Policy Prism AI

Security and Privacy

Federal

Security and Privacy

41 provisions · Centers for Medicare & Medicaid Services

Provisions

Citable source units

45 CFR § 164.102Authority PreemptionHIPAA Privacy Security

Statutory basis.

The HIPAA security and privacy provisions are adopted under the Secretary's authority to prescribe standards under the Social Security Act and other public laws.

Group

Definitions Scope Authority

Category

Authority Preemption

Domain

Not Service Specific

Topics

Hipaa statutory basis, Regulatory authority

Read provision
45 CFR § 164.103Definitions ContextHIPAA Privacy Security

Definitions.

Defines key terms for HIPAA security and privacy, including common control, hybrid entity, and required by law.

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Not Service Specific

Topics

Hipaa definitions, Covered entity terminology, Hybrid entity definitions

Read provision
45 CFR § 164.104Scope ApplicabilityHIPAA Privacy Security

Applicability.

Specifies that HIPAA security and privacy standards apply to health plans, health care clearinghouses, and health care providers who transmit health information electronically.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Not Service Specific

Topics

Hipaa applicability, Covered entity scope, Business associate scope

Read provision
45 CFR § 164.105HIPAA Privacy SecurityDefinitions Context

Organizational requirements.

Sets requirements for hybrid entities and affiliated covered entities, including documentation and safeguard obligations.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hybrid entity requirements, Affiliated covered entities, Hipaa documentation retention

Read provision
45 CFR § 164.106Scope ApplicabilityHIPAA Privacy Security

Relationship to other parts.

Covered entities and business associates must comply with applicable provisions of parts 160 and 162 in addition to the requirements of this part.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Not Service Specific

Topics

Hipaa compliance, Regulatory relationship

Read provision
45 CFR § 164.302Scope ApplicabilityHIPAA Privacy Security

Applicability.

Covered entities and business associates must comply with the security standards and requirements of this subpart regarding electronic protected health information.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Records

Topics

Hipaa security rule, Electronic protected health information

Read provision
45 CFR § 164.304Definitions ContextHIPAA Privacy Security

Definitions.

This section provides the specific definitions for terms used within the HIPAA security subpart.

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Records

Topics

Hipaa definitions, Security terminology

Read provision
45 CFR § 164.306HIPAA Privacy SecurityCompliance Programs

Security standards: General rules.

Covered entities and business associates must ensure the confidentiality, integrity, and availability of electronic protected health information and implement appropriate security measures.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Security standards, Risk management, Security implementation

Read provision
45 CFR § 164.308HIPAA Privacy SecurityCompliance Programs

Administrative safeguards.

Covered entities and business associates must implement administrative policies and procedures to manage the selection, development, implementation, and maintenance of security measures.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Administrative safeguards, Risk analysis, Security training

Read provision
45 CFR § 164.310HIPAA Privacy SecurityPhysical Environment

Physical safeguards.

A covered entity or business associate must, in accordance with § 164.306:

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Physical security safeguards, Facility access control, Workstation security

Read provision
45 CFR § 164.312HIPAA Privacy SecurityMedical Records

Technical safeguards.

A covered entity or business associate must, in accordance with § 164.306:

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Technical safeguards, Access control, Audit controls

Read provision
45 CFR § 164.314HIPAA Privacy SecurityCompliance Programs

Organizational requirements.

Covered entities must ensure that business associate contracts and group health plan documents include specific provisions to safeguard electronic protected health information.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Business associate agreements, Organizational security, Contractual requirements

Read provision
45 CFR § 164.316HIPAA Privacy SecurityDocumentation Retention

Policies and procedures and documentation requirements.

A covered entity or business associate must, in accordance with § 164.306:

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Security policies and procedures, Documentation retention, Security documentation

Read provision
45 CFR § 164.318Scope ApplicabilityHIPAA Privacy Security

Compliance dates for the initial implementation of the security standards.

This section specifies the compliance deadlines for health plans, clearinghouses, and health care providers regarding the security standards.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Not Service Specific

Topics

Compliance deadlines, Implementation dates

Read provision
45 CFR § 164.400Scope ApplicabilityHIPAA Privacy Security

Applicability.

The requirements of this subpart apply to breaches of protected health information occurring on or after September 23, 2009.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Records

Topics

Breach notification, Applicability date

Read provision
45 CFR § 164.402Definitions ContextHIPAA Privacy Security

Definitions.

As used in this subpart, the following terms have the following meanings:

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Records

Topics

Hipaa breach definition, Protected health information, Breach risk assessment

Read provision
45 CFR § 164.404HIPAA Privacy SecurityConfidentiality Disclosure

Notification to individuals.

Requires covered entities to notify individuals following the discovery of a breach of unsecured protected health information.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Breach notification, Protected health information, Individual notification

Read provision
45 CFR § 164.406HIPAA Privacy SecurityConfidentiality Disclosure

Notification to the media.

Mandates that covered entities notify prominent media outlets when a breach of unsecured protected health information affects more than 500 residents of a state or jurisdiction.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Media notification, Breach reporting, Large scale breach

Read provision
45 CFR § 164.408HIPAA Privacy SecurityConfidentiality Disclosure

Notification to the Secretary.

Requires covered entities to notify the Secretary of HHS regarding breaches of unsecured protected health information.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hhs notification, Breach reporting, Protected health information

Read provision
45 CFR § 164.410HIPAA Privacy SecurityConfidentiality Disclosure

Notification by a business associate.

Establishes the requirement for business associates to notify covered entities of breaches of unsecured protected health information.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Business associate, Breach notification, Vendor compliance

Read provision
45 CFR § 164.412HIPAA Privacy SecurityConfidentiality Disclosure

Law enforcement delay.

If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under this subpart would impede a criminal investigation or cause damage to national security, a covered enti...

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Law enforcement delay, Breach notification delay, Criminal investigation protection

Read provision
45 CFR § 164.414HIPAA Privacy SecurityCompliance Programs

Administrative requirements and burden of proof.

Outlines the administrative requirements and the burden of proof for covered entities and business associates regarding breach notifications.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Burden of proof, Administrative requirements, Breach documentation

Read provision
45 CFR § 164.500Scope ApplicabilityHIPAA Privacy Security

Applicability.

Defines the scope and applicability of the HIPAA privacy standards to covered entities, business associates, and health care clearinghouses.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Records

Topics

Hipaa applicability, Covered entities, Business associates

Read provision
45 CFR § 164.501HIPAA Privacy SecurityDefinitions Context

Definitions.

As used in this subpart, the following terms have the following meanings:

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa privacy definitions, Protected health information terms, Health care operations

Read provision
45 CFR § 164.502HIPAA Privacy SecurityMedical Records

Uses and disclosures of protected health information: General rules.

This provision establishes the general standards for the use and disclosure of protected health information by covered entities and business associates, including requirements for minimum necessary access, de-identification, and specific prohibitions regarding genetic information, sales of information, and reproductive health care.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Protected health information, Phi disclosure rules, Hipaa privacy rule

Read provision
45 CFR § 164.504HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures: Organizational requirements.

This regulation establishes organizational requirements for covered entities under HIPAA, including standards for business associate contracts, group health plan privacy, and the management of multiple covered functions.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Business associate agreements, Hipaa organizational requirements, Group health plan privacy

Read provision
45 CFR § 164.506HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures to carry out treatment, payment, or health care operations.

This provision outlines the standards and implementation specifications for covered entities to use or disclose protected health information for treatment, payment, and health care operations under the HIPAA Privacy Rule.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Phi disclosure, Treatment payment operations, Hipaa privacy rule

Read provision
45 CFR § 164.508HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures for which an authorization is required.

This provision establishes the requirements for valid patient authorizations for the use and disclosure of protected health information, including core elements, revocation procedures, and limitations on conditioning treatment or payment.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa authorization requirements, Phi disclosure, Patient authorization

Read provision
45 CFR § 164.509HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures for which an attestation is required.

This regulation mandates that covered entities obtain a valid attestation before disclosing protected health information related to reproductive health care for specific legal or administrative purposes.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Reproductive health information, Hipaa attestation requirements, Protected health information disclosure

Read provision
45 CFR § 164.510HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures requiring an opportunity for the individual to agree or to object.

A covered entity may use or disclose protected health information, provided that the individual is informed in advance of the use or disclosure and has the opportunity to agree to or prohibit or restrict the use or disclosure, in accorda...

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Facility directory disclosures, Patient care involvement, Notification of family

Read provision
45 CFR § 164.512HIPAA Privacy SecurityConfidentiality Disclosure

Uses and disclosures for which an authorization or opportunity to agree or object is not required.

Except as provided by § 164.502(a)(5)(iii), a covered entity may use or disclose protected health information without the written authorization of the individual, as described in § 164.508, or the opportunity for the individual to agree...

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Phi disclosure without authorization, Hipaa privacy rule exceptions, Public health reporting

Read provision
45 CFR § 164.514HIPAA Privacy SecurityConfidentiality Disclosure

Other requirements relating to uses and disclosures of protected health information.

This provision establishes standards for de-identification of protected health information, minimum necessary requirements for uses and disclosures, limited data set usage, fundraising communications, and verification of identity and authority for disclosures.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

De Identification of phi, Minimum necessary standard, Limited data set

Read provision
45 CFR § 164.520HIPAA Privacy SecurityConfidentiality Disclosure

Notice of privacy practices for protected health information.

This provision mandates that covered entities provide individuals with a clear, written notice of their privacy practices, legal duties, and the individual's rights regarding protected health information.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Notice of privacy practices, Hipaa privacy rule, Patient notification

Read provision
45 CFR § 164.522HIPAA Privacy SecurityConfidentiality Disclosure

Rights to request privacy protection for protected health information.

This regulation establishes the rights of individuals to request restrictions on the use and disclosure of their protected health information and to request confidential communications from covered entities.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Privacy restriction requests, Confidential communications, Phi disclosure limitations

Read provision
45 CFR § 164.524HIPAA Privacy SecurityHealth Information Access

Access of individuals to protected health information.

This regulation establishes the right of individuals to inspect and obtain copies of their protected health information in a designated record set, including procedures for requests, denials, and review of denials.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Patient access to records, Medical record requests, Hipaa privacy rule

Read provision
45 CFR § 164.526HIPAA Privacy SecurityMedical Records

Amendment of protected health information.

This provision establishes the right of an individual to request amendments to their protected health information maintained in a designated record set and outlines the covered entity's obligations for processing, documenting, and responding to such requests.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Phi amendment rights, Medical record correction, Hipaa privacy rule

Read provision
45 CFR § 164.528HIPAA Privacy SecurityMedical Records

Accounting of disclosures of protected health information.

This provision defines the individual's right to receive an accounting of disclosures of their protected health information made by a covered entity and specifies the required content, timelines, and documentation for such accountings.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Accounting of disclosures, Phi disclosure tracking, Hipaa privacy rule

Read provision
45 CFR § 164.530HIPAA Privacy SecurityMedical Records

Administrative requirements.

This provision establishes the mandatory administrative framework for covered entities, including personnel designations, workforce training, privacy safeguards, complaint processes, sanctions, and documentation retention requirements.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa privacy administrative requirements, Privacy official designation, Workforce privacy training

Read provision
45 CFR § 164.532HIPAA Privacy SecurityResearch Privacy Confidentiality

Transition provisions.

This provision outlines the transition rules for the use and disclosure of protected health information under prior authorizations, research permissions, and business associate contracts.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa transition rules, Prior authorization, Business associate agreements

Read provision
45 CFR § 164.534HIPAA Privacy Security

Compliance dates for initial implementation of the privacy standards.

This provision establishes the historical compliance deadlines for health care providers, health plans, and clearinghouses regarding the HIPAA privacy standards.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Hipaa compliance dates, Privacy rule implementation

Read provision
45 CFR § 164.535Authority PreemptionHIPAA Privacy Security

Severability.

This provision specifies that if any part of the HIPAA Privacy Rule is held invalid, the remaining provisions shall remain in effect.

Group

Definitions Scope Authority

Category

Authority Preemption

Domain

Not Service Specific

Topics

Severability clause, Hipaa privacy rule

Read provision