFR API, current through Aug. 6, 2026
  • HHS Breach Notification Rule page (breach definition and presumption, four-factor risk assessment, three exceptions, unsecured-PHI/encryption guidance, individual/media/Secretary/business-associate notification deadlines, burden of proof) — https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright)
  • 45 CFR Part 160, Subpart B — Preemption of State Law (§§ 160.201–160.205: general rule that contrary state law is preempted; "contrary" and "more stringent" definitions; exceptions) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-B — retrieved via the eCFR API
  • HHS, Preemption of State Law FAQ page (federal floor; more-stringent state law prevails; no HHS determinations on stringency) — https://www.hhs.gov/hipaa/for-professionals/faq/preemption-of-state-law/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright)
  • HHS, Summary of the HIPAA Privacy Rule, "State Law" section (preemption general rule and exceptions) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
8 A Culture of Compliance