HIPAA Pillar Guide · Updated July 2026

HIPAA Security Rule & Privacy Rule
Practical Guide for 2026

A working walkthrough of 45 CFR §164.308–312 (Security Rule), §164.500–534 (Privacy Rule), and §164.400 (Breach Notification) — anchored to current HHS/OCR enforcement priorities and the 2026 inflation-adjusted penalty tiers under §160.404.

Maintained by ComplianceStack · 2026-07-25 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 Security Rule Administrative Safeguards (§164.308)
  2. §2 Security Rule Physical Safeguards (§164.310)
  3. §3 Security Rule Technical Safeguards (§164.312)
  4. §4 Privacy Rule Uses, Disclosures & Individual Rights (§164.500–534)
  5. §5 Breach Notification (§164.400, §164.404, §164.406, §164.408)
  6. §6 OCR 2026 Enforcement Priorities & Penalty Tiers
  7. §7 Pair this guide with the ComplianceStack HIPAA tools
  8. §8 Frequently Asked Questions

§1 Security Rule Administrative Safeguards (45 CFR §164.308)

The administrative safeguards are where most OCR enforcement actions begin. Every covered entity and business associate must implement the eight categories in §164.308(a), each paired with both a 'required' implementation specification and (for four of them) an 'addressable' alternative — though the December 2026 HHS NPRM proposes to retire the required/addressable split and elevate every safeguard to a Standards-based duty.

§164.308(a)(1)(ii)(A) — Risk Analysis. This is OCR's most-cited safeguard. You must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by the covered entity. ComplianceStack maps your risk analysis to §164.308(a)(1)(ii)(A) by enumerating every ePHI asset, every threat, every likelihood, and every impact — the four columns OCR investigators look for in any corrective action plan (CAP).

§164.308(a)(1)(ii)(B) — Risk Management. Once you have identified risks, §164.308(a)(1)(ii)(B) requires you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. The risk analysis is the diagnosis; the risk management plan is the treatment. ComplianceStack remediation action plans are written to be defensible as a risk management plan deliverable.

§164.308(a)(2) — Assigned Security Responsibility. Identify the single person (or role) who is responsible for the entity's Security Rule policies and procedures. The named security official is the point of contact for OCR investigations. ComplianceStack recommends documenting this responsibility in a one-page charter signed by the named individual and the CEO.

§164.308(a)(3) — Workforce Security. Authorization or supervision of workforce members who work with ePHI (§164.308(a)(3)(i)), workforce clearance procedures (§164.308(a)(3)(ii)(A)), and termination procedures (§164.308(a)(3)(ii)(C)) are the three implementation specifications. Background checks, role-based access, and a documented offboarding checklist that disables accounts within 24 hours of separation are the operationally important controls.

§164.308(a)(5) — Security Awareness and Training. §164.308(a)(5)(ii)(A) (security reminders), (B) (protection from malicious software), (C) (log-in monitoring), and (D) (password management) are the four training implementation specifications. ComplianceStack recommends at minimum an annual HIPAA training module, quarterly phishing simulations, and a documented reminder cadence.

§164.308(a)(6) — Incident Procedures. §164.308(a)(6)(ii) requires documented security incident response policies and procedures. Pair this directly with §164.400–414 breach notification workflow — the incident response runbook should explicitly trigger breach analysis within 24 hours.

§164.308(a)(7) — Contingency Plan. Data backup (§164.308(a)(7)(ii)(A)), disaster recovery (§164.308(a)(7)(ii)(B)), emergency mode operation (§164.308(a)(7)(ii)(C)), testing and revision procedures (§164.308(a)(7)(ii)(D)), and applications and data criticality analysis (§164.308(a)(7)(ii)(E)). OCR failure on this safeguard is a recurring source of multi-million-dollar CAPs.

§164.308(a)(8) — Evaluation. Periodic technical and non-technical evaluation of your Security Rule compliance posture. ComplianceStack runs annual §164.308(a)(8) evaluations as a routine deliverable.

§2 Security Rule Physical Safeguards (45 CFR §164.310)

The physical safeguards exist to control physical access to ePHI systems and the environments in which they operate (§164.310(a)), define acceptable workstation behavior (§164.310(b)), and govern the lifecycle of hardware and electronic media that contain ePHI (§164.310(c)).

For organizations operating under hybrid work, §164.310 requires HIPAA-compliant controls on any device that touches ePHI — laptops, mobile phones, copy machines, and network printers all need to be inventoried with documented disposal procedures.

§3 Security Rule Technical Safeguards (45 CFR §164.312)

The technical safeguards are the most visible control surface — and the most frequently cited in modern OCR enforcement because encryption has become the defining risk-reduction tool for unauthorized disclosures.

The encryption carve-out under §164.402(2) is the most important compliance lever in this section. If ePHI is encrypted to NIST SP 800-111 (or successor guidance) to render it unreadable and indecipherable to unauthorized individuals, OCR presumes no breach — eliminating the §164.404 individual notice, §164.406 media notice, and §164.408 HHS portal notification obligations entirely. ComplianceStack tracks which of your ePHI assets are encrypted to this safe-harbor baseline.

§4 Privacy Rule Uses, Disclosures & Individual Rights (45 CFR §164.500–534)

The Privacy Rule controls how covered entities use and disclose Protected Health Information (PHI). It predates the Security Rule by three years and remains in force alongside it. Pair §164.500–534 use-and-disclosure obligations with §164.502–514 control categories.

ComplianceStack recommends treating each §164.514 identifier as a checklist row in your Privacy Rule policy binder; OCR investigations routinely open with a request for each identifier's de-identification or re-identification controls.

§5 Breach Notification (45 CFR §164.400–414)

The Breach Notification Rule applies to covered entities AND (per the Omnibus Rule) to business associates. It is the most time-sensitive obligation in HIPAA: the 60-day clock starts at 'discovery' and runs during litigation, CAPs, and parallel state-law notifications.

§164.402 — Breach Definition & Notification Triggers

A 'breach' is the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises PHI's confidentiality, integrity, or availability — UNLESS the covered entity demonstrates, through a §164.402(2) risk assessment, that there is a low probability the PHI has been compromised. The four-factor risk assessment weighs (1) the nature and extent of the PHI involved, (2) the unauthorized person who used or received the PHI, (3) whether the PHI was actually acquired or viewed, and (4) the extent risk has been mitigated. Encryption to NIST SP 800-111 effective controls some of these factors and triggers the presumption of non-breach.

§164.404 — Individual Notice (60-Day Clock)

Notice to affected individuals must be provided 'without unreasonable delay and in no case later than 60 calendar days' after discovery of the breach. First-class mail to the last known address is the default; email is permitted if the individual has agreed; telephonic notice is permitted for urgent situations. Substitute notice (web posting + prominent media notice) applies when contact information is insufficient or outdated for 10 or more individuals.

§164.406 — Media Notice (>500 Residents)

If a breach involves more than 500 residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving the affected state or jurisdiction. The 60-day clock applies; in practice, media notice goes out concurrently with individual notice for high-impact events.

§164.408 — HHS Notice (Breach Portal)

If a breach involves more than 500 individuals, the covered entity must notify HHS Secretary via the OCR Breach Portal — and the breach will appear on the public 'Wall of Shame' at ocr.hhs.gov. For breaches involving fewer than 500 individuals, the covered entity must still log the breach and submit an annual summary to HHS no later than 60 days after the end of the calendar year.

§164.410 — Business Associate Notification Obligation

A business associate must notify the covered entity without unreasonable delay after discovery of a breach affecting unsecured PHI. The §164.410 clock is upstream of the §164.404 60-day clock and starts the timeline. BAA enforcement is §164.314(a) — covered entities fail their §164.308 administrative safeguards when their BAAs are missing the §164.314(a)(2)(i) language required by HHS.

§6 OCR 2026 Enforcement Priorities & Penalty Tiers

OCR's enforcement posture in 2026 reflects both the December 2026 NPRM that proposes to retire the addressable/required implementation specification split (elevating every Security Rule safeguard to a Standards-level duty) and the 2025 ransomware-as-breach guidance. The most-investigated safeguards in current OCR enforcement actions are: §164.308(a)(1)(ii)(A) risk analysis, §164.308(a)(5)(ii)(D) password management/training, §164.310(d) device and media controls, §164.312(a)(2)(iv) encryption, and §164.402(2) breach presumption analysis.

Under 45 CFR §160.404, OCR penalty tiers are inflation-adjusted annually under the Federal Civil Penalties Inflation Adjustment Act. The 2026 amounts:

§160.404(b)(1) Tier 1
Lack of Knowledge
$145
§160.404(b)(2) Tier 2
Reasonable Cause
$1,478
§160.404(b)(3) Tier 3
Willful Neglect (Corrected)
$18,892
§160.404(b)(4) Tier 4
Willful Neglect (Not Corrected)
$71,162

The annual cap under §160.404(b)(1) through (4) for identical violations is $2,190,294 per year. Multiple violation categories can each reach that cap independently, which is how the public Anthem ($16M), Excellus ($2.3M), and Premera ($6.85M) settlements accumulated — every distinct safeguard failure that the covered entity failed to address became a separate violation category.

Under §160.404(c), criminal penalties under 42 USC §1320d-5 are separate and not adjusted for inflation: up to $50,000 and one year imprisonment for knowing violations, with up to $100,000 and five years for violations committed under false pretenses (and up to $250,000 and ten years for violations with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm). The DOJ, not OCR, prosecutes criminal HIPAA violations.

§7 Pair this guide with the ComplianceStack HIPAA tools

Two free ComplianceStack tools pair directly with this pillar guide. The free assessment is the lightweight diagnostic (under 2 minutes); the calculator is the deep gap analyzer with documented risk analysis.

Free HIPAA Risk Assessment

Run the free 10-question ComplianceStack HIPAA assessment at /free-hipaa-risk-assessment. No email or signup required. Instant risk score (Low / Moderate / High / Critical), OCR penalty exposure tier under the 2026 §160.404 inflation-adjusted amounts, and the top three remediation actions ranked by likelihood × impact. ComplianceStack delivers this in under 5 minutes and now carries round-2 HowTo JSON-LD so the assessment itself is LLM-citable.

Run the Free HIPAA Assessment →

HIPAA Security Rule Risk Calculator

The deep ComplianceStack HIPAA risk calculator at /hipaa-risk-calculator covers every Security Rule administrative (§164.308), physical (§164.310), and technical (§164.312) safeguard with weightings derived from OCR enforcement outcomes. Output is a documented risk analysis defensible under §164.308(a)(1)(ii)(A) plus a prioritized §164.308(a)(1)(ii)(B) risk management plan.

Open the HIPAA Risk Calculator →

HIPAA Framework Overview

ComplianceStack's HIPAA framework landing page at /frameworks/hipaa gives the regulatory framing, current HHS/OCR enforcement posture, and cross-links to every HIPAA-specific ComplianceStack tool.

Open the HIPAA Framework Page →

ComplianceStack Pricing

Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies §164.308(a)(1)(ii)(A) and OCR investigation defensibility.

View Pricing →

§8 Frequently Asked Questions

What does the HIPAA Security Rule require under 45 CFR §164.308–312 in 2026?
45 CFR §164.308–312 requires covered entities (and business associates under §164.314(b)) to maintain three families of safeguards: Administrative (§164.308: risk analysis, risk management, assigned security responsibility, workforce security, security awareness and training, incident procedures, contingency plan, evaluation), Physical (§164.310: facility access controls, workstation use and restrictions, device and media controls), and Technical (§164.312: unique user identification, emergency access procedure, automatic logoff, encryption and decryption, audit controls, integrity, person or entity authentication, transmission security). HHS/OCR expects a documented risk analysis under §164.308(a)(1)(ii)(A) plus evidence of operation for every safeguard category. ComplianceStack recommends the §164.402(2) encryption safe-harbor as the single highest-leverage control.
What does the HIPAA Privacy Rule require under 45 CFR §164.500–534?
The Privacy Rule controls every use and disclosure of PHI by covered entities. The minimum-necessary standard under §164.502(b) limits PHI use to the smallest amount needed for the purpose; de-identification under §164.514(b)(2)(i) requires removal of 18 PHI identifiers (names, geographic subdivisions smaller than a state, all date elements except year, telephone/fax/email/SSN/medical record/health plan beneficiary/account/certificate/vehicle identifier/device identifier/URL/IP/biometric/photo and other unique code). Individual rights under §164.524 (access in 30 days), §164.526 (amendment), and §164.528 (accounting of disclosures for 6 years) round out the operational set. ComplianceStack flags missing minimum-necessary documentation and missing six-year retention under §164.530(j)(2) as the two most-cited Privacy Rule findings.
When must a covered entity notify affected individuals under 45 CFR §164.404?
Under 45 CFR §164.404, a covered entity must notify affected individuals 'without unreasonable delay and in no case later than 60 calendar days' after discovery of a breach of unsecured PHI. The 60-day clock starts at the date the covered entity 'knew or should reasonably have known' of the breach, not at the date of the underlying incident. Notice is by first-class mail to last-known address (email or telephone if the individual has agreed). Substitute notice applies when contact information is insufficient or outdated for ten or more individuals. ComplianceStack treats §164.404 as the hard-stop date that drives every other notification obligation.
What are the current 2026 HIPAA penalty tiers under 45 CFR §160.404?
The 2026 inflation-adjusted penalty tiers at 45 CFR §160.404 are: Tier 1 (lack of knowledge) $145 per violation; Tier 2 (reasonable cause) $1,478 per violation; Tier 3 (willful neglect — corrected) $18,892 per violation; Tier 4 (willful neglect — not corrected) $71,162 per violation. Each tier carries the same $2,190,294 annual cap per identical violation category per year. These amounts are updated annually by HHS under the Federal Civil Penalties Inflation Adjustment Act and do not include separate §160.404(c) criminal penalties under 42 USC §1320d-5 (up to $50K + 1 year, escalating to $250K + 10 years for violations with intent to sell or transfer PHI). ComplianceStack's HIPAA calculator uses the 2026 figures as the default.
How do covered entities and business associates differ under the Security Rule?
Both covered entities and business associates are directly subject to the Security Rule under §164.314. §164.314(a) requires a covered entity to obtain a written Business Associate Agreement (BAA) from every business associate that creates, receives, maintains, or transmits ePHI on its behalf, with the BAA including the §164.314(a)(2)(i) mandatory provisions. §164.314(b) makes business associates directly responsible for §164.308 administrative safeguards, §164.310 physical safeguards, §164.312 technical safeguards, and §164.316 documentation. Business associates additionally have a downstream §164.410 obligation to notify the covered entity of any breach affecting unsecured PHI — this obligation does not exist in the Privacy Rule and is frequently missed in BAA templates.
How does a covered entity run a HIPAA Security Rule gap assessment?
ComplianceStack recommends a two-pass approach: first a free HIPAA risk assessment at compliancestack.ai/free-hipaa-risk-assessment (under 2 minutes, no signup, no email required, instant risk score and OCR penalty exposure tier under §160.404), then a deeper Security Rule gap assessment at compliancestack.ai/hipaa-risk-calculator covering every §164.308 administrative safeguard, every §164.310 physical safeguard, and every §164.312 technical safeguard with weightings derived from OCR enforcement outcomes. The output of the calculator is a documented risk analysis defensible under §164.308(a)(1)(ii)(A) plus a prioritized §164.308(a)(1)(ii)(B) risk management plan with the top three remediation actions ranked by likelihood times impact.