Federal
Security and Privacy
41 provisions · Centers for Medicare & Medicaid Services
Provisions
Citable source units
Statutory basis.
The HIPAA security and privacy provisions are adopted under the Secretary's authority to prescribe standards under the Social Security Act and other public laws.
Group
Definitions Scope Authority
Category
Authority Preemption
Domain
Not Service Specific
Topics
Hipaa statutory basis, Regulatory authority
Definitions.
Defines key terms for HIPAA security and privacy, including common control, hybrid entity, and required by law.
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Not Service Specific
Topics
Hipaa definitions, Covered entity terminology, Hybrid entity definitions
Applicability.
Specifies that HIPAA security and privacy standards apply to health plans, health care clearinghouses, and health care providers who transmit health information electronically.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Not Service Specific
Topics
Hipaa applicability, Covered entity scope, Business associate scope
Organizational requirements.
Sets requirements for hybrid entities and affiliated covered entities, including documentation and safeguard obligations.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hybrid entity requirements, Affiliated covered entities, Hipaa documentation retention
Relationship to other parts.
Covered entities and business associates must comply with applicable provisions of parts 160 and 162 in addition to the requirements of this part.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Not Service Specific
Topics
Hipaa compliance, Regulatory relationship
Applicability.
Covered entities and business associates must comply with the security standards and requirements of this subpart regarding electronic protected health information.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Records
Topics
Hipaa security rule, Electronic protected health information
Definitions.
This section provides the specific definitions for terms used within the HIPAA security subpart.
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Records
Topics
Hipaa definitions, Security terminology
Security standards: General rules.
Covered entities and business associates must ensure the confidentiality, integrity, and availability of electronic protected health information and implement appropriate security measures.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Security standards, Risk management, Security implementation
Administrative safeguards.
Covered entities and business associates must implement administrative policies and procedures to manage the selection, development, implementation, and maintenance of security measures.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Administrative safeguards, Risk analysis, Security training
Physical safeguards.
A covered entity or business associate must, in accordance with § 164.306:
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Physical security safeguards, Facility access control, Workstation security
Technical safeguards.
A covered entity or business associate must, in accordance with § 164.306:
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Technical safeguards, Access control, Audit controls
Organizational requirements.
Covered entities must ensure that business associate contracts and group health plan documents include specific provisions to safeguard electronic protected health information.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Business associate agreements, Organizational security, Contractual requirements
Policies and procedures and documentation requirements.
A covered entity or business associate must, in accordance with § 164.306:
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Security policies and procedures, Documentation retention, Security documentation
Compliance dates for the initial implementation of the security standards.
This section specifies the compliance deadlines for health plans, clearinghouses, and health care providers regarding the security standards.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Not Service Specific
Topics
Compliance deadlines, Implementation dates
Applicability.
The requirements of this subpart apply to breaches of protected health information occurring on or after September 23, 2009.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Records
Topics
Breach notification, Applicability date
Definitions.
As used in this subpart, the following terms have the following meanings:
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Records
Topics
Hipaa breach definition, Protected health information, Breach risk assessment
Notification to individuals.
Requires covered entities to notify individuals following the discovery of a breach of unsecured protected health information.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Breach notification, Protected health information, Individual notification
Notification to the media.
Mandates that covered entities notify prominent media outlets when a breach of unsecured protected health information affects more than 500 residents of a state or jurisdiction.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Media notification, Breach reporting, Large scale breach
Notification to the Secretary.
Requires covered entities to notify the Secretary of HHS regarding breaches of unsecured protected health information.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hhs notification, Breach reporting, Protected health information
Notification by a business associate.
Establishes the requirement for business associates to notify covered entities of breaches of unsecured protected health information.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Business associate, Breach notification, Vendor compliance
Law enforcement delay.
If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under this subpart would impede a criminal investigation or cause damage to national security, a covered enti...
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Law enforcement delay, Breach notification delay, Criminal investigation protection
Administrative requirements and burden of proof.
Outlines the administrative requirements and the burden of proof for covered entities and business associates regarding breach notifications.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Burden of proof, Administrative requirements, Breach documentation
Applicability.
Defines the scope and applicability of the HIPAA privacy standards to covered entities, business associates, and health care clearinghouses.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Records
Topics
Hipaa applicability, Covered entities, Business associates
Definitions.
As used in this subpart, the following terms have the following meanings:
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa privacy definitions, Protected health information terms, Health care operations
Uses and disclosures of protected health information: General rules.
This provision establishes the general standards for the use and disclosure of protected health information by covered entities and business associates, including requirements for minimum necessary access, de-identification, and specific prohibitions regarding genetic information, sales of information, and reproductive health care.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Protected health information, Phi disclosure rules, Hipaa privacy rule
Uses and disclosures: Organizational requirements.
This regulation establishes organizational requirements for covered entities under HIPAA, including standards for business associate contracts, group health plan privacy, and the management of multiple covered functions.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Business associate agreements, Hipaa organizational requirements, Group health plan privacy
Uses and disclosures to carry out treatment, payment, or health care operations.
This provision outlines the standards and implementation specifications for covered entities to use or disclose protected health information for treatment, payment, and health care operations under the HIPAA Privacy Rule.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Phi disclosure, Treatment payment operations, Hipaa privacy rule
Uses and disclosures for which an authorization is required.
This provision establishes the requirements for valid patient authorizations for the use and disclosure of protected health information, including core elements, revocation procedures, and limitations on conditioning treatment or payment.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa authorization requirements, Phi disclosure, Patient authorization
Uses and disclosures for which an attestation is required.
This regulation mandates that covered entities obtain a valid attestation before disclosing protected health information related to reproductive health care for specific legal or administrative purposes.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Reproductive health information, Hipaa attestation requirements, Protected health information disclosure
Uses and disclosures requiring an opportunity for the individual to agree or to object.
A covered entity may use or disclose protected health information, provided that the individual is informed in advance of the use or disclosure and has the opportunity to agree to or prohibit or restrict the use or disclosure, in accorda...
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Facility directory disclosures, Patient care involvement, Notification of family
Uses and disclosures for which an authorization or opportunity to agree or object is not required.
Except as provided by § 164.502(a)(5)(iii), a covered entity may use or disclose protected health information without the written authorization of the individual, as described in § 164.508, or the opportunity for the individual to agree...
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Phi disclosure without authorization, Hipaa privacy rule exceptions, Public health reporting
Other requirements relating to uses and disclosures of protected health information.
This provision establishes standards for de-identification of protected health information, minimum necessary requirements for uses and disclosures, limited data set usage, fundraising communications, and verification of identity and authority for disclosures.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
De Identification of phi, Minimum necessary standard, Limited data set
Notice of privacy practices for protected health information.
This provision mandates that covered entities provide individuals with a clear, written notice of their privacy practices, legal duties, and the individual's rights regarding protected health information.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Notice of privacy practices, Hipaa privacy rule, Patient notification
Rights to request privacy protection for protected health information.
This regulation establishes the rights of individuals to request restrictions on the use and disclosure of their protected health information and to request confidential communications from covered entities.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Privacy restriction requests, Confidential communications, Phi disclosure limitations
Access of individuals to protected health information.
This regulation establishes the right of individuals to inspect and obtain copies of their protected health information in a designated record set, including procedures for requests, denials, and review of denials.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Patient access to records, Medical record requests, Hipaa privacy rule
Amendment of protected health information.
This provision establishes the right of an individual to request amendments to their protected health information maintained in a designated record set and outlines the covered entity's obligations for processing, documenting, and responding to such requests.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Phi amendment rights, Medical record correction, Hipaa privacy rule
Accounting of disclosures of protected health information.
This provision defines the individual's right to receive an accounting of disclosures of their protected health information made by a covered entity and specifies the required content, timelines, and documentation for such accountings.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Accounting of disclosures, Phi disclosure tracking, Hipaa privacy rule
Administrative requirements.
This provision establishes the mandatory administrative framework for covered entities, including personnel designations, workforce training, privacy safeguards, complaint processes, sanctions, and documentation retention requirements.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa privacy administrative requirements, Privacy official designation, Workforce privacy training
Transition provisions.
This provision outlines the transition rules for the use and disclosure of protected health information under prior authorizations, research permissions, and business associate contracts.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa transition rules, Prior authorization, Business associate agreements
Compliance dates for initial implementation of the privacy standards.
This provision establishes the historical compliance deadlines for health care providers, health plans, and clearinghouses regarding the HIPAA privacy standards.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Hipaa compliance dates, Privacy rule implementation
Severability.
This provision specifies that if any part of the HIPAA Privacy Rule is held invalid, the remaining provisions shall remain in effect.
Group
Definitions Scope Authority
Category
Authority Preemption
Domain
Not Service Specific
Topics
Severability clause, Hipaa privacy rule
