Check our work
Every claim in this course has a source you can open.
The course was drafted exclusively from primary sources: the HIPAA regulations at 45 CFR Parts 160, 162, and 164 (via the official eCFR), HHS's own summaries and guidance pages, and NIST SP 800-66. Key claims were verified against the live HHS pages, and the verification dates are recorded alongside the sources. When a source page changes, we re-verify the course against it.
ecfr.gov — 45 CFR 160 / 162 / 164
HHS.gov HIPAA guidance
NIST SP 800-66r2
Honesty requires the other half too: this material was drafted with AI assistance from the sources below and has not yet been reviewed by an attorney or compliance professional. It is educational material, not legal advice — the disclaimer explains the scope. Read the disclaimer.
1 The Stakes: Why HIPAA Matters
- 45 CFR 160.103 (Definitions: PHI, workforce) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- 45 CFR 160.404 (Civil money penalty tiers) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.404
- HHS, Summary of the HIPAA Privacy Rule (HIPAA enacted Aug. 21, 1996, Pub. L. 104-191; compliance date Apr. 14, 2003; OCR enforcement; civil penalty ranges $127–$63,973 per violation and caps $25,000–$1,919,173 per HHS's Notification of Enforcement Discretion, 2022 adjustments; criminal penalty descriptions) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
- HITECH Act (Pub. L. 111-5, 2009) as described in the same HHS summary and 45 CFR Part 164 Subpart D
2 Recognizing PHI
- 45 CFR 160.103 (Definitions: individually identifiable health information, protected health information, and the education-record and employment-record exclusions) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- 45 CFR 164.502 (General rules for uses and disclosures; deceased individuals protected until 50 years after death, § 164.502(f)) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- 45 CFR 164.514 (De-identification: expert determination and identifier-removal methods) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- HHS, Summary of the HIPAA Privacy Rule (PHI defined and protected in any form — electronic, paper, or oral) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
3 Who Must Protect It
- 45 CFR 160.103 (Definitions: covered entity — health plan, health care clearinghouse, health care provider transmitting electronically; business associate and its service examples; subcontractors; workforce) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- 45 CFR 164.502(a)(3) (A business associate may use or disclose PHI only as permitted by its business associate contract or as required by law) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- HHS, Summary of the HIPAA Privacy Rule (covered entities and business associates; workforce obligations) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
4 Sharing PHI the Right Way
- 45 CFR 164.502 (general rule "may not use or disclose protected health information, except as permitted or required"; required disclosures; minimum necessary standard; prohibition on sale of PHI) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- 45 CFR 164.506 (treatment, payment, and health care operations) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.506
- 45 CFR 164.508 (authorizations: psychotherapy notes, marketing, sale of PHI; core elements; revocation; no conditioning) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.508
- 45 CFR 164.510 (facility directories; persons involved in care — opportunity to agree or object) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.510
- 45 CFR 164.512 (public interest and benefit disclosures) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.512
- 45 CFR 164.514 (limited data sets; minimum necessary implementation) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- HHS, Summary of the HIPAA Privacy Rule (six permitted purposes framing; required disclosures; minimum necessary exceptions) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
- HHS, "Incidental Uses and Disclosures" guidance (incidental disclosures permissible only with reasonable safeguards and minimum necessary) — https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/incidental-uses-and-disclosures/index.html — live page fetched and verified Aug. 9, 2026
5 Patients and Their Rights
- 45 CFR 164.520 (Notice of privacy practices) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- 45 CFR 164.524 (Right of access: designated record set; psychotherapy-notes exclusion; 30-day deadline with one 30-day extension; reasonable cost-based fees) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- 45 CFR 164.526 (Amendment: 60-day deadline with one 30-day extension; permissible denials; statement of disagreement) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.526
- 45 CFR 164.528 (Accounting of disclosures: six-year window; TPO/individual/authorization exceptions; first accounting free in any 12-month period) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.528
- 45 CFR 164.522 (Restrictions and confidential communications) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.522
- 45 CFR 160.306 (Complaints to the Secretary: written, within 180 days unless waived for good cause) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-C/section-160.306
- 45 CFR 164.530(g), (h) (No retaliation; no waiver of rights as condition of treatment, payment, enrollment, or benefits) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- HHS, Summary of the HIPAA Privacy Rule (individual rights: access, amendment, accounting, restrictions, confidential communications; retaliation and waiver prohibitions) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
6 Securing Electronic PHI
- 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information: § 164.302 compliance duty; § 164.304 definitions of confidentiality, integrity, availability; § 164.306 general rules, required/addressable framework, ongoing review; § 164.308 administrative safeguards including required risk analysis and risk management; § 164.310 physical safeguards including disposal and media re-use; § 164.312 technical safeguards including unique user identification, audit controls, authentication, transmission security; § 164.316 documentation and six-year retention) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C — full current text retrieved via the eCFR versioner API (point-in-time data current as of Aug 2026)
- HHS, Summary of the HIPAA Security Rule (e-PHI scope, including the quoted statement that the Security Rule does not apply to PHI maintained or transmitted on paper or verbally; regulated entities; general rules; required/addressable framework) — https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright); the page states "Content last reviewed August 7, 2026."
- 45 CFR 164.530(c) (Privacy Rule requirement of administrative, technical, and physical safeguards for PHI in any form, limiting incidental disclosures) — https://www.ecfr.gov/current/title-45/section-164.530 (via eCFR API)
- HHS, Summary of the HIPAA Privacy Rule (safeguards and everyday-handling expectations corroborated) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
7 When Things Go Wrong
- 45 CFR Part 164, Subpart D (Breach Notification Rule: § 164.402 breach definition, presumption, four-factor risk assessment, exclusions, "unsecured PHI"; § 164.404 individual notice content and 60-day deadline; § 164.406 media notice for more than 500 residents of a state or jurisdiction; § 164.408 notice to the Secretary — with individual notice for 500+, annually within 60 days of year end for smaller breaches; § 164.410 business associate notice within 60 days; discovery imputed when known, or when it would have been known with reasonable diligence, to any workforce member or agent) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D — retrieved via the eCFR API, current through Aug. 6, 2026
- HHS Breach Notification Rule page (breach definition and presumption, four-factor risk assessment, three exceptions, unsecured-PHI/encryption guidance, individual/media/Secretary/business-associate notification deadlines, burden of proof) — https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright)
- 45 CFR Part 160, Subpart B — Preemption of State Law (§§ 160.201–160.205: general rule that contrary state law is preempted; "contrary" and "more stringent" definitions; exceptions) — https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-B — retrieved via the eCFR API
- HHS, Preemption of State Law FAQ page (federal floor; more-stringent state law prevails; no HHS determinations on stringency) — https://www.hhs.gov/hipaa/for-professionals/faq/preemption-of-state-law/index.html — live page fetched and verified Aug. 9, 2026 (headless Chrome via Playwright)
- HHS, Summary of the HIPAA Privacy Rule, "State Law" section (preemption general rule and exceptions) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026
8 A Culture of Compliance
- 45 CFR 164.530 — Privacy Rule administrative requirements (privacy official and complaints contact; workforce training; safeguards; complaint process; sanctions; mitigation; no intimidation or retaliation; six-year documentation retention): https://www.ecfr.gov/current/title-45/section-164.530
- 45 CFR 164.308 — Security Rule administrative safeguards (security official; required risk analysis and risk management; workforce access management; security awareness and training including management; incident procedures; contingency planning; business associate assurances): https://www.ecfr.gov/current/title-45/section-164.308
- 45 CFR 164.316 — Security Rule policies, procedures, and documentation requirements (written policies; six-year retention): https://www.ecfr.gov/current/title-45/section-164.316
- NIST SP 800-66 Rev. 2, "Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide" (Feb. 2024): https://csrc.nist.gov/pubs/sp/800/66/r2/final
- HHS, Summary of the HIPAA Privacy Rule (administrative requirements: privacy official, workforce training, safeguards, complaints, sanctions, mitigation, retaliation/waiver ban, six-year documentation retention) — https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html — live page fetched and verified Aug. 9, 2026