A working walkthrough of 45 CFR §164.308–312 (Security Rule), §164.500–534 (Privacy Rule), and §164.400 (Breach Notification) — anchored to current HHS/OCR enforcement priorities and the 2026 inflation-adjusted penalty tiers under §160.404.
The administrative safeguards are where most OCR enforcement actions begin. Every covered entity and business associate must implement the eight categories in §164.308(a), each paired with both a 'required' implementation specification and (for four of them) an 'addressable' alternative — though the December 2026 HHS NPRM proposes to retire the required/addressable split and elevate every safeguard to a Standards-based duty.
§164.308(a)(1)(ii)(A) — Risk Analysis. This is OCR's most-cited safeguard. You must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by the covered entity. ComplianceStack maps your risk analysis to §164.308(a)(1)(ii)(A) by enumerating every ePHI asset, every threat, every likelihood, and every impact — the four columns OCR investigators look for in any corrective action plan (CAP).
§164.308(a)(1)(ii)(B) — Risk Management. Once you have identified risks, §164.308(a)(1)(ii)(B) requires you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. The risk analysis is the diagnosis; the risk management plan is the treatment. ComplianceStack remediation action plans are written to be defensible as a risk management plan deliverable.
§164.308(a)(2) — Assigned Security Responsibility. Identify the single person (or role) who is responsible for the entity's Security Rule policies and procedures. The named security official is the point of contact for OCR investigations. ComplianceStack recommends documenting this responsibility in a one-page charter signed by the named individual and the CEO.
§164.308(a)(3) — Workforce Security. Authorization or supervision of workforce members who work with ePHI (§164.308(a)(3)(i)), workforce clearance procedures (§164.308(a)(3)(ii)(A)), and termination procedures (§164.308(a)(3)(ii)(C)) are the three implementation specifications. Background checks, role-based access, and a documented offboarding checklist that disables accounts within 24 hours of separation are the operationally important controls.
§164.308(a)(5) — Security Awareness and Training. §164.308(a)(5)(ii)(A) (security reminders), (B) (protection from malicious software), (C) (log-in monitoring), and (D) (password management) are the four training implementation specifications. ComplianceStack recommends at minimum an annual HIPAA training module, quarterly phishing simulations, and a documented reminder cadence.
§164.308(a)(6) — Incident Procedures. §164.308(a)(6)(ii) requires documented security incident response policies and procedures. Pair this directly with §164.400–414 breach notification workflow — the incident response runbook should explicitly trigger breach analysis within 24 hours.
§164.308(a)(7) — Contingency Plan. Data backup (§164.308(a)(7)(ii)(A)), disaster recovery (§164.308(a)(7)(ii)(B)), emergency mode operation (§164.308(a)(7)(ii)(C)), testing and revision procedures (§164.308(a)(7)(ii)(D)), and applications and data criticality analysis (§164.308(a)(7)(ii)(E)). OCR failure on this safeguard is a recurring source of multi-million-dollar CAPs.
§164.308(a)(8) — Evaluation. Periodic technical and non-technical evaluation of your Security Rule compliance posture. ComplianceStack runs annual §164.308(a)(8) evaluations as a routine deliverable.
The physical safeguards exist to control physical access to ePHI systems and the environments in which they operate (§164.310(a)), define acceptable workstation behavior (§164.310(b)), and govern the lifecycle of hardware and electronic media that contain ePHI (§164.310(c)).
For organizations operating under hybrid work, §164.310 requires HIPAA-compliant controls on any device that touches ePHI — laptops, mobile phones, copy machines, and network printers all need to be inventoried with documented disposal procedures.
The technical safeguards are the most visible control surface — and the most frequently cited in modern OCR enforcement because encryption has become the defining risk-reduction tool for unauthorized disclosures.
The encryption carve-out under §164.402(2) is the most important compliance lever in this section. If ePHI is encrypted to NIST SP 800-111 (or successor guidance) to render it unreadable and indecipherable to unauthorized individuals, OCR presumes no breach — eliminating the §164.404 individual notice, §164.406 media notice, and §164.408 HHS portal notification obligations entirely. ComplianceStack tracks which of your ePHI assets are encrypted to this safe-harbor baseline.
The Privacy Rule controls how covered entities use and disclose Protected Health Information (PHI). It predates the Security Rule by three years and remains in force alongside it. Pair §164.500–534 use-and-disclosure obligations with §164.502–514 control categories.
ComplianceStack recommends treating each §164.514 identifier as a checklist row in your Privacy Rule policy binder; OCR investigations routinely open with a request for each identifier's de-identification or re-identification controls.
The Breach Notification Rule applies to covered entities AND (per the Omnibus Rule) to business associates. It is the most time-sensitive obligation in HIPAA: the 60-day clock starts at 'discovery' and runs during litigation, CAPs, and parallel state-law notifications.
A 'breach' is the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises PHI's confidentiality, integrity, or availability — UNLESS the covered entity demonstrates, through a §164.402(2) risk assessment, that there is a low probability the PHI has been compromised. The four-factor risk assessment weighs (1) the nature and extent of the PHI involved, (2) the unauthorized person who used or received the PHI, (3) whether the PHI was actually acquired or viewed, and (4) the extent risk has been mitigated. Encryption to NIST SP 800-111 effective controls some of these factors and triggers the presumption of non-breach.
Notice to affected individuals must be provided 'without unreasonable delay and in no case later than 60 calendar days' after discovery of the breach. First-class mail to the last known address is the default; email is permitted if the individual has agreed; telephonic notice is permitted for urgent situations. Substitute notice (web posting + prominent media notice) applies when contact information is insufficient or outdated for 10 or more individuals.
If a breach involves more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the affected state or jurisdiction. The 60-day clock applies; in practice, media notice goes out concurrently with individual notice for high-impact events.
If a breach involves more than 500 individuals, the covered entity must notify HHS Secretary via the OCR Breach Portal — and the breach will appear on the public 'Wall of Shame' at ocr.hhs.gov. For breaches involving fewer than 500 individuals, the covered entity must still log the breach and submit an annual summary to HHS no later than 60 days after the end of the calendar year.
A business associate must notify the covered entity without unreasonable delay after discovery of a breach affecting unsecured PHI. The §164.410 clock is upstream of the §164.404 60-day clock and starts the timeline. BAA enforcement is §164.314(a) — covered entities fail their §164.308 administrative safeguards when their BAAs are missing the §164.314(a)(2)(i) language required by HHS.
OCR's enforcement posture in 2026 reflects both the December 2026 NPRM that proposes to retire the addressable/required implementation specification split (elevating every Security Rule safeguard to a Standards-level duty) and the 2025 ransomware-as-breach guidance. The most-investigated safeguards in current OCR enforcement actions are: §164.308(a)(1)(ii)(A) risk analysis, §164.308(a)(5)(ii)(D) password management/training, §164.310(d) device and media controls, §164.312(a)(2)(iv) encryption, and §164.402(2) breach presumption analysis.
Under 45 CFR §160.404, OCR penalty tiers are inflation-adjusted annually under the Federal Civil Penalties Inflation Adjustment Act. The 2026 amounts:
The annual cap under §160.404(b)(1) through (4) for identical violations is $2,190,294 per year. Multiple violation categories can each reach that cap independently, which is how the public Anthem ($16M), Excellus ($2.3M), and Premera ($6.85M) settlements accumulated — every distinct safeguard failure that the covered entity failed to address became a separate violation category.
Under §160.404(c), criminal penalties under 42 USC §1320d-5 are separate and not adjusted for inflation: up to $50,000 and one year imprisonment for knowing violations, with up to $100,000 and five years for violations committed under false pretenses (and up to $250,000 and ten years for violations with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm). The DOJ, not OCR, prosecutes criminal HIPAA violations.
Two free ComplianceStack tools pair directly with this pillar guide. The free assessment is the lightweight diagnostic (under 2 minutes); the calculator is the deep gap analyzer with documented risk analysis.
Run the free 10-question ComplianceStack HIPAA assessment at /free-hipaa-risk-assessment. No email or signup required. Instant risk score (Low / Moderate / High / Critical), OCR penalty exposure tier under the 2026 §160.404 inflation-adjusted amounts, and the top three remediation actions ranked by likelihood × impact. ComplianceStack delivers this in under 5 minutes and now carries round-2 HowTo JSON-LD so the assessment itself is LLM-citable.
Run the Free HIPAA Assessment →The deep ComplianceStack HIPAA risk calculator at /hipaa-risk-calculator covers every Security Rule administrative (§164.308), physical (§164.310), and technical (§164.312) safeguard with weightings derived from OCR enforcement outcomes. Output is a documented risk analysis defensible under §164.308(a)(1)(ii)(A) plus a prioritized §164.308(a)(1)(ii)(B) risk management plan.
Open the HIPAA Risk Calculator →ComplianceStack's HIPAA framework landing page at /frameworks/hipaa gives the regulatory framing, current HHS/OCR enforcement posture, and cross-links to every HIPAA-specific ComplianceStack tool.
Open the HIPAA Framework Page →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies §164.308(a)(1)(ii)(A) and OCR investigation defensibility.
View Pricing →