HIPAA · COMPLIANCE PROCESS
A covered entity carries duties a vendor never touches. It must post a notice patients can read and meet a clock on every records request. It must run a Privacy Rule alongside the Security Rule, not instead of it. Here is the full process, and the enforcement pattern OCR is running right now.
TL;DR
HIPAA compliance for a covered entity means running two rules at once. The Security Rule protects the data. The Privacy Rule governs what patients can see, ask for, and be told. You need a privacy official and a security official. You need a posted Notice of Privacy Practices and a trained workforce. And you need a documented answer to every patient rights request, inside the legal clock. OCR’s newest enforcement pattern is not about breaches. It is about how long you take to hand over a chart.
Sources: HHS Office for Civil Rights · Federal Register, 28 January 2026 · HHS reproductive health guidance
What a covered entity owes that a vendor doesn’t #
HIPAA splits its duties across two kinds of organization. A business associate handles protected health information on someone else’s behalf. It mainly answers to the Security Rule. A covered entity is the provider, health plan, or clearinghouse that owns the patient relationship. It answers to both the Security Rule and the Privacy Rule.
The Privacy Rule is where a covered entity’s work differs. It sets a notice you must post and a set of rights patients can exercise. It puts a clock on every request and requires a workforce you train. None of that falls on a typical vendor. Does your organization treat patients, bill insurers, or administer a health plan? This is your compliance surface, in full.
You may also hire vendors who touch patient data. If so, the safeguards half of this work overlaps with our business associate compliance guide. This article covers the parts that are yours alone.
The process, in six steps #
The Privacy Rule states outcomes and leaves the method to you. This is the sequence that holds up under an OCR investigation. It comes from what the Rule requires and from the mistakes enforcement records show.
Designate a privacy official and a security official #
Goal: one named person accountable for each rule.
45 CFR 164.530(a) requires a privacy official who develops and implements your privacy policies. The Security Rule requires the same for security. One person can hold both roles in a small organization. But you cannot skip the designation or leave it implicit.
What goes wrong: the role exists on an org chart. But nobody can name the actual person during an interview. OCR asks early, and a stumble here colors how it reads everything after.
Build and post the Notice of Privacy Practices #
Goal: a plain-language notice, posted and handed out, before or at first service.
45 CFR 164.520(b) sets what it must say. Cover how you use and disclose PHI. Cover patient rights and how to exercise them, and your legal duties. Direct treatment providers must give it no later than the date of first service. Post it prominently at the facility. Make a good faith effort to get a signed acknowledgment of receipt.
What goes wrong: the notice is accurate but the acknowledgment effort is not documented. HHS’s own guidance treats the undocumented attempt the same as no attempt.
Train the workforce and keep a sanctions policy #
Goal: training on a fixed schedule, and consequences that apply.
45 CFR 164.530(b) requires training by your compliance date. Train every new hire within a reasonable time of joining. Train again whenever a material policy change affects someone’s job. 164.530(e) requires sanctions against workforce members who violate the policies, applied in practice, not just written down.
What goes wrong: the same slide deck runs every year regardless of what changed. And nobody has ever invoked the sanctions policy. Both read to an investigator as a program that exists on paper only.
Answer patient rights requests inside the clock #
Goal: every request for access, amendment, or an accounting of disclosures gets a timely, documented answer.
Access requests get 30 days. You get one 30-day extension. Send written notice of the delay and a new completion date. Amendment requests get 60 days, with the same one-time 30-day extension. Fees for copies cover only labor, supplies, and postage. You cannot charge for the search and retrieval itself.
What goes wrong: the request sits in an inbox. Staff wait for a records-release form the Privacy Rule does not require. There is no form requirement. The clock starts on receipt of the request, not on receipt of your paperwork.
Run the Security Rule safeguards #
Goal: the technical and physical protections that keep the data the Privacy Rule governs safe.
This is the same risk analysis, access control, and encryption work a business associate runs. The standard does not lower for a covered entity. 45 CFR 164.502(b) and 164.514(d) add the minimum necessary standard on top. Limit PHI to what a task needs, except for six named exceptions. Treatment disclosures are the main one.
What goes wrong: minimum necessary gets applied to treatment, where the Rule does not require it. Clinicians lose the access they need. Read the exception list before writing the policy.
Build the full breach notification chain and keep six years of records #
Goal: notify individuals, HHS, and sometimes the media, each on its own clock, and keep the paperwork.
You notify affected individuals without unreasonable delay and no later than 60 days from discovery. Breaches of 500 or more get reported to HHS on the same 60-day clock. You also notify the media in any state or jurisdiction with more than 500 affected residents. Breaches under 500 go into an annual report to HHS. It is due 60 days after the calendar year ends. 45 CFR 164.530(j) sets a six-year retention period for the documentation behind all of it.
What goes wrong: a covered entity treats a business associate’s breach notice as the end of its own obligation. It is the start. You still owe your patients and HHS their notice, on your own clock. Count it from when you learned of the breach.
The step OCR is watching right now #
A business associate’s exposure runs mostly through the Security Rule. A covered entity’s runs through both. OCR’s enforcement pattern shows where it is looking. Not encryption, not firewalls. How fast you hand over a chart.
The Right of Access Initiative began in 2019 with a $85,000 settlement against Bayfront Health St. Petersburg. It has not slowed down since.
What the Azul Vision case shows a covered entity #
Azul Vision, a California optometry and ophthalmology practice, settled with OCR in 2026. A patient had waited from January 2023 to January 2025, nearly two years, to receive her own medical records. That settlement marked OCR’s 55th action under the Right of Access Initiative.
“It should not be necessary for OCR to initiate a right of access investigation before a covered entity will provide an individual with access to their requested records.”
Paula M. Stannard, OCR DirectorAnnouncing the Azul Vision settlement
Azul Vision paid $50,000 and accepted a two-year corrective action plan. The plan requires the practice to rewrite its Privacy Rule policies and retrain its workforce. It also must send HHS a running log of every access request, with the dates attached. That log is the real cost. Two years of proving, request by request, that the clock gets met.
Fifty-five settlements is not an edge case. It is the single most repeated finding in Privacy Rule enforcement. The fix does not require new technology. It requires a workflow that starts the moment a request arrives instead of the moment paperwork clears.
| Patient right | Your deadline | One extension allowed |
|---|---|---|
| Access to their own records | 30 days | +30 days, written notice |
| Amendment of a record | 60 days | +30 days, written notice |
| Accounting of disclosures | 60 days | +30 days, written notice |
| Notify individuals of a breach | 60 days | No extension |
What a failure costs #
The same civil penalty structure applies whether the finding is a Security Rule gap. Or a blown Privacy Rule deadline. HHS adjusts the figures for inflation every January. The amounts below took effect on 28 January 2026. They apply to penalties OCR assesses on or after that date. All figures are USD.
| Culpability tier | Minimum per violation | Maximum per violation | Annual cap |
|---|---|---|---|
| Did not know, and reasonable diligence would not have found it | $145 | $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Where covered entities land in the top tier
The Azul Vision timeline is typical. A single missed request rarely draws willful neglect on its own. A pattern of missed requests is what moves a case from reasonable cause into willful neglect. That is especially true after a prior complaint put the organization on notice.
A rule that quietly reversed, and why it matters now #
In April 2024, HHS finalized a rule adding new protections for reproductive health information, including limits on disclosing it for criminal or civil investigations. Many compliance guides still describe it as current. It is not, mostly.
On 18 June 2025, the U.S. District Court for the Northern District of Texas vacated most of that rule. The vacatur applies nationwide. The standard Privacy Rule now governs reproductive health information again, the same as any other PHI. Did your organization build a separate reproductive health policy, an attestation process, or special disclosure restrictions for that 2024 rule? You can retire them now.
One piece survived. The Notice of Privacy Practices language covering substance use disorder records was not part of the vacated section. HHS set a compliance deadline of 16 February 2026 for that specific NPP update. Check your notice against that date, not against the reproductive health rule as a whole.
None of this changes state law. If your state gives reproductive health information stronger protection than the baseline Privacy Rule, that state law still applies. The vacatur removed a federal layer, not the state ones underneath it.
Frequently asked questions #
How fast do we have to respond to a patient’s records request?
30 days from receipt of the request. You get one 30-day extension. Send the patient written notice of the delay and a firm completion date. There is no separate clock for electronic versus paper records. You cannot require a specific form before the clock starts.
Can we charge a patient for copies of their records?
Only a reasonable, cost-based fee limited to labor for copying, supplies, and postage if mailed. You cannot bill for the time spent searching for or retrieving the records. You also cannot charge a flat per-page rate that exceeds your actual cost.
Is the 2024 HIPAA reproductive health rule still in effect?
Mostly no. A federal court vacated most of it nationwide on 18 June 2025. The standard Privacy Rule now governs reproductive health information again. One narrow piece survived: an NPP update covering substance use disorder records. It carries a compliance deadline of 16 February 2026. State laws that protect reproductive health information more strongly than HIPAA still apply.
Do we need a separate privacy official and security official?
Not necessarily. One person can hold both roles in a smaller organization. The Rule requires a named individual for each function. It allows no implicit designation, and no informal split across a team with no clear owner.
What happens if a business associate causes a breach of our patients’ data?
The business associate must notify you within 60 days of discovery. That does not end your obligation. You still have your own 60-day clock. Notify the affected individuals, HHS, and the media. Do this if the breach affects more than 500 people in one state or jurisdiction. Count all of it from when you learned of the breach.
Does SOC 2 or ISO 27001 satisfy our HIPAA obligations?
Neither is a legal substitute, and no HIPAA certification exists in any form. HHS states plainly that it does not endorse or recognize private certifications. A SOC 2 or ISO 27001 program gives you a structured way to run and evidence the Security Rule half of your obligations. The Privacy Rule duties in this guide sit outside either framework and need their own process.
Key takeaways #
- A covered entity runs the Security Rule and the Privacy Rule together. Vendors mostly carry only the first.
- Designate a privacy official and a security official by name, not by org chart.
- Patient access requests get 30 days, amendments get 60, both with one 30-day extension if you document it.
- OCR’s Right of Access Initiative has produced 55 settlements. It is the most consistently enforced Privacy Rule failure.
- A business associate’s breach notice to you starts your own 60-day clock. It does not end your obligation.
- A federal court vacated most of the 2024 reproductive health privacy rule nationwide in June 2025. Check your policies against the current baseline, not the 2024 rule.
- Penalties for uncorrected willful neglect start at $73,011 per violation in 2026, whichever rule the finding comes from.
Run the Privacy Rule process without the paper trail #
Nank.ai helps covered entities across Canada and the United States build the privacy program HIPAA requires. It also helps keep that program evidenced. A compliance manager tracks every request and every deadline. A corrective action plan never becomes your only proof of process.