3.1 Privacy and Security Law: HIPAA and HITECH
Key Takeaways
- HIPAA covered entities are health plans, healthcare clearinghouses, and providers who conduct standard electronic transactions; vendors that create, receive, maintain, or transmit PHI for them are business associates and need a BAA.
- The minimum necessary standard limits PHI uses, disclosures, and requests to what the purpose requires, with listed exceptions that include treatment and disclosures to the individual.
- The Security Rule organizes ePHI protections into administrative, physical, and technical safeguards for confidentiality, integrity, and availability; addressable specifications require a documented risk-based decision, not a skip.
- A breach of unsecured PHI requires individual notice without unreasonable delay and no later than 60 calendar days after discovery; incidents affecting 500 or more individuals also require timely HHS notice and media notice in the affected state or jurisdiction.
- HITECH strengthened HIPAA by creating statutory breach notification, making business associates directly liable for the Security Rule and specified Privacy Rule duties, and increasing enforcement—it did not replace HIPAA.
3.1 Privacy and Security Law: HIPAA and HITECH
Quick Answer: HIPAA’s Privacy, Security, and Breach Notification Rules—strengthened by HITECH—are the operational floor for HIT. CPHIMS Domain I A.4 expects you to apply covered-entity and business-associate roles, the minimum necessary standard, Security Rule safeguard categories, and breach-notification triggers to system, vendor, and workforce decisions.
Why this law stack matters for HIT
A CPHIMS professional does not “do HIPAA” as an annual slide deck. Privacy and security law is how you decide who may open a problem list, whether a cloud host may store images, how fast a lost laptop becomes a reportable event, and whether an interface should send a full continuity-of-care document when a single laboratory result is all the receiving clinician needs. Domain I A.4 tests whether you can translate HHS rules into configuration, contracts, and incident response, not whether you can recite that HIPAA was enacted in 1996.
The HIPAA rule family (use official names)
HIPAA’s Administrative Simplification framework lives mainly in 45 CFR Parts 160 and 164. Keep four interlocking rules distinct:
| Rule | What it governs | Typical HIT artifacts |
|---|---|---|
| Privacy Rule | When PHI may be used or disclosed; individual rights | Role design, notice of privacy practices, access and amendment workflows, accounting of disclosures |
| Security Rule | Confidentiality, integrity, and availability of ePHI | Risk analysis, access control, audit logs, encryption, facility security, contingency plans |
| Breach Notification Rule | Notice after a breach of unsecured PHI | Incident playbooks, encryption inventory, OCR reporting, individual and media notices |
| Enforcement Rule | Investigations, civil money penalties, resolution agreements | Evidence retention, sanction policy, OCR response packets |
Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate in any form. Electronic PHI (ePHI) is PHI in electronic form—the Security Rule’s target. Data that meet the Privacy Rule’s expert-determination or safe-harbor de-identification methods are not PHI. A limited data set is still PHI and requires a data-use agreement.
Do not treat “it is in the EHR” as the definition of PHI. Paper charts, verbal disclosures, faxes, photos, and backup tapes can all be PHI. The Security Rule applies when that information is electronic.
Who is regulated: covered entities, workforce, business associates
Covered entities (CEs) are (1) health plans, (2) healthcare clearinghouses, and (3) healthcare providers who transmit health information electronically in connection with a HIPAA standard transaction (claims, eligibility, remittance, and similar). A hospital, medical group, or health plan is usually a CE. Assuming a modern electronic practice is “not a covered entity” is a high-risk exam and operational error.
Workforce members—employees, volunteers, trainees, and others under the CE’s direct control—are not business associates. They are controlled through policies, role-based access, training, and sanctions.
Business associates (BAs) create, receive, maintain, or transmit PHI on behalf of a CE: EHR and cloud hosts, transcription, billing companies, many HIE operators, consultants who need PHI, and destruction vendors that handle PHI. Subcontractors of a BA that handle PHI are BAs of that BA.
A business associate agreement (BAA) is the required contract that binds the BA to permitted uses and disclosures, safeguard duties, breach reporting to the CE, and flow-down to subcontractors. CPHIMS trap: “The vendor signed an NDA, so we are fine.” An NDA is not a BAA. Another trap: treating a cloud infrastructure provider as “just a conduit” when it stores or maintains ePHI. If the vendor maintains ePHI, obtain a BAA before go-live.
Minimum necessary
The minimum necessary standard requires a CE or BA to make reasonable efforts to limit PHI uses, disclosures, and requests to the minimum needed for the purpose. Operationalize it with role-based access and audited break-the-glass; interface filters that send the needed payload rather than the entire longitudinal record by default; extract reviews so analytics teams do not pull full charts for a quality numerator; and vendor statements of work that name data elements.
Listed exceptions include disclosures for treatment, disclosures to the individual, uses or disclosures required by law, and certain compliance investigations. Candidates often over-apply minimum necessary to a treating physician requesting the record—that treatment pathway is not the classic choke point. Conversely, a revenue-cycle vendor that receives a full psychiatric narrative when a claim attachment would suffice is a textbook failure.
Security Rule: CIA and three safeguard categories
The Security Rule requires reasonable and appropriate administrative, physical, and technical safeguards so ePHI remains confidential, intact, and available. HHS expects a risk analysis and risk-management process scaled to size, complexity, and capabilities—not a vendor brochure pasted into policy.
| Safeguard category | Exam-ready examples |
|---|---|
| Administrative | Security official, workforce security, information-access management, security awareness training, incident procedures, contingency plan, evaluation, BA contracts |
| Physical | Facility access controls, workstation use and security, device and media controls (reuse, disposal, backup movement) |
| Technical | Unique user identification, emergency access procedure, automatic logoff, encryption and decryption, audit controls, integrity controls, transmission security |
Implementation specifications are required or addressable. Addressable does not mean optional. The entity must implement the specification if reasonable and appropriate, or document why an equivalent alternative (or, rarely, why neither is reasonable) fits the risk analysis. Encryption of ePHI at rest and in transit is the classic addressable control that most organizations should treat as expected practice because it also supports the breach safe harbor for secured PHI.
HITECH made business associates directly responsible for Security Rule compliance. The CE cannot outsource accountability by pointing at the vendor; both the BAA and the BA’s own safeguards matter.
What HITECH actually changed
The Health Information Technology for Economic and Clinical Health (HITECH) Act (2009, enacted as part of the American Recovery and Reinvestment Act) did not repeal HIPAA. It strengthened it:
- Statutory breach notification for unsecured PHI, now the Breach Notification Rule.
- Direct liability for BAs and their subcontractors for the Security Rule and specified Privacy Rule provisions.
- Stronger enforcement. Civil money penalty tiers are inflation-adjusted; do not memorize a stale dollar table. If a scenario cites dollars, use the current HHS/OCR published amounts rather than inventing a figure.
- A policy push toward certified EHR technology that later evolved into today’s Medicare Promoting Interoperability Program. Do not call the current CMS program “Meaningful Use.”
HITECH is why a “we only hired them” defense fails. If the billing clearinghouse or cloud EHR is a BA, OCR can look at that BA directly. OCR remains the primary federal HIPAA enforcer.
Breach notification triggers and clocks
A breach is generally an impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy. The rule presumes a breach unless the CE or BA demonstrates a low probability that PHI has been compromised, using a documented four-factor assessment: nature and extent of PHI; the unauthorized person; whether PHI was actually acquired or viewed; and the extent of mitigation.
Unsecured PHI has not been rendered unusable, unreadable, or indecipherable to unauthorized persons per HHS guidance. Properly encrypted ePHI that meets that guidance can qualify for the encryption safe harbor—another reason encryption is an operational control, not a slogan. Password-only laptop login is not that safe harbor.
Discovery starts the clock. Business associates notify the covered entity so the CE can notify individuals (contracts often require much faster BA notice than the regulatory outer bound):
| Event | Who is notified | Timing |
|---|---|---|
| Any breach of unsecured PHI | Affected individuals | Without unreasonable delay and no later than 60 calendar days after discovery |
| Breach affecting 500 or more individuals | HHS (OCR) and a prominent media outlet serving the state or jurisdiction | Without unreasonable delay and no later than 60 calendar days after discovery |
| Breach affecting fewer than 500 individuals | HHS via the annual log | No later than 60 days after the end of the calendar year of discovery |
| BA discovers the incident | The covered entity | Without unreasonable delay and no later than 60 days |
Law enforcement may permit delay. Do not invent other delay rights. Do not wait for a forensic firm’s polished final report if you already reasonably believe a 500-or-more unsecured breach occurred.
CPHIMS decision scenarios
A nurse’s unencrypted laptop holding downloaded discharge summaries is stolen from a car. HIT’s first professional moves are containment and a documented risk assessment—not a press release and not “it is probably fine because the operating system had a password.” If unsecured PHI of 500 or more individuals is involved and low probability cannot be shown, individual, HHS, and media notices sit on the 60-day clocks.
A population-health vendor wants production claims and clinical notes “to tune the model.” Without a BAA, a defined purpose, and minimum-necessary data, this is an impermissible disclosure, not a clever analytics project.
A researcher asks for a fully identified extract “because the IRB approved it.” IRB approval does not replace a HIPAA authorization, a waiver of authorization, or a properly limited data set with a data-use agreement.
Exam traps
- Calling addressable specifications optional — they require a documented, risk-based decision.
- Confusing workforce with a business associate — employed analysts are workforce; the offshore transcription firm is a BA.
- Using an NDA or generic MSA as a BAA substitute.
- Applying minimum necessary to block treating clinicians — treatment is a listed exception.
- Thinking encryption makes every incident vanish — only if it meets HHS guidance for securing PHI; paper printouts and screenshots remain unsecured.
- Mixing HIPAA with Joint Commission or CMS Conditions of Participation — different authorities (section 3.3).
- Treating “Meaningful Use” as the current CMS program name — use Promoting Interoperability.
HIPAA is the privacy and security floor. The next section adds Cures Act sharing duties that sometimes require release of electronic health information a nervous privacy office would rather sit on.
A health system is moving the EHR and image archive to a cloud host that will store ePHI. Legal has a mutual NDA and a master services agreement that is silent on HIPAA. What is the CPHIMS-aligned next contract action before go-live?
An emergency physician at a receiving trauma center requests the sending hospital’s current medication list and allergy history for a patient en route. The HIM clerk wants to withhold the data because “minimum necessary means we only send what billing needs.” What is the correct application of the Privacy Rule?
On March 10 a covered entity discovers that an unencrypted backup containing the unsecured PHI of 620 clinic patients was posted to a public share. Low probability of compromise cannot be shown. Besides notifying affected individuals, which HHS Breach Notification Rule duty applies?