8.1 HIPAA Privacy and Security Rules
Key Takeaways
- HIPAA covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a standard transaction; business associates handle PHI for them under a BAA
- PHI is individually identifiable health information in any form; de-identified data (Safe Harbor or Expert Determination) is not PHI and the Privacy Rule does not restrict its use or disclosure
- The Privacy Rule permits Treatment, Payment, and Health Care Operations without authorization; the minimum necessary standard applies to most other uses and disclosures but not to treatment
- The Security Rule protects only ePHI through administrative, physical, and technical safeguards; addressable specifications are not optional
- HHS OCR enforces the HIPAA Rules; its tracking bulletin treats pixels on authenticated patient portals as PHI, while a 2024 court order vacated the bulletin’s IP-plus-public-condition-page theory
Who HIPAA Actually Covers
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created the federal Administrative Simplification framework. The Privacy Rule (45 CFR Parts 160 and 164, Subparts A and E) limits uses and disclosures of protected health information (PHI) and gives individuals rights in that information. The Security Rule (45 CFR Part 164, Subparts A and C) requires safeguards for electronic protected health information (ePHI). Inside the U.S. Department of Health and Human Services (HHS), the Office for Civil Rights (OCR) implements and enforces both Rules, plus the later Breach Notification Rule.
The Rules do not apply to every company that mentions health. They apply to covered entities and their business associates. The three covered-entity categories are:
- Health plans — individual and group plans that provide or pay the cost of medical care, including health, dental, vision, and prescription insurers, health maintenance organizations (HMOs), Medicare, Medicaid, Medicare supplement insurers, long-term care insurers (other than nursing-home fixed-indemnity policies), and most employer-sponsored group health plans. A group health plan with fewer than 50 participants that the employer administers solely is not a covered entity. Workers’ compensation, automobile, and property-and-casualty insurers are not health plans merely because a claim has a medical component.
- Health care clearinghouses — entities that convert nonstandard health information into a standard format or data content, or the reverse. Billing services, repricing companies, and similar switches are clearinghouses when they perform that conversion.
- Health care providers who transmit electronically — every provider, regardless of size, that transmits health information in electronic form in connection with a standard transaction for which HHS has adopted standards (claims, eligibility inquiries, referral authorizations, and similar Transactions Rule exchanges). Sending ordinary email does not make a provider a covered entity. Transmitting a standard claim, or hiring a billing service to do so, does.
A business associate is a person or organization, other than a workforce member, that performs functions or activities on behalf of a covered entity — or provides legal, actuarial, accounting, consulting, data-aggregation, management, administrative, accreditation, or financial services — that involve using or disclosing individually identifiable health information. Claims processors, cloud hosts that store ePHI, transcriptionists, and many analytics vendors are business associates. A janitorial service with only incidental, unplanned exposure is not. Covered entities must put specified safeguards in a business associate agreement (BAA) and may not authorize a use or disclosure the Privacy Rule would forbid if the covered entity made it itself.
PHI Versus De-Identified Information
PHI is individually identifiable health information a covered entity or business associate holds or transmits in any form — electronic, paper, or oral. It relates to an individual’s past, present, or future physical or mental health or condition, the provision of health care, or payment for that care, and it either identifies the individual or provides a reasonable basis to identify the individual. A lab report with a name, a hospital bill with an address, or an oral consult that names the patient is PHI. Employment records a hospital keeps as employer, and education records subject to the Family Educational Rights and Privacy Act (FERPA), are excluded.
De-identified information is not PHI. The Privacy Rule does not restrict its use or disclosure. HHS recognizes two methods under 45 CFR 164.514:
| Method | What the covered entity must do | Residual rule |
|---|---|---|
| Expert Determination | A person with appropriate statistical or scientific knowledge determines that the risk is very small that an anticipated recipient could identify an individual, alone or with other reasonably available information, and documents the methods and results | Documentation of the analysis is part of the method |
| Safe Harbor | Remove specified identifiers of the individual and of relatives, employers, and household members, and have no actual knowledge that the remaining information could identify the individual | Residual identifiers or “actual knowledge” of re-identification defeat Safe Harbor |
Safe Harbor’s identifier list includes names; geographic subdivisions smaller than a state (street, city, county, precinct, ZIP code, and equivalent geocodes), except the initial three ZIP digits when the combined area has more than 20,000 people (otherwise those three digits become 000); all elements of dates except year that relate to an individual, plus ages over 89 (which collapse to 90 or older); telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health-plan beneficiary numbers; account numbers; certificate and license numbers; vehicle and device identifiers; uniform resource locators (URLs); Internet Protocol (IP) addresses; biometric identifiers; full-face photographs; and any other unique identifying number, characteristic, or code. Both methods leave a very small, non-zero re-identification risk. That residual risk does not keep properly de-identified data inside the Privacy Rule.
Privacy Rule: TPO, Minimum Necessary, and Individual Rights
A covered entity may use or disclose PHI only as the Privacy Rule permits or requires, or as the individual (or personal representative) authorizes in writing. Required disclosures are narrow: to the individual who requests access or an accounting, and to HHS for a compliance investigation, review, or enforcement action.
The workhorse permission is Treatment, Payment, and Health Care Operations (TPO). A covered entity may use or disclose PHI for its own TPO without authorization. Treatment is the provision, coordination, or management of health care, including consultations and referrals. Payment is activities to obtain or provide reimbursement. Health care operations include quality assessment, credentialing, auditing, legal services, and certain business-management functions. A covered entity may choose to collect a consent for TPO; HIPAA does not require one. A TPO consent is not a substitute for a 45 CFR 164.508 authorization, which is still required for most marketing, sale of PHI, and uses of psychotherapy notes.
Minimum necessary requires reasonable efforts to use, disclose, or request only the PHI needed for the purpose. Policies must limit routine disclosures, and the entire designated record set is not the default. Minimum necessary does not apply to disclosures for treatment, to the individual, pursuant to an authorization, or required by law (including to HHS).
Individuals have a cluster of Privacy Rule rights that CIPP/US treats as testable mechanics, not slogans:
- Access — inspect or obtain a copy of PHI in a designated record set, generally within 30 days, with a limited extension. HITECH added a right to an electronic copy of ePHI.
- Amendment — request correction of inaccurate or incomplete PHI; the covered entity may deny in defined circumstances and must allow a statement of disagreement.
- Accounting of disclosures — an accounting of certain disclosures for the prior six years. Most TPO disclosures are excluded from the accounting.
- Notice of Privacy Practices — a description of uses, disclosures, and rights.
- Restrictions and confidential communications — individuals may request limits on TPO uses. After HITECH, a covered entity must agree when the individual pays in full out of pocket and asks the entity not to disclose that item to a health plan, unless another law requires the disclosure.
Security Rule: Safeguards and Addressable Versus Required
The Security Rule protects only ePHI — PHI maintained in or transmitted by electronic media. Paper charts and hallway conversations are Privacy Rule problems, not Security Rule problems. Regulated entities (covered entities and, after HITECH, business associates) must ensure the confidentiality, integrity, and availability of ePHI; protect against reasonably anticipated threats and impermissible uses or disclosures; and ensure workforce compliance.
Safeguards come in three buckets. Administrative safeguards are the management layer: a required risk analysis and risk-management process, a security official, workforce clearance and training, information-access management, security-incident procedures, a contingency plan, periodic evaluation, and BAAs. Physical safeguards control buildings and devices: facility access, workstation use and security, and device and media controls (including disposal and reuse). Technical safeguards are the system controls: unique user identification and other access controls, audit controls, integrity protections, person or entity authentication, and transmission security.
Implementation specifications are required or addressable. Required means implement it. Addressable does not mean optional. The entity must assess whether the specification is reasonable and appropriate; implement it if it is; or, if it is not, document why and implement an equivalent alternative if one is reasonable and appropriate. Encryption of ePHI at rest and in transit is the classic addressable example. Skipping encryption without that documented analysis is a Security Rule failure. OCR has proposed (January 2025 Security Rule notice of proposed rulemaking (NPRM)) to eliminate the addressable category and require encryption; that proposal is not current law. Study the Rule that is in effect: flexible, scalable, technology-neutral, and built on a living risk analysis.
Online Tracking on Portals and Public Pages
OCR’s bulletin on Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates is now part of the exam’s HIPAA story. Tracking technologies — cookies, pixels, web beacons, session-replay scripts, fingerprinting, and mobile advertising IDs — collect how users interact with a site or app. When that collection includes PHI, the HIPAA Rules apply. Disclosing PHI to a tracking vendor for marketing without a valid authorization is an impermissible disclosure.
On user-authenticated pages — patient portals, plan-beneficiary portals, telehealth platforms — tracking technologies generally have access to PHI: IP address plus medical record number, appointment dates, diagnoses, prescriptions, or billing data the user can see after login. The regulated entity must configure those pages so any tracking uses and discloses PHI only as the Privacy Rule permits, protect the ePHI under the Security Rule, and execute a BAA if the vendor creates, receives, maintains, or transmits PHI on the entity’s behalf.
On unauthenticated public pages the analysis is narrower. A June 20, 2024 order in American Hospital Association v. Becerra (N.D. Tex.) vacated the bulletin to the extent it treated as PHI a combination of (1) an individual’s IP address and (2) a visit to an unauthenticated public webpage that merely addresses specific health conditions or lists providers. HHS is evaluating next steps. Teach the holding: connecting an IP address to a public condition page is not automatically IIHI. Teach the remainder of the bulletin as still operative: authenticated portals, appointment flows that transmit identifiers, and any tracking that actually captures health, care, or payment information remain inside HIPAA.
Scenario. A hospital drops a third-party analytics pixel on its logged-in patient portal. The pixel sends the vendor the patient’s portal user ID, appointment type, and IP address. That is PHI. The vendor is a business associate if it receives that data to perform health-care operations analytics, and a BAA is required. The same pixel on a “visiting hours” page that captures only IP and page URL, after AHA v. Becerra, is not automatically a HIPAA disclosure.
Exam traps
- A cash-only physician who never conducts a standard electronic transaction is not a covered entity merely for keeping paper charts.
- De-identified data is not “still PHI with fewer fields.” It is outside the Privacy Rule if Safe Harbor or Expert Determination is satisfied.
- Minimum necessary does not throttle a treating physician’s access.
- Addressable encryption is not a free pass to leave ePHI in cleartext.
- OCR, not the FTC, is the primary HIPAA enforcement agency. The FTC Health Breach Notification Rule is a different statute for vendors of personal health records that are not HIPAA covered entities.
A rural cash-only dentist keeps paper charts and uses email only to send appointment reminders. She never transmits claims, eligibility inquiries, or other HIPAA standard transactions and does not hire a billing service to do so. Which statement is correct?
Which statement correctly describes HIPAA de-identification?
A hospital places a third-party advertising pixel on its logged-in patient portal. The pixel transmits portal user IDs, upcoming appointment types, and IP addresses to the vendor. What does OCR’s tracking bulletin require?