6.1 HIPAA Privacy, Security, & Breach Notification Rules

Key Takeaways

  • The Health Insurance Portability and Accountability Act (HIPAA) of 1996 and HITECH Act of 2009 establish federal standards protecting Protected Health Information (PHI) and electronic PHI (ePHI).
  • The Privacy Rule defines Covered Entities (CEs) and Business Associates (BAs), mandating Business Associate Agreements (BAAs) and adherence to the Minimum Necessary Rule.
  • Treatment, Payment, and Healthcare Operations (TPO) represent statutory exceptions where patient authorization is NOT required to disclose PHI for billing and claim submission.
  • The Security Rule establishes Administrative, Physical, and Technical Safeguards designed to safeguard ePHI confidentiality, integrity, and availability.
  • The Breach Notification Rule requires individual notifications within 60 calendar days of discovery and HHS OCR notification (plus prominent media alert if breach affects 500+ individuals).
Last updated: August 2026

6.1 HIPAA Privacy, Security, & Breach Notification Rules

Healthcare compliance, patient privacy, and data security are foundational pillars of modern medical billing and coding practice. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 (Public Law 104-191) and the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 (enacted under the ARRA) establish comprehensive federal standards to safeguard sensitive patient health information, regulate health data transactions, and enforce severe civil and criminal penalties for non-compliance.

For the National Certified Insurance and Coding Specialist (NCICS) exam, billing professionals must master the core provisions of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, alongside business associate obligations, Notice of Privacy Practices (NPP) standards, Treatment, Payment, and Healthcare Operations (TPO) billing exceptions, and federal administrative penalty structures.


1. Statutory Foundations: HIPAA & HITECH Act Overview

Congress enacted HIPAA in 1996 with two primary objectives: Title I protects health insurance coverage for workers and their families when they change or lose jobs (portability), while Title II establishes Administrative Simplification provisions requiring standard national electronic transactions, unique health identifiers, and federal privacy and security safeguards.

In 2009, the HITECH Act significantly expanded HIPAA's legal scope and enforcement mechanisms. HITECH incentivized the adoption of Electronic Health Records (EHRs), extended direct legal liability for HIPAA compliance to Business Associates (BAs), introduced mandatory breach notification requirements, and dramatically increased civil monetary penalty caps for regulatory violations.

Federal LegislationPrimary Legislative Enactment YearCore Statutory Mandates & Regulatory Focus
HIPAA Title II1996Established Administrative Simplification, national EDI coding standards, and initial Privacy/Security Rules
HITECH Act2009Extended direct statutory liability to Business Associates, enacted Breach Notification Rule, and increased penalty tiers
Omnibus Rule2013Finalized HITECH implementation, modified Privacy/Security standards, and strengthened enforcement guidelines

2. The HIPAA Privacy Rule & Protected Health Information (PHI)

The HIPAA Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) regulates the use and disclosure of Protected Health Information (PHI) by regulated entities. Privacy standards apply to all forms of PHI—whether electronic, paper, or oral.

Defining Protected Health Information (PHI)

PHI is defined as individually identifiable health information created, received, maintained, or transmitted by a Covered Entity or Business Associate that relates to:

  1. The past, present, or future physical or mental health condition of an individual.
  2. The provision of healthcare to the individual.
  3. The past, present, or future payment for the provision of healthcare to the individual.

Statutory PHI encompasses 18 specific personal identifiers when combined with health data, including patient names, geographic subdivisions smaller than a state, all dates (birth date, admission date, discharge date, date of death), phone/fax numbers, email addresses, Social Security Numbers (SSNs), Medical Record Numbers (MRNs), health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers, device serial numbers, Web URLs, IP addresses, biometric identifiers (fingerprints), full-face photographic images, and any other unique identifying number or characteristic.

Covered Entities (CEs) vs. Business Associates (BAs)

HIPAA explicitly defines regulated organizations into two legal classes:

  • Covered Entities (CEs): Organizations directly bound by HIPAA rules, comprising (1) Healthcare Providers who transmit health information electronically in connection with covered transactions (e.g., physicians, hospitals, pharmacies, clinics), (2) Health Plans (e.g., commercial insurers, Medicare, Medicaid, HMOs, employer group health plans), and (3) Healthcare Clearinghouses (entities that process nonstandard health information into standard EDI format).
  • Business Associates (BAs): Individuals or third-party entities that perform functions, activities, or services on behalf of a Covered Entity that involve the use or disclosure of PHI. Examples include third-party medical billing companies, external coding consultants, EHR software vendors, cloud hosting providers, IT infrastructure contractors, collection agencies, and legal/accounting firms.
  • Business Associate Agreements (BAAs): CEs must execute a legally binding Business Associate Agreement (BAA) with all BAs prior to sharing PHI. A BAA formally establishes the permitted uses and disclosures of PHI, mandates that the BA implement administrative, physical, and technical safeguards, and requires the BA to report any security incidents or breaches to the CE.

Minimum Necessary Rule

The Minimum Necessary Standard requires Covered Entities and Business Associates to make reasonable efforts to limit the access, use, and disclosure of PHI to the absolute minimum necessary to accomplish the intended administrative or clinical purpose.

  • Administrative Application: Medical billing specialists must only access patient record sections relevant to claim submission (e.g., encounter notes, diagnosis lists, procedure codes, demographics) rather than browsing complete psychiatric or historical records.
  • Statutory Exceptions to Minimum Necessary: The Minimum Necessary standard does NOT apply to:
    1. Disclosures to or requests by a healthcare provider for treatment purposes.
    2. Disclosures made directly to the patient.
    3. Uses or disclosures authorized by the patient in writing.
    4. Disclosures required by law (e.g., court orders, mandatory communicable disease reporting).
    5. Disclosures required for HIPAA compliance investigations.

Notice of Privacy Practices (NPP)

Covered Entities must provide patients with a Notice of Privacy Practices (NPP) at or prior to the first service delivery. The NPP outlines how patient PHI may be used and disclosed, details patient privacy rights (right to inspect/copy records, request amendments, receive an accounting of disclosures, request confidential communications), and specifies CE duties. Providers must make a good-faith effort to obtain a signed written acknowledgment of receipt from the patient.


3. TPO Exceptions: Billing & Claim Submission Disclosures

A critical concept for NCICS specialists is Treatment, Payment, and Healthcare Operations (TPO). Under HIPAA Privacy Rule 45 CFR 164.506, Covered Entities are permitted to use and disclose PHI for TPO purposes without obtaining prior written patient authorization.

                    ┌─────────────────────────────────────────┐
                    │ TPO DISCLOSURE EXCEPTIONS (No Prior     │
                    │ Patient Authorization Required)         │
                    └────────────────────┬────────────────────┘
                                         │
         ┌───────────────────────────────┼───────────────────────────────┐
         ▼                               ▼                               ▼
┌─────────────────┐             ┌─────────────────┐             ┌─────────────────┐
│   TREATMENT     │             │     PAYMENT     │             │   OPERATIONS    │
│ Provision,      │             │ Claim submission│             │ Quality review, │
│ coordination, or│             │ eligibility, PA,│             │ compliance,     │
│ referral among  │             │ billing, &      │             │ auditing, &     │
│ providers       │             │ collections     │             │ accreditation   │
└─────────────────┘             └─────────────────┘             └─────────────────┘

Defining TPO Categories

  1. Treatment: The provision, coordination, or management of healthcare and related services by one or more healthcare providers, including consultations between providers and patient referrals.
  2. Payment: Activities undertaken by healthcare providers or health plans to obtain premiums, fulfill coverage responsibilities, and obtain reimbursement for healthcare services. This includes determining eligibility/coverage, coordination of benefits, prior authorization (PA), utilization review, billing, claims adjudication, subrogation, and debt collection.
  3. Healthcare Operations: Administrative, financial, legal, and quality improvement activities necessary to run a healthcare facility, including quality assessment, practitioner auditing, credentialing, employee training, legal compliance, and business planning.

Exam Tip: Submitting a CMS-1500 or UB-04 claim to Medicare, commercial insurers, or clearinghouses falls squarely under Payment. Patient authorization is NOT legally required to submit standard insurance claims containing PHI.


4. The HIPAA Security Rule: Protecting ePHI

While the Privacy Rule applies to PHI in all mediums, the HIPAA Security Rule (45 CFR Part 164, Subpart C) specifically governs electronic Protected Health Information (ePHI)—PHI created, received, maintained, or transmitted in electronic form. The Security Rule establishes three mandatory categories of safeguards: Administrative, Physical, and Technical.

Security Safeguard PillarOperational Scope & FocusMandatory & Addressable Standards
Administrative SafeguardsManagement policies, administrative procedures, and workforce oversight (~54% of Security Rule)Risk analysis, risk management, sanction policy, assigned security official, workforce security/training, periodic evaluation
Physical SafeguardsPhysical protection of facility infrastructure, workstations, and physical mediaFacility access controls, workstation use policy, workstation security, device and media controls (disposal/re-use)
Technical SafeguardsHardware and software technology controls managing access to ePHIAccess control (unique user ID, auto-logoff), audit controls, integrity controls, transmission security (encryption)

1. Administrative Safeguards

  • Risk Analysis & Management: Conducting mandatory, ongoing risk assessments to identify vulnerabilities in electronic systems and implementing measures to reduce risks.
  • Assigned Security Responsibility: Formally designating a Chief Security Officer (CSO) responsible for security policy oversight.
  • Workforce Training: Mandatory initial and periodic security awareness training for all personnel (covering password management, phishing prevention, and incident reporting).
  • Contingency Planning: Establishing data backup plans, disaster recovery procedures, and emergency mode operation plans.

2. Physical Safeguards

  • Facility Access Controls: Implementing door locks, keycard access systems, visitor logs, and physical barriers to restrict unauthorized entry to server rooms and coding areas.
  • Workstation Security & Position: Establishing strict workstation use policies. Monitors must be positioned away from public view or fitted with privacy filters, and screens must automatically lock after specified inactivity periods.
  • Device and Media Controls: Protocol policies governing the receipt, transfer, sanitization, and physical disposal of hardware/media containing ePHI (e.g., hard drive degaussing, physical shredding).

3. Technical Safeguards

  • Access Controls: Assigning unique user identifiers (user IDs) to every employee, enforcing emergency access procedures ("break-glass" protocols), establishing role-based access limits, and enforcing automatic logoff.
  • Audit Controls: Deploying software audit logs that track, record, and index all system activities, logins, file views, edits, and deletions involving ePHI.
  • Integrity Controls: Implementing digital signatures, checksums, and hash functions to verify that ePHI has not been altered or destroyed in an unauthorized manner.
  • Transmission Security: Mandatory encryption of ePHI in transit across public networks using standard cryptographic protocols (e.g., TLS 1.3, AES-256) for email, clearinghouse claim transmissions, and cloud interfaces.

5. Breach Notification Rule & Civil Penalty Tiers

Enacted under the HITECH Act, the Breach Notification Rule (45 CFR §§ 164.400–414) mandates Covered Entities and Business Associates to provide formal notifications following a breach of unencrypted PHI.

Defining a HIPAA Breach

A breach is defined as the unauthorized acquisition, access, use, or disclosure of unencrypted PHI that compromises the security or privacy of the information. Any unauthorized disclosure is presumptively a breach unless the entity demonstrates through a four-factor risk assessment that there is a low probability the PHI was compromised.

Statutory Breach Notification Requirements

  1. Notification to Affected Individuals: The Covered Entity must notify every affected individual in writing via first-class mail (or email if consented) without unreasonable delay and no later than 60 calendar days after discovery of the breach.
  2. Notification to HHS Office for Civil Rights (OCR):
    • Breaches affecting < 500 Individuals: The CE must report the breach to HHS OCR annually via the online portal no later than 60 days after the end of the calendar year.
    • Breaches affecting 500+ Individuals: The CE must notify HHS OCR without unreasonable delay and no later than 60 calendar days following discovery. Additionally, the CE must issue a prominent media alert / press release to major media outlets in the state or jurisdiction.
  3. Business Associate Reporting: BAs must report any discovered breach to the Covered Entity without unreasonable delay and within the timeframe established in their BAA (typically within 5 to 10 business days).

HITECH Civil Monetary Penalty (CMP) Tiers

HHS OCR enforces statutory civil monetary penalties categorized into four culpability tiers based on intent and remediation efforts:

The HITECH Act set the original tiers at $100/$1,000/$10,000/$50,000 minimums with a $1,500,000 annual cap, but every one of those figures is adjusted for inflation each year. The amounts below are the current codified figures at 45 CFR 102.3, effective January 28, 2026. For the exam, learn the four culpability tiers and what separates them — the dollar amounts change annually and the tier definitions do not.

Penalty Culpability TierStandard of CulpabilityPenalty Range per ViolationAnnual Cap (identical provision)
Tier 1: No KnowledgeEntity did not know and, exercising reasonable diligence, would not have known$145 to $73,011$2,190,294
Tier 2: Reasonable CauseViolation due to reasonable cause and not to willful neglect$1,461 to $73,011$2,190,294
Tier 3: Willful Neglect (Corrected)Conscious, intentional failure or reckless indifference, corrected within 30 days of discovery$14,602 to $73,011$2,190,294
Tier 4: Willful Neglect (Uncorrected)Conscious, intentional failure or reckless indifference, NOT corrected within 30 days$73,011 to $2,190,294$2,190,294

The enforcement-discretion overlay. Under a Notice of Enforcement Discretion issued in April 2019, OCR applies lower annual caps than the codified table to the three lower tiers while it works through rulemaking: roughly $36,506 for Tier 1, $146,053 for Tier 2, and $365,052 for Tier 3, with Tier 4 unchanged at $2,190,294. The regulation and OCR's stated practice therefore differ — a distinction worth knowing if a question asks which tier carries the highest exposure (Tier 4, in every version).

Criminal Penalties: Criminal HIPAA violations (e.g., knowingly obtaining or disclosing PHI for commercial advantage or malicious harm) are prosecuted by the U.S. Department of Justice (DOJ), carrying criminal fines up to $250,000 and up to 10 years imprisonment.

Test Your Knowledge

Under the HIPAA Privacy Rule, which of the following scenarios represents a permitted disclosure of Protected Health Information (PHI) WITHOUT requiring prior written patient authorization?

A
B
C
D
Test Your Knowledge

A healthcare provider discovers a security breach compromising the unencrypted ePHI of 650 patients. What is the provider's statutory obligation regarding HHS OCR and media notification under the HIPAA Breach Notification Rule?

A
B
C
D
Test Your Knowledge

Which category of HIPAA Security Rule safeguards specifically governs automatic workstation logoffs, unique user identification numbers, software audit logs, and data transmission encryption?

A
B
C
D