HIPAAmart

HIPAA foundations · 9 min read

HIPAA Overview

A map of the HIPAA rules, the organizations they reach, and the operational work that turns obligations into evidence.

Reviewed August 2026

Definition

HIPAA is a federal framework that includes privacy, security, breach notification, and related administrative requirements for covered entities and business associates.

In practice

  • A physician practice maps its EHR, billing service, cloud backup, workforce access, and patient-request process before selecting controls.
  • A software vendor distinguishes its contractual business associate obligations from the customer's own configuration responsibilities.

Who this applies to

  • Covered entities
  • Business associates and their subcontractors
  • Workforce members whose duties involve protected health information

What the rule asks for

  • Identify which HIPAA rules and definitions apply to the organization and activity.
  • Protect PHI under the Privacy Rule and ePHI under the Security Rule when those rules apply.
  • Maintain documentation, training, risk analysis, and response processes that match the organization's environment.

How teams put it into practice

  • Start with an inventory of data, systems, people, vendors, and disclosures.
  • Assign accountable owners for privacy, security, incident response, and individual rights.
  • Use the rule text and official guidance as the source of truth, then document risk-based implementation choices.

Common mistakes

  • Treating HIPAA as a single software setting or certification.
  • Copying a policy set without connecting it to actual workflows and evidence.
  • Overlooking business associates, subcontractors, and non-production systems.

Questions that come up

What are the main HIPAA rules?

The Privacy, Security, and Breach Notification Rules are the core operational rules for many organizations; HIPAA also includes transactions and code sets, identifiers, and enforcement provisions.

References