HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).
Expertise Areas
HIPAA Security Rule Overview
Regulatory Citation: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information)
Effective Date: April 21, 2003 (Compliance Date: April 20, 2005)
Enforcement: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR)
Guidance Document: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)
Scope:
Applies to electronic PHI (ePHI) only - not paper records or oral communications
Covered Entities (CEs): Healthcare providers, health plans, healthcare clearinghouses that transmit ePHI
Business Associates (BAs): Vendors/contractors who create, receive, maintain, or transmit ePHI on behalf of CEs (e.g., cloud providers, EHR vendors, billing companies, data analytics firms)
Subcontractors: BAs must have contracts with their own subcontractors
What is ePHI?
Individually identifiable health information in electronic form
Includes any demographic information collected from an individual that:
Relates to physical/mental health condition
Relates to provision of healthcare
Relates to payment for healthcare
18 HIPAA identifiers (names, dates, medical record numbers, etc.) + health information
Enforcement and Penalties
OCR Enforcement Triggers:
Breach Reports: Unsecured ePHI affecting 500+ individuals (must report to OCR within 60 days)
Complaints: Patients/employees filing complaints with OCR
Desk Audits: OCR requests documentation remotely
On-Site Audits: Comprehensive compliance reviews
Media Reports: News of breaches or violations
Penalty Tiers (per violation category per year):
Tier 1: Lack of knowledge (reasonable diligence would not have known) - Minimum $100 per violation, max $25,000
Tier 2: Reasonable cause (not willful neglect) - Minimum $1,000 per violation, max $100,000
Tier 3: Willful neglect corrected within 30 days - Minimum $10,000 per violation, max $250,000
Tier 4: Willful neglect not corrected - Minimum $50,000 per violation, max $1.9 million
Note: "Per violation category" means penalties are capped annually, not per individual breach event.
The Five Safeguard Categories
1. Administrative Safeguards (45 CFR §164.308)
What It Governs: Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.
Key Standards/Implementation Specifications:
Security Management Process (§164.308(a)(1)): Risk analysis, risk management, sanction policy, information system activity review
Assigned Security Responsibility (§164.308(a)(2)): Designated security official with authority and responsibility
What It Governs: Physical measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.
Key Standards/Implementation Specifications:
Facility Access Controls (§164.310(a)(1)): Contingency operations, facility security plan, access control and validation, maintenance records
Workstation Use (§164.310(b)): Policies specifying proper workstation use for ePHI
Workstation Security (§164.310(c)): Physical safeguards for workstations that access ePHI
Device and Media Controls (§164.310(d)(1)): Disposal, media re-use, accountability, data backup and storage
What It Governs: Business Associate Agreements and group health plan requirements.
Key Standards/Implementation Specifications:
Business Associate Agreements (§164.314(a)(1)): Written contract between CE and BA specifying permitted/required uses, safeguards, reporting, and BA obligations to subcontractors
Business Associate Agreements - Group Health Plans (§164.314(b)(1)): Plan documents must provide that the plan sponsor will adequately safeguard ePHI
Documentation must explain why destruction is not appropriate
Password Management (§164.308(a)(5)(ii)(D))
Why addressable: Some organizations use alternative authentication
Alternative: Biometrics, smart cards, certificates, or other multi-factor methods
Documentation must explain why passwords are not used
Best Practice for Addressable Specs:
Conduct an organization-wide assessment
For each addressable spec, document:
Whether you implement it as-is
If not, why it is not reasonable/appropriate (cost, technical feasibility, operational impact)
What alternative you implemented instead
How the alternative provides equivalent protection
Review annually as technology and operations evolve
Risk Analysis (§164.308(a)(1)(ii)(A)) - The Linchpin
Why It's Critical:
The risk analysis is the foundation of every HIPAA Security Rule compliance program. It is the most frequently cited requirement in OCR Resolution Agreements and enforcement actions.
What a Defensible Risk Analysis Includes:
ePHI Scope and Data Flow Inventory:
Map all systems that create, receive, maintain, or transmit ePHI
Document data flows between systems
Identify all external connections (internet-facing systems, VPNs, BAs)
Catalog storage locations (databases, file servers, cloud storage, mobile devices)