HIPAA Security Rule Safeguards: Breach Notification and Penalties

The HIPAA Security Rule safeguards are the federal standards, codified at 45 CFR Part 164, Subpart C, that require health care organizations and their vendors to protect electronic protected health information (ePHI) through three categories of controls: administrative, physical, and technical. The rule also imposes organizational and documentation duties, and failure to comply can bring civil penalties up to $2,190,294 per violation category per year, plus criminal prosecution for intentional misuse of patient data.

Who Has to Follow the Rule

Two groups are bound by the Security Rule. The first is covered entities: health care providers that transmit information electronically in connection with a standard transaction, health plans (including insurance companies, HMOs, employer-sponsored plans, Medicare, and Medicaid), and health care clearinghouses.1U.S. Department of Health & Human Services. Covered Entities and Business Associates

The second is business associates — vendors, contractors, and subcontractors that create, receive, maintain, or transmit ePHI on behalf of a covered entity. They are directly liable for Security Rule compliance under the HITECH Act and the 2013 Omnibus Rule.2U.S. Department of Health and Human Services. Direct Liability of Business Associates A cloud storage provider hosting patient records, a billing company processing claims, and an IT contractor managing a hospital’s servers all sit on the hook alongside the provider.

Required Versus Addressable: How the Rule Flexes

The Security Rule does not name specific technologies. Each organization picks measures that are reasonable and appropriate for its situation, weighing four factors: its size, complexity, and capabilities; its existing technical infrastructure; the cost of implementation; and the probability and severity of risks to ePHI.3eCFR. 45 CFR 164.306 – Security Standards: General Rules A large hospital system and a solo clinic face the same standards but can meet them very differently.

Within each safeguard standard, the implementation specifications are labeled either “required” or “addressable.” Required means implement it, no exceptions. Addressable does not mean optional. If an addressable measure is reasonable and appropriate given your risk analysis, you must implement it. If it is not, you must adopt an equivalent alternative that achieves the same purpose, or document why neither the specification nor any alternative is necessary. Every decision about an addressable specification has to be in writing.4U.S. Department of Health & Human Services. What Is the Difference Between Addressable and Required Implementation Specifications

Administrative Safeguards

Administrative safeguards, at 45 CFR § 164.308, cover the policies, procedures, and management actions used to protect ePHI. This is the broadest category and the one where enforcement actions most often land.5eCFR. 45 CFR 164.308 – Administrative Safeguards

Risk Analysis and Risk Management

The risk analysis is the foundation of the whole program, and it is the requirement OCR cites most often in enforcement actions. You must conduct an accurate and thorough assessment of every potential risk and vulnerability to the confidentiality, integrity, and availability of all ePHI you create, receive, store, or transmit. That includes ePHI on servers, laptops, portable drives, and data moving across networks.

A proper risk analysis is not a checklist. It requires identifying where all ePHI lives, cataloging internal and external threats, evaluating existing security measures, estimating likelihood and severity, and assigning a risk level to each finding. From that, the organization builds a risk management plan to reduce risks to a reasonable level. This is ongoing work. The analysis needs updating whenever technology, operations, or the threat picture shifts.

Workforce Security and Training

A designated security official must own the program. Workforce security standards require screening procedures for anyone who touches ePHI, termination procedures that immediately revoke access when someone leaves, and access authorization policies that define who can view, modify, or transmit which data.5eCFR. 45 CFR 164.308 – Administrative Safeguards

Security awareness training is required for the entire workforce — employees, volunteers, trainees, anyone whose work you control. The rule does not set a frequency, but most compliance professionals recommend at least annual refreshers, plus training at hire, after material policy or job-duty changes, and whenever a risk analysis turns up a gap.6U.S. Department of Health & Human Services. Summary of the HIPAA Security Rule Topics should include recognizing phishing and malicious software, handling passwords, and reporting suspicious activity.

Contingency Planning

Contingency planning keeps patient records available through fires, floods, ransomware, and system failures. Required components include a data backup plan storing ePHI copies in a separate secure location, a disaster recovery plan for restoring lost data, and an emergency mode operation plan that keeps critical processes running during recovery. Test the procedures regularly. A backup that cannot actually be restored is no backup.

Physical Safeguards

Physical safeguards at 45 CFR § 164.310 protect the buildings, rooms, and equipment where ePHI is stored or accessed.7eCFR. 45 CFR 164.310 – Physical Safeguards

Facility Access

Limit who can physically enter areas containing servers, workstations, or other hardware that stores ePHI. ID badges, visitor logs, surveillance cameras, and locked server rooms all count. A facility security plan should also address tampering and theft, and the controls extend to every location where ePHI is accessible, including remote offices and off-site data centers.

Workstations and Devices

Workstation use policies define how devices should be operated to prevent unauthorized viewing. That means positioning monitors away from public sight lines, using privacy filters in patient-facing areas, and making sure workstations in shared spaces cannot be casually observed.7eCFR. 45 CFR 164.310 – Physical Safeguards

Device and media controls govern hardware and portable storage moving within or out of a facility. Before a hard drive is repurposed, follow approved methods to wipe sensitive data. When equipment is discarded, physically destroy or shred it. The same rules apply to a data center server and to the USB drive an employee used last week.

Technical Safeguards

Technical safeguards at 45 CFR § 164.312 cover the technology-based tools that control access to ePHI and protect it in storage and transit.8eCFR. 45 CFR 164.312 – Technical Safeguards

Access Controls

Every user needs a unique identifier that ties system activity back to one person. This one is required, no exceptions. Emergency access procedures must also be in place so staff can reach critical patient information during a crisis when normal login fails. Automatic logoff, which ends inactive sessions after a set period, is addressable, and most organizations implement it because unattended workstations are a constant clinical risk.8eCFR. 45 CFR 164.312 – Technical Safeguards

Audit Controls, Integrity, and Authentication

Audit controls require hardware, software, or procedural mechanisms that record and examine activity in any system containing ePHI. The logs create the forensic trail investigators use to identify unauthorized access and scope a breach. Reviewing them regularly catches suspicious patterns before they become reportable incidents.

Integrity controls protect ePHI from improper alteration or destruction. Checksums and digital signatures can verify that a file has not been tampered with. A separate person or entity authentication standard requires procedures to verify that anyone requesting access is who they claim to be.

Transmission Security and Encryption

Transmission security guards against interception of ePHI moving across networks. Encryption is the primary tool. The Security Rule classifies encryption as addressable rather than required, but few organizations can justify skipping it, and encryption also provides the safe harbor from breach notification described below.8eCFR. 45 CFR 164.312 – Technical Safeguards

Business Associate Agreements

Before you share ePHI with a vendor, the two parties must execute a business associate agreement (BAA). The contract has to require the business associate to comply with the applicable Security Rule provisions, report any security incident to the covered entity (including breaches of unsecured ePHI), and ensure that any subcontractors it hires also enter compliant agreements.9eCFR. 45 CFR 164.314 – Organizational Requirements

Subcontractor liability catches many organizations off guard. A business associate that hires a subcontractor to handle ePHI is directly liable for failing to put a BAA in place with that subcontractor and for failing to take reasonable steps to address a subcontractor’s material violation.2U.S. Department of Health and Human Services. Direct Liability of Business Associates Liability chains down through every layer of outsourcing.

Documentation and Retention

Under 45 CFR § 164.316, every security policy, procedure, and compliance action must be maintained in written or electronic form. If the rule requires an action, activity, or assessment to be documented, a written record has to exist.10eCFR. 45 CFR 164.316 – Policies and Procedures and Documentation Requirements

Retention runs six years from the date a document was created or the date it was last in effect, whichever is later. When you update a policy, the original version has to stay in the archives for the full six-year period.10eCFR. 45 CFR 164.316 – Policies and Procedures and Documentation Requirements Documentation must be available to staff responsible for carrying out the policies. During an OCR investigation, these records are the primary evidence of compliance. An organization that did the work but cannot prove it will be treated the same as one that did not.

When Safeguards Fail: Breach Notification

When ePHI is compromised, the HIPAA Breach Notification Rule adds a separate set of obligations. A breach is any unauthorized acquisition, access, use, or disclosure of protected health information that compromises its security or privacy. Narrow exceptions exist, such as an unintentional access by a workforce member acting in good faith and within the scope of authority. Outside those exceptions, any unauthorized exposure is presumed to be a breach unless a risk assessment shows a low probability that the information was actually compromised.11eCFR. 45 CFR 164.402 – Definitions

You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach. The clock starts the day the breach is known or should have been known through reasonable diligence. Written notice goes by first-class mail to the last known address, or by email if the individual has agreed to electronic communication.12eCFR. 45 CFR 164.404 – Notification to Individuals

If a breach affects more than 500 residents of a single state or jurisdiction, notify prominent media outlets serving that area within 60 days.13U.S. Department of Health & Human Services. Breach Notification Rule Breaches of that size also go to the Secretary of HHS within the same 60-day window through the online breach reporting portal. Smaller breaches — those affecting fewer than 500 individuals — may be reported to HHS annually, within 60 days of the end of the calendar year in which they were discovered.14U.S. Department of Health and Human Services. Submitting Notice of a Breach to the Secretary

The notification requirements apply only to “unsecured” PHI, meaning information not rendered unusable, unreadable, or indecipherable to unauthorized persons. HHS guidance identifies encryption and destruction as the two qualifying methods. If ePHI was properly encrypted at the time of a breach, the organization is relieved from the notification obligations entirely.13U.S. Department of Health & Human Services. Breach Notification Rule That safe harbor is one of the strongest practical arguments for encrypting all ePHI at rest and in transit, even though encryption is technically addressable.

Penalties

The HHS Office for Civil Rights enforces the Security Rule through complaint investigations, compliance reviews, and audits. The audit cycle launched in 2024 focused specifically on Security Rule provisions most relevant to hacking and ransomware.15U.S. Department of Health and Human Services. OCR’s HIPAA Audit Program

Civil Penalty Tiers

Civil monetary penalties follow four tiers based on culpability. Base amounts set by 45 CFR § 160.404 are adjusted annually for inflation.16eCFR. 45 CFR 160.404 – Amount of a Civil Money Penalty The 2026 inflation-adjusted figures:17Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Tier 1, did not know: the entity did not know and could not reasonably have known about the violation. $145 to $73,011 per violation.
  • Tier 2, reasonable cause: the violation resulted from reasonable cause rather than willful neglect. $1,461 to $73,011 per violation.
  • Tier 3, willful neglect, corrected: willful neglect but corrected within 30 days of discovery. $14,602 to $73,011 per violation.
  • Tier 4, willful neglect, not corrected: willful neglect and not corrected within 30 days. $73,011 to $2,190,294 per violation.

The annual cap for identical violations across all tiers is $2,190,294 per calendar year. “Willful neglect” means a conscious, intentional failure or reckless indifference to the obligation to comply.18eCFR. 45 CFR 160.401 – Definitions Failing to conduct a risk analysis at all, the most common finding in OCR enforcement actions, is the kind of gap that tends to land in Tier 3 or Tier 4.

Criminal Penalties

Separate from civil enforcement, criminal penalties apply to individuals who knowingly obtain or disclose protected health information in violation of HIPAA. The tiers escalate with intent:

  • Basic offense: up to $50,000 in fines and one year in prison.
  • False pretenses: up to $100,000 in fines and five years in prison.
  • Commercial or malicious intent: up to $250,000 in fines and ten years in prison, for offenses committed with intent to sell, transfer, or use health information for commercial advantage, personal gain, or malicious harm.

OCR refers criminal cases to the Department of Justice for prosecution.19Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

What Could Change Soon

In January 2025, HHS published a Notice of Proposed Rulemaking that would substantially overhaul the Security Rule if finalized. Proposed changes include mandatory multi-factor authentication, required network segmentation, penetration testing of relevant information systems, and compliance audits conducted by regulated entities themselves.20Federal Register. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information

Business associates would have to analyze their own compliance with technical safeguards and verify that to covered entities, and business associates would need the same verification from their subcontractors. As of early 2026 the rule remains a proposal and has not been finalized. Organizations that begin lining up multi-factor authentication, segmentation, and penetration testing now will have less to scramble for if it takes effect.