Compyl

The Complete Guide to HIPAA Compliance

June 04, 2026
Framework · HIPAA

The Complete Guide to HIPAA Compliance

By Compyl ResearchUpdated June 20264 min read

HIPAA compliance means meeting the U.S. rules that protect health information: the Privacy Rule, the Security Rule, and the Breach Notification Rule — applicable to covered entities (providers, plans, clearinghouses) and their business associates.

Key takeaways
  • HIPAA has three core rules: Privacy, Security (for electronic PHI), and Breach Notification.
  • The Security Rule requires administrative, physical, and technical safeguards.
  • Both covered entities and business associates are directly liable.
  • A proposed 2025 update would make all safeguards mandatory and add explicit MFA, encryption, and testing requirements.

The three rules

  • Privacy Rule — governs the use and disclosure of protected health information (PHI) and patients’ rights over their data.
  • Security Rule — requires safeguards for electronic PHI (ePHI) across administrative, physical, and technical domains.
  • Breach Notification Rule — requires notifying affected individuals, HHS, and (for large breaches) the media. Breaches affecting 500+ individuals must be reported without unreasonable delay and no later than 60 days.

The Security Rule safeguards

Safeguard Examples
Administrative Risk analysis, workforce training, access management, contingency planning
Physical Facility access controls, device and media controls, workstation security
Technical Access control, audit logging, integrity controls, transmission security

Covered entities vs. business associates

A covered entity is a healthcare provider, health plan, or clearinghouse. A business associate is any vendor that handles PHI on their behalf (e.g., a cloud host or SaaS tool). Both are directly liable, and a signed Business Associate Agreement (BAA) is required before PHI is shared.

Steps to HIPAA compliance

  1. Run a security risk analysis — the foundational, explicitly required step.
  2. Implement the safeguards across administrative, physical, and technical domains.
  3. Sign BAAs with every vendor that touches PHI.
  4. Train your workforce and enforce least-privilege access.
  5. Prepare breach response so you can meet notification timelines.
  6. Monitor and document continuously — HIPAA expects ongoing, demonstrable compliance.

What’s changing: the 2025 Security Rule update

OCR published a Notice of Proposed Rulemaking in January 2025 that, if finalized, would significantly tighten the Security Rule. Proposed changes include: eliminating the “required vs. addressable” distinction so all specifications become mandatory; explicit encryption of ePHI in transit and at rest; multi-factor authentication; annual penetration testing and biannual vulnerability scans; network segmentation; and annual written verification that business associates have deployed required safeguards. Healthcare organizations should plan for a stricter, more prescriptive standard.

Frequently asked questions

Who must comply with HIPAA?
Covered entities (healthcare providers, health plans, clearinghouses) and their business associates — any vendor that creates, receives, maintains, or transmits PHI on their behalf.
What are the HIPAA safeguards?
The Security Rule requires administrative, physical, and technical safeguards for electronic PHI — from risk analysis and training to access control, encryption, and audit logging.
How fast must a breach be reported?
For breaches affecting 500 or more individuals, without unreasonable delay and no later than 60 days after discovery, to individuals and HHS (and the media for large breaches).
Is HIPAA changing in 2025–2026?
A proposed Security Rule update would make all safeguards mandatory and add explicit MFA, encryption, penetration testing, and vendor-verification requirements. It was not yet final as of mid-2026.

See HIPAA compliance on your own data

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research, referencing HHS/OCR guidance and the January 2025 NPRM. Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies