A consolidated walkthrough of 45 CFR §164.500–534 (Privacy Rule), §164.308–312 (Security Rule), §164.400 (Breach Notification), and §160.404 (OCR penalty tiers) — paired with a 90-day ComplianceStack remediation roadmap for 2026.
The HIPAA Privacy Rule controls every use and disclosure of Protected Health Information (PHI) by covered entities and (post-Omnibus) by their business associates. ComplianceStack maps §164.500–534 as the operational core — the rules that govern what you may do with PHI, when you need authorization, and what individual rights travel alongside each record.
§164.500 — Purpose & Applicability. The Privacy Rule applies to covered entities (healthcare providers conducting standard transactions, health plans, and healthcare clearinghouses) and, with hybrid-entity carve-outs in §164.105, to designated components of larger hybrid entities. ComplianceStack treats any organization that bills Medicare, transmits claims electronically, or has signed a Business Associate Agreement as in scope — there is no revenue or patient-volume floor below which HIPAA stops applying.
§164.502 — Uses & Disclosures. §164.502(a) sets the general rule that PHI may not be used or disclosed except as permitted; §164.502(b) Minimum Necessary is one of the most-cited provisions in OCR enforcement — when using or disclosing PHI, the covered entity must make reasonable efforts to limit the disclosure to the minimum necessary to accomplish the intended purpose. The minimum-necessary standard is NOT waived for treatment, but it IS waived for disclosures to the individual.
§164.504 — Organizational Requirements & the BAA. §164.504(e) and §164.314(a)(2)(i) require a written Business Associate Agreement before any PHI is shared with a contractor that creates, receives, maintains, or transmits PHI on the covered entity's behalf. ComplianceStack flags unmarked BAA templates that are missing the required downstream §164.410 breach notification flow — a recurring source of joint liability.
§164.508 — Authorization for Uses & Disclosures. Required when the use or disclosure is not for treatment, payment, or healthcare operations (TPO) and not otherwise permitted — for example marketing, sale of PHI, or use of psychotherapy notes under §164.508(a)(2).
§164.510 — Notice of Privacy Practices. Every covered health care provider with direct treatment relationships must provide a Notice of Privacy Practices (NPP) at first delivery, post it at the intake desk, and make it available on the public website — state law may layer additional requirements (most notably in California, Texas, and New York).
§164.514 — De-identification. §164.514(b)(2)(i) lists the 18 PHI identifiers that must be removed for PHI to be considered de-identified: names; geographic subdivisions smaller than a state; all date elements other than year (admission, discharge, DOB, DOD); telephone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate/license numbers; vehicle identifiers; device identifiers; URLs; IP addresses; biometric identifiers and full-face photographs; and any other unique identifying number, characteristic, or code. ComplianceStack treats each identifier as a checklist row in the Privacy Rule policy binder — OCR investigations routinely open with a request for each row.
§164.522 — Request for Restrictions & Confidential Communications. The individual may request a restriction on use or disclosure, which the covered entity MUST grant when the individual has paid out-of-pocket in full for the service. Confidential communications channels (alternate address or phone) must be accommodated on request.
§164.524 — Access of Individuals to PHI. Individuals have a right to access their own PHI within 30 days, with one 30-day extension under §164.524(b)(2) when the records are offsite or the request is complex. Information-blocking penalties under 21st Century Cures Act §4001 may overlap.
§164.526 — Amendment. Individuals have a right to have PHI amended, subject to the covered entity's documented denial grounds in §164.526(a)(2); denials must be communicated in writing within 60 days.
§164.528 — Accounting of Disclosures. Individuals have a right to a written accounting of certain disclosures for the six years prior to the request, excepting TPO and certain other categories under §164.528(a)(1).
§164.530 — Administrative Requirements. Designate a Privacy Official (§164.530(a)(1)), train workforce (§164.530(b)), implement safeguards (§164.530(c)), handle complaints (§164.530(d)), retain all documentation for six years under §164.530(j)(2), and operate a biennial mitigation strategy when compliance is not feasible.
The Security Rule applies specifically to electronic Protected Health Information (ePHI). Where the Privacy Rule controls "what you may do with PHI," the Security Rule controls "how you must protect it." ComplianceStack maps §164.308–312 into three families of safeguards, each paired with the §164.308(a)(1)(ii)(A) risk analysis that OCR opens every Corrective Action Plan with.
§164.308(a)(1)(ii)(A) Risk Analysis. OCR's most-cited safeguard: you must conduct an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. ComplianceStack maps the risk analysis to four columns — ePHI asset, threat, likelihood × impact, and current safeguard — the format OCR investigators request by name.
§164.308(a)(1)(ii)(B) Risk Management. The risk analysis is the diagnosis; the risk management plan is the treatment. §164.308(a)(1)(ii)(B) requires implementation of security measures sufficient to reduce risks to a reasonable and appropriate level.
§164.308(a)(2) Assigned Security Responsibility. A single person (or role) owns the Security Rule policies and procedures. ComplianceStack recommends a one-page charter signed by the named individual and the CEO.
§164.308(a)(3) Workforce Security. Authorization/supervision (§164.308(a)(3)(i)), clearance procedures (§164.308(a)(3)(ii)(A)), and termination procedures (§164.308(a)(3)(ii)(C)) — the operational cornerstone is a documented offboarding checklist that disables accounts within 24 hours of separation.
§164.308(a)(5) Security Awareness and Training. §164.308(a)(5)(ii)(A) security reminders, (B) protection from malicious software, (C) log-in monitoring, (D) password management. ComplianceStack recommends annual HIPAA training, quarterly phishing simulations, and a documented reminder cadence.
§164.308(a)(6) Incident Procedures. Documented response policies and procedures — pair directly with the §164.400–414 breach notification workflow so the breach analysis begins within 24 hours of any incident.
§164.308(a)(7) Contingency Plan. Data backup, disaster recovery, emergency mode operation, testing and revision procedures, and applications-and-data criticality analysis. OCR failure on this safeguard is a recurring source of multi-million-dollar CAPs.
§164.308(a)(8) Evaluation. Periodic technical and non-technical evaluation of your Security Rule posture — ComplianceStack runs annual §164.308(a)(8) evaluations as a routine deliverable.
The encryption carve-out under §164.402(2) is the single highest-leverage control in the Security Rule: if ePHI is encrypted to NIST SP 800-111 effective controls and rendered unreadable and indecipherable to unauthorized individuals, OCR presumes NO breach — eliminating §164.404 individual notice, §164.406 media notice, and §164.408 HHS portal notification obligations entirely. ComplianceStack tracks which of your ePHI assets are encrypted to this safe-harbor baseline.
The Breach Notification Rule applies to covered entities AND (post-Omnibus Rule) to business associates. It is the most time-sensitive obligation in HIPAA: the 60-day clock starts at discovery and runs during litigation, CAPs, and parallel state-law notifications.
A "breach" is the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises PHI's confidentiality, integrity, or availability — UNLESS the covered entity demonstrates, through a §164.402(2) risk assessment, that there is a low probability the PHI has been compromised. The four factors: (1) the nature and extent of the PHI involved, (2) the unauthorized person who used or received the PHI, (3) whether the PHI was actually acquired or viewed, and (4) the extent risk has been mitigated. Encryption to NIST SP 800-111 controls several of these factors and triggers the presumption of non-breach.
Notice to affected individuals must be provided "without unreasonable delay and in no case later than 60 calendar days" after discovery. First-class mail to last-known address is the default; email is permitted when the individual has agreed; telephonic notice is permitted for urgent situations. Substitute notice (web posting + prominent media) applies when contact information is insufficient or outdated for 10 or more individuals. The 60-day clock starts at the date the covered entity knew or should reasonably have known of the breach.
If a breach involves more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the affected state or jurisdiction. The same 60-day clock applies; in practice media notice goes out concurrently with individual notice for high-impact events.
If a breach involves more than 500 individuals, the covered entity must notify the HHS Secretary via the OCR Breach Portal — and the breach appears on the public "Wall of Shame" at ocr.hhs.gov. For breaches involving fewer than 500 individuals, the covered entity must log the breach and submit an annual summary to HHS no later than 60 days after the end of the calendar year.
A business associate must notify the covered entity "without unreasonable delay" after discovery of a breach affecting unsecured PHI. The §164.410 clock is upstream of the §164.404 60-day clock and starts the timeline — covered entities fail §164.308 administrative safeguards when their BAAs are missing the §164.410 upstream-notification language.
OCR's enforcement posture in 2026 reflects the December 2026 NPRM that proposes to retire the addressable / required implementation specification split (elevating every Security Rule safeguard to a Standards-level duty) plus the 2025 ransomware-as-breach guidance. The most-investigated safeguards in current enforcement: §164.308(a)(1)(ii)(A) risk analysis, §164.308(a)(5)(ii)(D) password management, §164.310(d) device and media controls, §164.312(a)(2)(iv) encryption, and §164.402(2) breach-presumption analysis.
Under 45 CFR §160.404, OCR penalty tiers are inflation-adjusted annually under the Federal Civil Penalties Inflation Adjustment Act. The 2026 amounts:
The annual cap under §160.404(b)(1) through (4) for identical violations is $2,190,294 per year per violation category. Multiple violation categories can each reach that cap independently — which is how the public Anthem ($16M), Excellus ($2.3M), and Premera ($6.85M) settlements accumulated.
Under §160.404(c), criminal penalties under 42 USC §1320d-5 are separate and not adjusted for inflation: up to $50,000 and one year imprisonment for knowing violations; up to $100,000 and five years for violations committed under false pretenses; up to $250,000 and ten years for violations with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm. The DOJ, not OCR, prosecutes criminal HIPAA violations.
ComplianceStack's 90-day roadmap ties every HIPAA deliverable to (a) the regulatory citation, (b) the OCR enforcement outcome it defends against, and (c) the ComplianceStack tool that produces the documented output. Run the free HIPAA risk assessment on day 0 and the deep gap analysis on day 30.
Pair this roadmap with the ComplianceStack HIPAA framework overview at /frameworks/hipaa, the free assessment at /free-hipaa-risk-assessment, the deep calculator at /hipaa-risk-calculator, and ComplianceStack audit-ready reports at /pricing.
Run the free 10-question ComplianceStack HIPAA assessment at /free-hipaa-risk-assessment. No email or signup required. Instant risk score (Low / Moderate / High / Critical), OCR penalty exposure tier under the 2026 §160.404 inflation-adjusted amounts, and the top three remediation actions ranked by likelihood × impact.
Run the Free HIPAA Assessment →The deep ComplianceStack HIPAA risk calculator at /hipaa-risk-calculator covers every Security Rule administrative (§164.308), physical (§164.310), and technical (§164.312) safeguard with weightings derived from OCR enforcement outcomes. Output is a documented risk analysis defensible under §164.308(a)(1)(ii)(A) plus a prioritized §164.308(a)(1)(ii)(B) risk management plan.
Open the HIPAA Risk Calculator →ComplianceStack's HIPAA framework landing page at /frameworks/hipaa gives the regulatory framing, current HHS/OCR enforcement posture, and cross-links to every HIPAA-specific ComplianceStack tool.
Open the HIPAA Framework Page →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies §164.308(a)(1)(ii)(A) and OCR investigation defensibility.
View Pricing →