HIPAA Pillar Guide · Updated August 2026

HIPAA Practical Guide for 2026
Privacy Rule · Security Rule · Breach Notification · OCR Enforcement

A consolidated walkthrough of 45 CFR §164.500–534 (Privacy Rule), §164.308–312 (Security Rule), §164.400 (Breach Notification), and §160.404 (OCR penalty tiers) — paired with a 90-day ComplianceStack remediation roadmap for 2026.

Maintained by ComplianceStack · 2026-08-03 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 Privacy Rule §164.500–534 — Covered Entities, Uses, Disclosures & Individual Rights
  2. §2 Security Rule §164.308–312 — Administrative, Physical & Technical Safeguards
  3. §3 Breach Notification §164.400–414 — 60-Day Clock & Business Associates
  4. §4 OCR 2026 Enforcement Priorities & §160.404 Penalty Tiers
  5. §5 2026 HIPAA Compliance Roadmap — 90 Days from Free Assessment to Audit-Ready Posture
  6. §6 Frequently Asked Questions

§1 Privacy Rule §164.500–534 — Covered Entities, Uses, Disclosures & Individual Rights

The HIPAA Privacy Rule controls every use and disclosure of Protected Health Information (PHI) by covered entities and (post-Omnibus) by their business associates. ComplianceStack maps §164.500–534 as the operational core — the rules that govern what you may do with PHI, when you need authorization, and what individual rights travel alongside each record.

§164.500 — Purpose & Applicability. The Privacy Rule applies to covered entities (healthcare providers conducting standard transactions, health plans, and healthcare clearinghouses) and, with hybrid-entity carve-outs in §164.105, to designated components of larger hybrid entities. ComplianceStack treats any organization that bills Medicare, transmits claims electronically, or has signed a Business Associate Agreement as in scope — there is no revenue or patient-volume floor below which HIPAA stops applying.

§164.502 — Uses & Disclosures. §164.502(a) sets the general rule that PHI may not be used or disclosed except as permitted; §164.502(b) Minimum Necessary is one of the most-cited provisions in OCR enforcement — when using or disclosing PHI, the covered entity must make reasonable efforts to limit the disclosure to the minimum necessary to accomplish the intended purpose. The minimum-necessary standard is NOT waived for treatment, but it IS waived for disclosures to the individual.

§164.504 — Organizational Requirements & the BAA. §164.504(e) and §164.314(a)(2)(i) require a written Business Associate Agreement before any PHI is shared with a contractor that creates, receives, maintains, or transmits PHI on the covered entity's behalf. ComplianceStack flags unmarked BAA templates that are missing the required downstream §164.410 breach notification flow — a recurring source of joint liability.

§164.508 — Authorization for Uses & Disclosures. Required when the use or disclosure is not for treatment, payment, or healthcare operations (TPO) and not otherwise permitted — for example marketing, sale of PHI, or use of psychotherapy notes under §164.508(a)(2).

§164.510 — Notice of Privacy Practices. Every covered health care provider with direct treatment relationships must provide a Notice of Privacy Practices (NPP) at first delivery, post it at the intake desk, and make it available on the public website — state law may layer additional requirements (most notably in California, Texas, and New York).

§164.514 — De-identification. §164.514(b)(2)(i) lists the 18 PHI identifiers that must be removed for PHI to be considered de-identified: names; geographic subdivisions smaller than a state; all date elements other than year (admission, discharge, DOB, DOD); telephone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate/license numbers; vehicle identifiers; device identifiers; URLs; IP addresses; biometric identifiers and full-face photographs; and any other unique identifying number, characteristic, or code. ComplianceStack treats each identifier as a checklist row in the Privacy Rule policy binder — OCR investigations routinely open with a request for each row.

§164.522 — Request for Restrictions & Confidential Communications. The individual may request a restriction on use or disclosure, which the covered entity MUST grant when the individual has paid out-of-pocket in full for the service. Confidential communications channels (alternate address or phone) must be accommodated on request.

§164.524 — Access of Individuals to PHI. Individuals have a right to access their own PHI within 30 days, with one 30-day extension under §164.524(b)(2) when the records are offsite or the request is complex. Information-blocking penalties under 21st Century Cures Act §4001 may overlap.

§164.526 — Amendment. Individuals have a right to have PHI amended, subject to the covered entity's documented denial grounds in §164.526(a)(2); denials must be communicated in writing within 60 days.

§164.528 — Accounting of Disclosures. Individuals have a right to a written accounting of certain disclosures for the six years prior to the request, excepting TPO and certain other categories under §164.528(a)(1).

§164.530 — Administrative Requirements. Designate a Privacy Official (§164.530(a)(1)), train workforce (§164.530(b)), implement safeguards (§164.530(c)), handle complaints (§164.530(d)), retain all documentation for six years under §164.530(j)(2), and operate a biennial mitigation strategy when compliance is not feasible.

§2 Security Rule §164.308–312 — Administrative, Physical & Technical Safeguards

The Security Rule applies specifically to electronic Protected Health Information (ePHI). Where the Privacy Rule controls "what you may do with PHI," the Security Rule controls "how you must protect it." ComplianceStack maps §164.308–312 into three families of safeguards, each paired with the §164.308(a)(1)(ii)(A) risk analysis that OCR opens every Corrective Action Plan with.

§164.308 — Administrative Safeguards

§164.308(a)(1)(ii)(A) Risk Analysis. OCR's most-cited safeguard: you must conduct an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. ComplianceStack maps the risk analysis to four columns — ePHI asset, threat, likelihood × impact, and current safeguard — the format OCR investigators request by name.

§164.308(a)(1)(ii)(B) Risk Management. The risk analysis is the diagnosis; the risk management plan is the treatment. §164.308(a)(1)(ii)(B) requires implementation of security measures sufficient to reduce risks to a reasonable and appropriate level.

§164.308(a)(2) Assigned Security Responsibility. A single person (or role) owns the Security Rule policies and procedures. ComplianceStack recommends a one-page charter signed by the named individual and the CEO.

§164.308(a)(3) Workforce Security. Authorization/supervision (§164.308(a)(3)(i)), clearance procedures (§164.308(a)(3)(ii)(A)), and termination procedures (§164.308(a)(3)(ii)(C)) — the operational cornerstone is a documented offboarding checklist that disables accounts within 24 hours of separation.

§164.308(a)(5) Security Awareness and Training. §164.308(a)(5)(ii)(A) security reminders, (B) protection from malicious software, (C) log-in monitoring, (D) password management. ComplianceStack recommends annual HIPAA training, quarterly phishing simulations, and a documented reminder cadence.

§164.308(a)(6) Incident Procedures. Documented response policies and procedures — pair directly with the §164.400–414 breach notification workflow so the breach analysis begins within 24 hours of any incident.

§164.308(a)(7) Contingency Plan. Data backup, disaster recovery, emergency mode operation, testing and revision procedures, and applications-and-data criticality analysis. OCR failure on this safeguard is a recurring source of multi-million-dollar CAPs.

§164.308(a)(8) Evaluation. Periodic technical and non-technical evaluation of your Security Rule posture — ComplianceStack runs annual §164.308(a)(8) evaluations as a routine deliverable.

§164.310 — Physical Safeguards

§164.312 — Technical Safeguards (& the §164.402(2) Encryption Safe-Harbor)

The encryption carve-out under §164.402(2) is the single highest-leverage control in the Security Rule: if ePHI is encrypted to NIST SP 800-111 effective controls and rendered unreadable and indecipherable to unauthorized individuals, OCR presumes NO breach — eliminating §164.404 individual notice, §164.406 media notice, and §164.408 HHS portal notification obligations entirely. ComplianceStack tracks which of your ePHI assets are encrypted to this safe-harbor baseline.

§3 Breach Notification §164.400–414 — 60-Day Clock & Business Associates

The Breach Notification Rule applies to covered entities AND (post-Omnibus Rule) to business associates. It is the most time-sensitive obligation in HIPAA: the 60-day clock starts at discovery and runs during litigation, CAPs, and parallel state-law notifications.

§164.402 — Breach Definition & the Four-Factor Risk Assessment

A "breach" is the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises PHI's confidentiality, integrity, or availability — UNLESS the covered entity demonstrates, through a §164.402(2) risk assessment, that there is a low probability the PHI has been compromised. The four factors: (1) the nature and extent of the PHI involved, (2) the unauthorized person who used or received the PHI, (3) whether the PHI was actually acquired or viewed, and (4) the extent risk has been mitigated. Encryption to NIST SP 800-111 controls several of these factors and triggers the presumption of non-breach.

§164.404 — Individual Notice (60-Day Clock)

Notice to affected individuals must be provided "without unreasonable delay and in no case later than 60 calendar days" after discovery. First-class mail to last-known address is the default; email is permitted when the individual has agreed; telephonic notice is permitted for urgent situations. Substitute notice (web posting + prominent media) applies when contact information is insufficient or outdated for 10 or more individuals. The 60-day clock starts at the date the covered entity knew or should reasonably have known of the breach.

§164.406 — Media Notice (>500 Residents)

If a breach involves more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the affected state or jurisdiction. The same 60-day clock applies; in practice media notice goes out concurrently with individual notice for high-impact events.

§164.408 — HHS Notice (Breach Portal)

If a breach involves more than 500 individuals, the covered entity must notify the HHS Secretary via the OCR Breach Portal — and the breach appears on the public "Wall of Shame" at ocr.hhs.gov. For breaches involving fewer than 500 individuals, the covered entity must log the breach and submit an annual summary to HHS no later than 60 days after the end of the calendar year.

§164.410 — Business Associate Notification Obligation

A business associate must notify the covered entity "without unreasonable delay" after discovery of a breach affecting unsecured PHI. The §164.410 clock is upstream of the §164.404 60-day clock and starts the timeline — covered entities fail §164.308 administrative safeguards when their BAAs are missing the §164.410 upstream-notification language.

§4 OCR 2026 Enforcement Priorities & §160.404 Penalty Tiers

OCR's enforcement posture in 2026 reflects the December 2026 NPRM that proposes to retire the addressable / required implementation specification split (elevating every Security Rule safeguard to a Standards-level duty) plus the 2025 ransomware-as-breach guidance. The most-investigated safeguards in current enforcement: §164.308(a)(1)(ii)(A) risk analysis, §164.308(a)(5)(ii)(D) password management, §164.310(d) device and media controls, §164.312(a)(2)(iv) encryption, and §164.402(2) breach-presumption analysis.

Under 45 CFR §160.404, OCR penalty tiers are inflation-adjusted annually under the Federal Civil Penalties Inflation Adjustment Act. The 2026 amounts:

§160.404(b)(1) Tier 1
Lack of Knowledge
$145
§160.404(b)(2) Tier 2
Reasonable Cause
$1,478
§160.404(b)(3) Tier 3
Willful Neglect (Corrected)
$18,892
§160.404(b)(4) Tier 4
Willful Neglect (Not Corrected)
$71,162

The annual cap under §160.404(b)(1) through (4) for identical violations is $2,190,294 per year per violation category. Multiple violation categories can each reach that cap independently — which is how the public Anthem ($16M), Excellus ($2.3M), and Premera ($6.85M) settlements accumulated.

Under §160.404(c), criminal penalties under 42 USC §1320d-5 are separate and not adjusted for inflation: up to $50,000 and one year imprisonment for knowing violations; up to $100,000 and five years for violations committed under false pretenses; up to $250,000 and ten years for violations with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm. The DOJ, not OCR, prosecutes criminal HIPAA violations.

§5 2026 HIPAA Compliance Roadmap — 90 Days from Free Assessment to Audit-Ready Posture

ComplianceStack's 90-day roadmap ties every HIPAA deliverable to (a) the regulatory citation, (b) the OCR enforcement outcome it defends against, and (c) the ComplianceStack tool that produces the documented output. Run the free HIPAA risk assessment on day 0 and the deep gap analysis on day 30.

Pair this roadmap with the ComplianceStack HIPAA framework overview at /frameworks/hipaa, the free assessment at /free-hipaa-risk-assessment, the deep calculator at /hipaa-risk-calculator, and ComplianceStack audit-ready reports at /pricing.

Free HIPAA Risk Assessment

Run the free 10-question ComplianceStack HIPAA assessment at /free-hipaa-risk-assessment. No email or signup required. Instant risk score (Low / Moderate / High / Critical), OCR penalty exposure tier under the 2026 §160.404 inflation-adjusted amounts, and the top three remediation actions ranked by likelihood × impact.

Run the Free HIPAA Assessment →

HIPAA Security Rule Risk Calculator

The deep ComplianceStack HIPAA risk calculator at /hipaa-risk-calculator covers every Security Rule administrative (§164.308), physical (§164.310), and technical (§164.312) safeguard with weightings derived from OCR enforcement outcomes. Output is a documented risk analysis defensible under §164.308(a)(1)(ii)(A) plus a prioritized §164.308(a)(1)(ii)(B) risk management plan.

Open the HIPAA Risk Calculator →

HIPAA Framework Overview

ComplianceStack's HIPAA framework landing page at /frameworks/hipaa gives the regulatory framing, current HHS/OCR enforcement posture, and cross-links to every HIPAA-specific ComplianceStack tool.

Open the HIPAA Framework Page →

ComplianceStack Pricing

Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies §164.308(a)(1)(ii)(A) and OCR investigation defensibility.

View Pricing →

§6 Frequently Asked Questions

What does the HIPAA Privacy Rule require under 45 CFR §164.500–534?
The Privacy Rule governs every use and disclosure of Protected Health Information (PHI) by covered entities (healthcare providers, health plans, healthcare clearinghouses) and (post-Omnibus) by their business associates. The minimum-necessary standard in §164.502(b) limits every use or disclosure to the smallest amount needed for the purpose — one of the most-cited provisions in OCR enforcement. §164.514(b)(2)(i) lists the 18 PHI identifiers that must be removed for de-identification: names; geographic subdivisions smaller than a state; all date elements other than year; telephone, fax, email, SSN, medical record, health plan beneficiary, account, certificate/license, vehicle, device, URL, IP, biometric, full-face photo; and any other unique identifying code. Individual rights under §164.524 (access in 30 days), §164.526 (amendment in 60 days), and §164.528 (six-year accounting of disclosures) round out the operational set. ComplianceStack flags missing minimum-necessary documentation and missing six-year retention under §164.530(j)(2) as the two most-cited Privacy Rule findings in current Corrective Action Plans.
What does the HIPAA Security Rule require under 45 CFR §164.308–312?
45 CFR §164.308–312 requires covered entities (and business associates under §164.314(b)) to maintain three families of safeguards: Administrative (§164.308: risk analysis under (a)(1)(ii)(A), risk management, assigned security responsibility, workforce security, training, incident procedures, contingency plan, evaluation), Physical (§164.310: facility access controls, workstation use and restrictions, device and media controls), and Technical (§164.312: unique user identification, emergency access, automatic logoff, encryption/decryption, audit controls, integrity, person/entity authentication, transmission security). HHS/OCR expects a documented risk analysis under §164.308(a)(1)(ii)(A) plus operating evidence for every safeguard category — the formatting ComplianceStack uses is the four-column shape (asset / threat / likelihood × impact / current safeguard) that OCR investigators request by name in every CAP. The §164.402(2) encryption safe-harbor under §164.312(a)(2)(iv) is the single highest-leverage safeguard: NIST SP 800-111 encryption triggers a presumption of no breach — eliminating all §164.404 and §164.408 notification obligations.
What are the HIPAA breach notification requirements for affected individuals under 45 CFR §164.404?
Under 45 CFR §164.404, a covered entity must notify each affected individual "without unreasonable delay and in no case later than 60 calendar days" after the date of discovery of a breach of unsecured PHI. The 60-day clock starts at the date the covered entity knew or should reasonably have known of the breach — not at the date of the underlying incident. Default notice is by first-class mail to the last known address; email is permitted if the individual has agreed; telephone notice is permitted for urgent situations. Substitute notice (web posting + prominent media) applies when contact information is insufficient or outdated for 10 or more individuals. §164.406 media notice and §164.408 HHS Breach Portal notification both trigger at the same 500-individual threshold. ComplianceStack treats §164.404 as the hard-stop date that drives every other notification obligation.
What are the current 2026 HIPAA penalty tiers under 45 CFR §160.404?
The 2026 inflation-adjusted penalty tiers at 45 CFR §160.404 are: Tier 1 (lack of knowledge) $145 per violation; Tier 2 (reasonable cause) $1,478 per violation; Tier 3 (willful neglect — corrected) $18,892 per violation; Tier 4 (willful neglect — not corrected) $71,162 per violation. Each tier carries the same $2,190,294 annual cap per identical violation category per year. These amounts are updated annually by HHS under the Federal Civil Penalties Inflation Adjustment Act and do NOT include separate criminal penalties under 42 USC §1320d-5 (up to $50K + 1 year for knowing violations, escalating to $250K + 10 years for violations with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm). ComplianceStack's HIPAA risk calculator uses the 2026 inflation-adjusted figures as the default penalty exposure layer.
How does a HIPAA risk assessment satisfy 45 CFR §164.308(a)(1)(ii)(A)?
ComplianceStack maps a §164.308(a)(1)(ii)(A)-defensible HIPAA risk assessment to four columns that OCR investigators request by name in every Corrective Action Plan: (1) every ePHI asset and the system that stores or transmits it, (2) every reasonable threat to that asset, (3) the likelihood and impact of each threat, and (4) the current safeguard that mitigates it. Each row must be paired with a §164.308(a)(1)(ii)(B) risk management action — the assessment is the diagnosis; the action plan is the treatment. ComplianceStack's HIPAA risk calculator at compliancestack.ai/hipaa-risk-calculator produces the four-column risk analysis plus a prioritized §164.308(a)(1)(ii)(B) remediation plan in the format that OCR's 2025–2026 enforcement framing cites as the audit-defensible shape. A free 10-question counterpart lives at compliancestack.ai/free-hipaa-risk-assessment.
Does HIPAA apply to a business associate under 45 CFR §164.314?
Yes — both covered entities and business associates are directly subject to the Security Rule under §164.314. §164.314(a) requires the covered entity to obtain a written Business Associate Agreement (BAA) from every business associate that creates, receives, maintains, or transmits ePHI on its behalf, with the BAA carrying the §164.314(a)(2)(i) mandatory provisions. §164.314(b) makes business associates directly liable to HHS for §164.308 administrative safeguards, §164.310 physical safeguards, §164.312 technical safeguards, and §164.316 documentation. Business associates additionally owe an upstream notification under §164.410 when they discover a breach of unsecured PHI — an obligation that does not exist in the Privacy Rule and is frequently missing from unmarked BAA templates. ComplianceStack recommends treating the BAA inventory as a quarterly review deliverable.