The Complete Guide to HIPAA Compliance
HIPAA compliance means meeting the U.S. rules that protect health information: the Privacy Rule, the Security Rule, and the Breach Notification Rule — applicable to covered entities (providers, plans, clearinghouses) and their business associates.
- HIPAA has three core rules: Privacy, Security (for electronic PHI), and Breach Notification.
- The Security Rule requires administrative, physical, and technical safeguards.
- Both covered entities and business associates are directly liable.
- A proposed 2025 update would make all safeguards mandatory and add explicit MFA, encryption, and testing requirements.
The three rules
- Privacy Rule — governs the use and disclosure of protected health information (PHI) and patients’ rights over their data.
- Security Rule — requires safeguards for electronic PHI (ePHI) across administrative, physical, and technical domains.
- Breach Notification Rule — requires notifying affected individuals, HHS, and (for large breaches) the media. Breaches affecting 500+ individuals must be reported without unreasonable delay and no later than 60 days.
The Security Rule safeguards
| Safeguard | Examples |
|---|---|
| Administrative | Risk analysis, workforce training, access management, contingency planning |
| Physical | Facility access controls, device and media controls, workstation security |
| Technical | Access control, audit logging, integrity controls, transmission security |
Covered entities vs. business associates
A covered entity is a healthcare provider, health plan, or clearinghouse. A business associate is any vendor that handles PHI on their behalf (e.g., a cloud host or SaaS tool). Both are directly liable, and a signed Business Associate Agreement (BAA) is required before PHI is shared.
Steps to HIPAA compliance
- Run a security risk analysis — the foundational, explicitly required step.
- Implement the safeguards across administrative, physical, and technical domains.
- Sign BAAs with every vendor that touches PHI.
- Train your workforce and enforce least-privilege access.
- Prepare breach response so you can meet notification timelines.
- Monitor and document continuously — HIPAA expects ongoing, demonstrable compliance.
What’s changing: the 2025 Security Rule update
OCR published a Notice of Proposed Rulemaking in January 2025 that, if finalized, would significantly tighten the Security Rule. Proposed changes include: eliminating the “required vs. addressable” distinction so all specifications become mandatory; explicit encryption of ePHI in transit and at rest; multi-factor authentication; annual penetration testing and biannual vulnerability scans; network segmentation; and annual written verification that business associates have deployed required safeguards. Healthcare organizations should plan for a stricter, more prescriptive standard.
Frequently asked questions
Who must comply with HIPAA?
What are the HIPAA safeguards?
How fast must a breach be reported?
Is HIPAA changing in 2025–2026?
See HIPAA compliance on your own data
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research, referencing HHS/OCR guidance and the January 2025 NPRM. Compyl is an AI-powered, agentic GRC platform built by CISOs.