What is HIPAA Security? Understanding Healthcare Data Protection

8 minute read
Intermediate

HIPAA security rules govern electronic health information protection for healthcare organizations.

The HIPAA Security Rule: Technical Safeguards

The HIPAA Security Rule establishes the federal standards for protecting electronic protected health information (ePHI) — health information that is created, received, maintained, or transmitted in electronic form. It applies to covered entities — healthcare providers, health plans, and healthcare clearinghouses — and business associates who handle ePHI on their behalf.

The Security Rule is organized around three categories of safeguards: administrative, physical, and technical. Technical safeguards are the technology and policy controls directly relevant to cybersecurity. Required technical safeguards include access controls (unique user identification, emergency access procedures, automatic logoff, and encryption), audit controls (hardware and software activity recording), integrity controls (mechanisms to ensure ePHI has not been altered or destroyed), and transmission security (encryption of ePHI transmitted over electronic communications networks).

The Risk Analysis Requirement

The foundational requirement of the HIPAA Security Rule — and the one most frequently cited in enforcement actions — is the requirement to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability. The risk analysis is not a one-time exercise; it must be conducted when material changes to the environment occur and must be reviewed and updated periodically. Organizations that cannot produce a current risk analysis document are in violation of the most fundamental HIPAA Security Rule requirement, regardless of how many other security controls they have implemented.

HIPAA Enforcement and Breach Notification

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, the Department of Health and Human Services, and in some cases the media following the discovery of a breach of unsecured ePHI. Notification must occur without unreasonable delay and within 60 days of discovery. Breaches affecting 500 or more individuals in a state must be reported to prominent media outlets in that state.

HIPAA enforcement is conducted by the HHS Office for Civil Rights (OCR). Civil monetary penalties for HIPAA violations are tiered based on culpability, ranging from $137 per violation for unknowing violations to $2.07 million per violation for willful neglect not corrected within 30 days. Penalties are calculated per violation, per year of violation, with caps that can result in multi-million dollar settlements for significant breaches. The 2023 HHS settlement with Banner Health for $1.25 million for a breach affecting 2.8 million patients is a representative example of enforcement scale.

HIPAA Diligence for Healthcare M&A

For PE buyers acquiring healthcare organizations or businesses that handle PHI as business associates, HIPAA exposure is the dominant cyber due diligence consideration. The standard questions: What is the organization's most recent HIPAA Security Rule risk assessment, and what gaps did it surface? Is there documentation of completed Security Rule training for the workforce? What is the organization's breach history, and how were breaches reported and remediated? Are Business Associate Agreements in place with all vendors that handle PHI? What is the organization's HHS OCR enforcement history and current audit status? HIPAA findings in due diligence drive representations and warranties, pre-close remediation requirements, and in some cases escrow arrangements for potential OCR enforcement liability.

Related: Compliance Risk Assessment for HIPAA Programs

HIPAA Security Rule compliance programs benefit substantially from a formal compliance risk assessment that maps the specific Administrative, Physical, and Technical safeguards against the organization's current implementation state. For healthcare organizations subject to additional frameworks (HITRUST, state-level health information privacy laws, payment card data handling), the compliance risk assessment also identifies overlapping control requirements that can be addressed through unified programs rather than parallel work.

What is HIPAA Security?

HIPAA Security refers to the Security Rule under the US Health Insurance Portability and Accountability Act, which mandates administrative, physical, and technical safeguards for electronic protected health information. Any covered entity or business associate handling ePHI must implement risk assessments, access controls, audit logging, encryption where reasonable, and incident response procedures. HIPAA is enforced by the Department of Health and Human Services Office for Civil Rights through investigations and penalties up to $2 million per violation category per year.

How does HIPAA Security differ from the HIPAA Privacy Rule?

The Privacy Rule governs how protected health information can be used and disclosed across all formats including paper, oral, and electronic. The Security Rule specifically addresses ePHI and the technical and operational controls required to protect it. Most healthcare data breaches trigger both rules simultaneously, but the Security Rule is what cybersecurity programs are typically built against because it enumerates required safeguards.

What technical safeguards does HIPAA require?

HIPAA's technical safeguards cover access control with unique user IDs and emergency access procedures, audit controls that record and examine activity in systems handling ePHI, integrity controls to prevent improper alteration, person or entity authentication, and transmission security including encryption for data in transit. Encryption is technically addressable rather than required, but failing to encrypt ePHI is now near-impossible to defend during OCR investigations.

What tools and platforms support HIPAA compliance?

Cloud platforms like AWS, Azure, and Google Cloud offer HIPAA-eligible services under signed Business Associate Agreements. SIEM platforms including Microsoft Sentinel, Splunk, and LogRhythm provide the audit logging and monitoring required by the rule. Identity providers like Okta and Microsoft Entra ID handle authentication. Specialized compliance platforms including Vanta, Drata, and HITRUST manage evidence collection and continuous monitoring.

How do organizations achieve and maintain HIPAA compliance?

Compliance begins with a comprehensive risk analysis documenting where ePHI lives, who accesses it, and what threats it faces. Policies and procedures formalize each required safeguard, technical controls are deployed against the risk analysis, and workforce training ensures employees understand their obligations. Business Associate Agreements bind every vendor that touches ePHI. Annual risk assessments and ongoing monitoring maintain compliance over time.

What does HIPAA non-compliance cost?

Civil penalties tier from $137 per violation for unknowing violations to $68,928 for willful neglect not corrected, with annual maximums up to $2.1 million per violation category. Recent OCR settlements have ranged from $25,000 for small practices to over $16 million for major breaches involving large patient populations. Beyond fines, breach notification costs, state attorney general actions, and class action litigation regularly exceed the federal penalties.

What is the first step in HIPAA Security compliance?

Complete a thorough risk analysis covering every system, application, and vendor that creates, receives, maintains, or transmits ePHI. Most organizations underestimate the scope, missing shadow IT, business associates, and ancillary systems. The risk analysis becomes the foundation document OCR will request first during any investigation, so investing in a high-quality analysis pays off well before any breach occurs.

Real-World Example: Advocate Health Care — Laptops, PHI, and $5.55M

In 2017, HHS reached a $5.55 million settlement with Advocate Health Care Network — the largest HIPAA settlement at the time — following the theft of four unencrypted laptops that contained the ePHI of over 4 million patients. The investigation found that Advocate had failed to conduct an enterprise-wide risk analysis as required by the Security Rule, had insufficient security policies for removing hardware containing ePHI from facilities, and had failed to obtain business associate agreements with vendors who had access to PHI. The laptops were stolen from a business associate's office. The settlement amount reflected both the scale of affected individuals and the number of compliance failures underlying the breach.

$10.93M

Average cost of a healthcare data breach in 2023 — the highest of any industry sector and 53% higher than the cross-industry average. Healthcare's combination of sensitive data, regulatory liability, and operational criticality makes it the most expensive breach sector.

How Cloudskope Can Help

Cloudskope's healthcare sector cyber risk assessments include comprehensive HIPAA Security Rule evaluation: risk analysis adequacy, technical safeguard implementation, breach notification compliance history, and business associate agreement coverage. For PE sponsors acquiring healthcare organizations, HIPAA compliance assessment is a standard component of our M&A cyber due diligence program.

Where the gap is closure rather than documentation, Cloudskope SARTUS™ is the instrument: a six-day, fixed-fee engagement that spends three days finding what current controls missed across Microsoft 365, Azure, dark web exposure, and active compromise, and three days fixing it. Every finding lands in one risk register mapped to NIST SP 800-53 and the CIS Benchmarks, with the Security Rule safeguards crosswalked. The Rule requires a risk analysis. SARTUS™ delivers the analysis and the remediation in the same week, before the exposure becomes a reportable breach.