Shieldra
HIPAA Framework Guide
HIPAA — the Health Insurance Portability and Accountability Act of 1996 — is the U.S. law setting national standards for protecting health information. Covered entities and business associates need documented safeguards, policies, training, vendor agreements, risk analysis, and breach response evidence.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- HIPAA stands for the Health Insurance Portability and Accountability Act, passed in 1996 and substantially updated since.
- It applies to covered entities — providers, health plans, and clearinghouses — and to business associates handling PHI on their behalf.
- The framework is four rules: Privacy, Security, Breach Notification, and Enforcement, plus HITECH and Omnibus updates.
- The Security Rule organizes requirements into administrative, physical, and technical safeguards.
- There is no HIPAA certificate. Compliance is a demonstrated state, evidenced by documentation, not a badge you are issued.
What HIPAA stands for and what it does
HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Despite the name, the part almost everyone means today is the privacy and security regime built on top of it: national standards for how protected health information (PHI) may be used, disclosed, and safeguarded.
PHI is individually identifiable health information held or transmitted in any form. That is broader than most people assume — it includes not just diagnoses and treatment records but names, dates, contact details, and identifiers when they are tied to health care, payment, or the operation of a health plan.
HIPAA is enforced by the HHS Office for Civil Rights (OCR). There is no HIPAA certification body and no certificate to display; compliance is a state you must be able to evidence on request.
Core HIPAA rules
- Privacy Rule — how PHI may be used and disclosed, and patients’ rights over it
- Security Rule — administrative, physical, and technical safeguards for electronic PHI
- Breach Notification Rule — reporting breaches of unsecured PHI to individuals, HHS, and sometimes the media
- Enforcement Rule — investigations, penalties, and procedures
- HITECH and Omnibus updates — direct liability for business associates and increased penalties
Security Rule safeguard groups
- Administrative safeguards — risk analysis, workforce training, access management, incident procedures, contingency planning
- Physical safeguards — facility access, workstation use and security, device and media controls
- Technical safeguards — access control, audit controls, integrity, authentication, transmission security
- Organizational requirements — Business Associate Agreements and plan documents
- Policies, procedures, and documentation — written, maintained, and retained for six years
Who has to comply
Covered entities
Health care providers who transmit health information electronically in connection with covered transactions, health plans, and health care clearinghouses. This includes dental and medical practices, clinics, hospitals, and insurers.
Business associates
Any person or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity — billing companies, IT and managed service providers, cloud vendors, analytics and AI products, transcription services, and shredding companies. Since HITECH, business associates are directly liable under HIPAA rather than only contractually liable.
Subcontractors
A business associate’s own vendors that touch PHI are themselves business associates, and the chain of BAAs has to extend down to them.
What the 2026 Security Rule update changes
HHS has proposed major updates to the Security Rule taking effect in 2026, and the theme is the removal of discretion. Controls that were formerly "addressable" — which many organizations read as optional — become expected baseline.
- Multi-factor authentication becomes mandatory rather than addressable
- Encryption of all ePHI at rest and in transit
- 72-hour incident reporting timelines
- Annual penetration testing
- A 2026 civil monetary penalty maximum of $2,190,294 for penalties assessed on or after January 28, 2026
Audit evidence
- Risk analysis — thorough, accurate, and current
- Policies and procedures, with version history
- Workforce training records
- Access reviews and audit logs, with evidence of triage
- Business Associate Agreements, current and unexpired
- Incident and breach documentation from detection through closure
How to approach HIPAA compliance
Start with the Security Risk Analysis. It is the requirement OCR asks about first, it is cited in over 60% of settlements above $1 million, and it tells you which of the other requirements carry real risk in your specific environment. Everything else is prioritization downstream of it.
Then close the two controls with the largest consequences: encryption, which is the only safe harbor under the Breach Notification Rule, and MFA, whose absence is now treated as willful neglect. After that, the work is documentation discipline — BAAs, access reviews, training, incident records — maintained continuously rather than reconstructed annually.
Frequently asked questions
What is HIPAA?
HIPAA (the Health Insurance Portability and Accountability Act of 1996) is a U.S. federal law that sets national standards for protecting the privacy and security of protected health information (PHI). It applies to covered entities — healthcare providers, health plans, and clearinghouses — and to their business associates.
What are the main HIPAA rules?
The core rules are the Privacy Rule (how PHI may be used and disclosed), the Security Rule (administrative, physical, and technical safeguards for electronic PHI), the Breach Notification Rule (reporting breaches of unsecured PHI), and the Enforcement Rule, with updates from HITECH and the Omnibus and 2026 Security Rule changes.
Who must comply with HIPAA?
Covered entities (healthcare providers, health plans, and healthcare clearinghouses) and business associates that handle PHI on their behalf must comply with HIPAA.
What does HIPAA stand for?
HIPAA stands for the Health Insurance Portability and Accountability Act, a U.S. federal law passed in 1996. Its privacy and security rules set national standards for protecting protected health information.
Is there such a thing as HIPAA certification?
No. There is no official HIPAA certification or certificate. HIPAA is enforced by the HHS Office for Civil Rights, and compliance is a state you must be able to evidence through documentation — risk analyses, policies, training records, BAAs, and audit logs — rather than a credential a body issues you.
What counts as protected health information?
PHI is individually identifiable health information held or transmitted in any form or medium. It covers diagnoses and treatment records, and also names, dates, contact details, and other identifiers when they are linked to health care, payment for care, or health plan operations.
Are business associates directly liable under HIPAA?
Yes. Since the HITECH Act and the Omnibus Rule, business associates are directly liable for compliance with the Security Rule and parts of the Privacy Rule, not merely contractually liable to the covered entity. Their subcontractors that handle PHI are business associates too.