Skip to content

04 HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a major U.S. healthcare privacy and security framework.

HIPAA governs how certain organizations and their service providers handle:

Protected Health Information
Electronic Protected Health Information
Healthcare Operations
Patient Information
Security of Health Systems

A practical HIPAA governance model looks like:

Applicability
Covered Entity / Business Associate
PHI Identification
Privacy Rule
Security Rule
Safeguards
Minimum Necessary
Individual Rights
Business Associate Governance
Risk Analysis
Breach Management
Documentation & Evidence

The central question is:

Can the organization demonstrate that Protected Health Information is used, disclosed, accessed, stored, and protected in accordance with HIPAA requirements?

By the end of this lesson, you will be able to:

  • Explain HIPAA.

  • Understand HIPAA applicability.

  • Identify Covered Entities.

  • Identify Business Associates.

  • Define PHI.

  • Define ePHI.

  • Understand the Privacy Rule.

  • Understand the Security Rule.

  • Understand Administrative Safeguards.

  • Understand Physical Safeguards.

  • Understand Technical Safeguards.

  • Understand the Minimum Necessary standard.

  • Understand individual rights.

  • Understand Business Associate Agreements.

  • Understand HIPAA risk analysis.

  • Understand breach notification.

  • Understand workforce access.

  • Understand security incident procedures.

  • Build HIPAA compliance artifacts.

  • Support HIPAA assessments and audits.

HIPAA is a U.S. federal law originally enacted in:

1996

It includes provisions relating to:

Healthcare Portability
Administrative Simplification
Privacy
Security
Breach Notification

For GRC professionals, the most important areas are typically:

Privacy Rule
Security Rule
Breach Notification Rule

HIPAA does not apply to every organization simply because it handles health-related information.

Applicability depends heavily on:

Entity Type
Role
Healthcare Transaction
Business Relationship
Type of Information

Start with:

01 HIPAA Applicability Assessment

Ask:

Are we a Covered Entity?
Are we a Business Associate?
Do we create, receive, maintain,
or transmit PHI?
Do we provide services
to a Covered Entity?

Covered Entities generally fall into three major categories:

Health Plans
Healthcare Clearinghouses
Certain Healthcare Providers

Examples may include:

Hospitals
Clinics
Physicians
Pharmacies
Dentists

where they meet applicable HIPAA conditions.

Examples include certain:

Health Insurance Plans
HMOs
Government Health Programs
Employer-Sponsored Health Plans

depending on structure and scope.

These entities process healthcare information into standardized formats or perform related transaction functions.

A:

Business Associate

is generally an organization or person that performs certain functions or services for a Covered Entity involving PHI.

Examples can include:

Cloud Service Provider
Billing Company
IT Managed Service Provider
Analytics Provider
Legal Service Provider
Backup Provider

when PHI is involved in the service.

A common model:

Covered Entity
Business Associate
Subcontractor

Certain subcontractors can also have HIPAA obligations.

Create:

02 HIPAA Entity & Relationship Register

Use:

Entity Role Service PHI Access Agreement

PHI generally means:

Individually Identifiable
Health Information

that is created or received by a Covered Entity or Business Associate and relates to areas such as:

Health Condition
Healthcare Provision
Payment for Healthcare

Examples may include:

Patient Name + Diagnosis
Patient Email + Treatment
Medical Record Number
Insurance Information
Prescription Information
Billing Information

14. Health Information Is Not Automatically PHI

Section titled “14. Health Information Is Not Automatically PHI”

A fitness application may contain:

Heart Rate
Weight
Exercise Data

but whether HIPAA applies depends on the relationship and entity involved.

Electronic Protected Health Information is commonly called:

ePHI

It refers to PHI maintained or transmitted electronically.

Examples:

Electronic Health Record
Cloud Database
Email
Backup
Mobile Application
API

Create:

03 PHI / ePHI Inventory

Use:

Data PHI? ePHI? System Owner Location

A practical flow:

Patient
Hospital Application
EHR
Billing Provider
Insurance Plan

Each step should be governed.

Create:

04 HIPAA PHI Data Flow Register

Use:

Source Destination PHI Purpose Protection

The Privacy Rule governs:

Uses
Disclosures
Individual Rights
Minimum Necessary
Privacy Practices

relating to PHI.

HIPAA allows certain uses and disclosures without individual authorization in specified circumstances.

A major operational category is:

Treatment
Payment
Healthcare Operations

often abbreviated:

TPO

Example:

Doctor
Specialist

sharing information for treatment.

Example:

Hospital
Insurance Plan

for billing and payment activities.

Examples may include:

Quality Assessment
Training
Auditing
Business Planning

subject to applicable HIPAA requirements.

Some uses or disclosures require individual authorization.

Do not assume:

We Have PHI
We Can Use It
for Any Business Purpose

Covered Entities generally provide a:

Notice of Privacy Practices

or:

NPP

The notice explains areas such as:

How PHI May Be Used
Individual Rights
Organization Responsibilities
Contact Information

Create:

05 Notice of Privacy Practices Register

Use:

Notice Audience Version Effective Date Owner

One of HIPAA’s most important operational concepts is:

Minimum Necessary

Organizations should generally limit certain uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose.

Billing employee needs:

Patient Name
Insurance Details
Billing Code

They may not need:

Complete Clinical Notes

These concepts overlap.

Least Privilege

is primarily a security concept.

Minimum Necessary

is a HIPAA privacy requirement.

Together:

User
Only Necessary PHI
Only Necessary Access

Create:

06 Minimum Necessary Access Matrix

Use:

Role PHI Needed Purpose Access Level Approval

Access to PHI should align with:

Job Role
Business Need
Minimum Necessary
Security Controls
Hire
Role Assignment
PHI Access
Review
Role Change
Termination

Workforce members should receive appropriate HIPAA training.

Training topics may include:

PHI
Permitted Uses
Minimum Necessary
Security
Incident Reporting
Patient Rights

HIPAA provides individuals with several rights relating to PHI.

Examples include rights to:

Access
Copies
Amendment
Accounting of Disclosures
Restrictions in Certain Cases
Confidential Communications

Individuals generally have rights to access PHI maintained in a designated record set, subject to applicable limitations.

Request
Identity Verification
Locate Records
Review
Provide Access / Copy
Record Completion

Create:

07 HIPAA Individual Rights Register

Use:

Request Type Received Due Completed Owner

An individual may request amendment of certain PHI.

The organization should have a process to:

Receive
Review
Approve / Deny
Document

Certain disclosures may need to be tracked so individuals can receive an accounting when applicable.

The Security Rule applies specifically to:

ePHI

and requires administrative, physical, and technical safeguards.

Administrative Safeguards
Physical Safeguards
Technical Safeguards

These focus on:

Governance
Risk Management
Workforce Security
Policies
Incident Response
Contingency Planning

A key component is:

Risk Analysis
Risk Management

Organizations should identify risks to ePHI across:

Systems
Applications
Networks
Facilities
People
Third Parties

Create:

08 HIPAA Risk Analysis Register

Use:

Asset Threat Vulnerability Likelihood Impact Risk

47. Risk Analysis Should Be Enterprise-Wide

Section titled “47. Risk Analysis Should Be Enterprise-Wide”

Weak:

Only EHR Reviewed

Strong:

EHR
Cloud
Email
Backups
Mobile Devices
Network
Third Parties

After identifying risk:

Risk
Control
Mitigation
Owner
Due Date

Organizations should assign responsibility for development and implementation of security policies.

Processes should help ensure:

Authorized Workforce
Appropriate Access

Access should be authorized based on:

Role
Need
Approval

Security awareness may address:

Passwords
Phishing
Malware
Incident Reporting
Device Security

Organizations should establish procedures to:

Identify
Respond
Mitigate
Document

security incidents.

HIPAA Security Rule governance includes planning for:

Backup
Disaster Recovery
Emergency Operations
Testing

ePHI should have appropriate backup protection.

Example:

EHR
Encrypted Backup
Separate Recovery Environment

Organizations should plan how to restore critical ePHI systems after disruption.

Critical healthcare operations may need continuity during:

Cyberattack
Outage
Disaster
Infrastructure Failure

Physical safeguards protect:

Facilities
Workstations
Devices
Media

Control access to locations containing systems processing ePHI.

Examples:

Data Center
Server Room
Records Facility

Define appropriate use of workstations accessing ePHI.

Controls may include:

Screen Lock
Device Encryption
Physical Positioning
Endpoint Security

Organizations should govern:

Laptop
USB Drive
Hard Disk
Backup Media

that may contain ePHI.

Before disposal:

ePHI
Securely Removed

Before a storage device is reused:

Previous ePHI
Securely Cleared

Technical safeguards protect ePHI using technology.

Key areas include:

Access Control
Audit Controls
Integrity
Authentication
Transmission Security

Technical systems should allow access only to authorized users.

Controls may include:

Unique User IDs
MFA
Role-Based Access
Emergency Access

Weak:

Shared Account:
nurse

Stronger:

nurse-alice
nurse-bob

supporting accountability.

Healthcare systems may require:

Emergency Access Procedure

for urgent situations.

Automatic session termination may help reduce unauthorized access.

HIPAA’s Security Rule includes encryption-related implementation considerations.

Organizations should evaluate encryption based on risk and applicable implementation requirements.

Systems processing ePHI should support mechanisms to:

Record
Examine
Monitor

system activity.

User:
doctor-a
Action:
Viewed Patient Record
Time:
10:04

Create:

09 HIPAA Audit Logging Matrix

Use:

System Audit Enabled Events Retention Owner

Protect ePHI against:

Improper Modification
Unauthorized Alteration
Destruction

Systems should verify that individuals or entities seeking access are who they claim to be.

Protect ePHI transmitted over:

Internet
VPN
API
Email
Internal Networks

as appropriate.

Weak:

PHI
Unencrypted Email

Stronger:

Secure Messaging
Encrypted Email
Secure Portal

depending on context.

Create:

10 HIPAA Safeguard Matrix

Use:

Safeguard Control System Owner Evidence

HIPAA Security Rule implementation specifications are often categorized as:

Required
Addressable

A common mistake is:

Addressable
=
Ignore

Wrong.

The organization should assess whether the specification is:

Reasonable and Appropriate

and either:

Implement It

or document an appropriate alternative where permitted.

For addressable specifications, maintain:

Risk Analysis
Decision
Alternative Control
Rationale

A Covered Entity engaging a Business Associate generally needs an appropriate:

Business Associate Agreement

or:

BAA

A BAA defines obligations relating to:

Permitted PHI Use
Security
Breach Reporting
Subcontractors
Return / Destruction
Compliance

Create:

11 Business Associate Register

Use:

Business Associate Service PHI BAA Owner Review

A cloud provider maintaining ePHI may be a Business Associate even when the provider cannot routinely view the encrypted information.

The role should be assessed based on service and applicable HIPAA guidance.

Hospital
Cloud Scheduling Platform
Patient Data

Review:

Business Associate Status
BAA
Security Controls
Incident Process

Business Associates should govern subcontractors that handle PHI.

Example:

Hospital
Billing Company
Cloud Hosting Provider

Vendor review should consider:

PHI Access
Security Controls
Breach History
Encryption
IAM
Audit Logs
Backup
Subcontractors

HIPAA also includes requirements relating to breaches of unsecured PHI.

A breach generally involves impermissible:

Acquisition
Access
Use
Disclosure

of PHI that compromises privacy or security, subject to applicable exceptions and assessment.

Employee Laptop
Unencrypted
Contains 4,000 Patient Records
Stolen

This requires structured breach assessment.

Organizations should evaluate factors such as:

Nature of PHI
Unauthorized Person
Whether PHI Was Actually Acquired or Viewed
Extent of Mitigation

Create:

12 HIPAA Breach Assessment Register

Use:

Incident PHI Individuals Risk Notification Status

Depending on the breach:

Individuals
HHS
Media

may need notification under applicable HIPAA rules and thresholds.

Not every:

Security Incident

automatically becomes a:

Reportable HIPAA Breach

Perform a documented assessment.

Incident
Contain
PHI Involved?
Breach Assessment
Notification Decision
Remediation
Evidence

Ransomware affecting ePHI requires careful assessment.

Ask:

Was ePHI encrypted by attacker?
Was data accessed?
Was data exfiltrated?
Was availability affected?
What evidence exists?

Example:

Patient Report
Sent to Wrong Person

This may be a privacy incident requiring HIPAA breach assessment.

HIPAA provides pathways for de-identifying health information.

Once appropriately de-identified, information is treated differently under HIPAA.

HIPAA recognizes methods commonly known as:

Safe Harbor
Expert Determination

Safe Harbor requires removal of specified identifiers and no actual knowledge that remaining information could identify the individual.

A qualified expert applies statistical or scientific principles to determine that re-identification risk is very small.

Create:

13 HIPAA De-Identification Register

Use:

Dataset Method Reviewer Date Intended Use

Cloud environments processing ePHI should be assessed across:

IAM
Encryption
Logging
Networking
Backup
Monitoring
Configuration

Example:

Cloud Provider
→ Physical Infrastructure
Healthcare Organization
→ IAM
Healthcare Organization
→ Encryption Configuration
Healthcare Organization
→ Security Groups
Healthcare Organization
→ Application Controls

106. HIPAA Does Not Make Cloud Secure Automatically

Section titled “106. HIPAA Does Not Make Cloud Secure Automatically”

Weak:

Cloud Provider
Has HIPAA Offering
We Are Compliant

Wrong.

The customer remains responsible for its configuration and operations.

Healthcare staff may access ePHI from:

Laptop
Tablet
Mobile Phone

Evaluate:

Encryption
MDM
Screen Lock
Remote Wipe
Application Security

Email containing PHI should be governed through:

Encryption
Approved Platform
Recipient Validation
Minimum Necessary

Do not assume consumer messaging applications are suitable for PHI.

Evaluate:

Security
Retention
Access
BAA
Audit Capability

Backups containing ePHI should be:

Encrypted
Access Controlled
Tested
Recoverable

Create evidence showing:

Backup Completed
Restore Tested
Recovery Time
Issues

Create:

14 HIPAA Contingency Plan Register

Use:

System Backup Recovery Emergency Mode Last Test

Asset:

EHR

Threat:

Credential Theft

Vulnerability:

No MFA

Impact:

Unauthorized Access
to Patient Records

Risk:

High

Correction:

Enable MFA

Corrective action:

Enterprise Authentication Standard
Continuous MFA Monitoring

Typical evidence includes:

Policies
Risk Analysis
Access Reviews
Training
BAAs
Audit Logs
Incident Records
Backup Tests
Security Assessments
Rights Requests

Create:

15 HIPAA Evidence Register

Use:

Control Evidence Source Owner Frequency

A GRC analyst may test:

Risk Analysis
Access Controls
Training
Audit Logs
BAAs
Incident Procedures
Backup
Individual Rights
Minimum Necessary

Population:

150 EHR Users

Sample:

30

Verify:

Role
Approval
Access Level
MFA
Employment Status

Population:

40 Departed Employees

Result:

38 Disabled Same Day
2 Disabled After 5 Days

Potential:

Workforce Security Gap

Billing role currently has:

Full Clinical Record Access

Ask:

Is Full Access Necessary?

If not:

Minimum Necessary Gap

EHR servers:

12

Central logging:

10

Gap:

2 Systems
Not Logging Centrally

Critical vendors:

20

Valid BAAs:

18

Potential:

Business Associate
Governance Gap

Last enterprise HIPAA risk analysis:

3 Years Ago

Since then:

Cloud Migration
New EHR
New Mobile App

Potential:

Risk Analysis
Outdated

Policy:

Quarterly Restore Test

Evidence:

Q1 ✓
Q2 ✓
Q3 ✗
Q4 ✓

Potential:

Contingency Control Gap

Workforce:

500

Completed required training:

462

Potential:

38 Workforce Members
Without Required Training

Create:

16 HIPAA Compliance Gap Register

Use:

Gap HIPAA Area Risk Severity Owner Due

Problem:

Cloud Vendor
Handles ePHI
No BAA

Why?

Vendor Purchased
Directly by Department

Why?

Procurement Has
No HIPAA Trigger

Root cause:

Vendor onboarding does not identify suppliers that create, receive, maintain, or transmit PHI.

Execute Appropriate BAA
Add HIPAA Screening
to Procurement Workflow

130. Root Cause Example — Excessive EHR Access

Section titled “130. Root Cause Example — Excessive EHR Access”

Problem:

Billing Staff
Can Access Clinical Notes

Why?

Role Template
Grants Full Record

Root cause:

EHR access roles were designed around technical convenience rather than minimum necessary requirements.

Redesign Access Roles
Perform Full Access Review
Monitor Privileged Access

Track:

Metric Target
ePHI Systems Inventoried 100%
Critical Risks With Treatment 100%
Workforce Training 100%
Business Associates With BAA 100%
Privileged MFA Coverage 100%
Required Audit Logging 100%
Overdue High Risks 0
Restore Tests Completed 100%
Percentage of workforce
completing required
HIPAA training
Percentage of Business Associates
with current appropriate
agreements
Users with PHI access
beyond role requirement
High-risk HIPAA findings
past remediation target
ePHI systems
without required
audit coverage
Critical vendors
handling PHI
without appropriate BAA

139. Practical Activity — HIPAA Applicability

Section titled “139. Practical Activity — HIPAA Applicability”

Use fictional organization:

HealthCloud

Services:

Cloud Hosting
Patient Portal
Analytics
Backup
Billing

Determine:

Covered Entity?
Business Associate?
Subcontractor?
No HIPAA Role?

for each relevant organization.

Classify:

Patient Name
Diagnosis
Medical Record Number
IP Address
Insurance Number
Appointment Date
Employee Payroll

Determine:

PHI?
ePHI?
Why?

141. Practical Activity — Minimum Necessary

Section titled “141. Practical Activity — Minimum Necessary”

Roles:

Doctor
Nurse
Billing Specialist
IT Administrator
Receptionist

Define appropriate PHI access for each.

System:

Patient Portal

Threats:

Credential Theft
API Attack
Misconfiguration
Data Leakage

Build:

Threat
Vulnerability
Likelihood
Impact
Risk
Control

143. Practical Activity — Business Associate Review

Section titled “143. Practical Activity — Business Associate Review”

Vendor:

Cloud Backup Provider

Stores encrypted ePHI.

Assess:

BA Status
BAA
Encryption
IAM
Logging
Subcontractors
Incident Notification

Scenario:

Unencrypted Laptop
Stolen
8,000 Patient Records

Assess:

PHI
Risk
Containment
Breach Analysis
Notification
Remediation

145. Practical Activity — Cloud Misconfiguration

Section titled “145. Practical Activity — Cloud Misconfiguration”

A storage bucket containing:

Patient Lab Reports

is accidentally made public for:

6 Hours

Determine:

Incident Classification
Affected Individuals
Evidence
Containment
Breach Analysis
Corrective Action

146. Practical Activity — Individual Access Request

Section titled “146. Practical Activity — Individual Access Request”

Patient requests:

Give Me a Copy
of My Medical Record

Build:

Identity Verification
Record Discovery
Review
Response
Evidence

147. Practical Activity — Audit Log Review

Section titled “147. Practical Activity — Audit Log Review”

User:

nurse-04

viewed:

347 Patient Records

in:

20 Minutes

Determine:

Legitimate Workflow?
Minimum Necessary?
Account Compromise?
Privacy Incident?
  • Covered Entity status assessed.

  • Business Associate status assessed.

  • subcontractor relationships identified.

  • applicable HIPAA functions documented.

  • PHI inventory maintained.

  • ePHI systems identified.

  • PHI data flows documented.

  • storage locations known.

  • permitted uses documented.

  • authorization process defined.

  • NPP maintained.

  • minimum necessary implemented.

  • individual rights supported.

  • workforce access approved.

  • role-based access defined.

  • termination access removed.

  • workforce training completed.

  • sanctions process defined.

  • ePHI systems assessed.

  • threats identified.

  • vulnerabilities identified.

  • risks rated.

  • treatment plans assigned.

  • analysis updated after major change.

  • security responsibility assigned.

  • access management established.

  • awareness program operating.

  • incident procedures established.

  • contingency plan maintained.

  • facility access controlled.

  • workstation use governed.

  • devices protected.

  • media disposal controlled.

  • media reuse controlled.

  • unique IDs implemented.

  • access controls enforced.

  • audit controls enabled.

  • authentication implemented.

  • transmission security addressed.

  • integrity controls assessed.

  • Business Associates identified.

  • BAAs maintained.

  • subcontractors considered.

  • security reviewed.

  • incident responsibilities defined.

  • breach process documented.

  • incidents assessed.

  • notification decisions recorded.

  • corrective action tracked.

  • backups maintained.

  • restore tests performed.

  • disaster recovery documented.

  • emergency operations considered.

  • policies retained.

  • risk analysis retained.

  • training evidence retained.

  • BAAs retained.

  • access-review evidence retained.

  • audit logs retained.

  • incident records retained.

Mistake 1 — Any Health Data Equals HIPAA

Section titled “Mistake 1 — Any Health Data Equals HIPAA”

HIPAA applicability depends on entity and relationship.

Mistake 2 — Business Associate Means Ordinary Vendor

Section titled “Mistake 2 — Business Associate Means Ordinary Vendor”

Business Associate status depends on functions and PHI involvement.

Mistake 3 — Security Rule Covers All PHI

Section titled “Mistake 3 — Security Rule Covers All PHI”

The Security Rule specifically focuses on ePHI.

Addressable implementation specifications require documented evaluation.

Mistake 5 — Encryption Alone Equals HIPAA Compliance

Section titled “Mistake 5 — Encryption Alone Equals HIPAA Compliance”

HIPAA also requires governance, risk analysis, access control, training, contingency planning, and other safeguards.

Mistake 6 — Risk Analysis Is Only a Vulnerability Scan

Section titled “Mistake 6 — Risk Analysis Is Only a Vulnerability Scan”

Risk analysis must consider broader risks to ePHI.

Mistake 7 — Minimum Necessary Is Ignored

Section titled “Mistake 7 — Minimum Necessary Is Ignored”

Users receive excessive access.

Mistake 8 — Vendor Has Security Certification, So No BAA Needed

Section titled “Mistake 8 — Vendor Has Security Certification, So No BAA Needed”

Contractual HIPAA requirements still matter.

Mistake 9 — All Security Incidents Are Automatically Breaches

Section titled “Mistake 9 — All Security Incidents Are Automatically Breaches”

A documented breach assessment is needed.

Mistake 10 — HIPAA Is Treated as Annual Audit Work

Section titled “Mistake 10 — HIPAA Is Treated as Annual Audit Work”

Security and privacy controls must operate continuously.

HIPAA Policy
Annual Training
Wait for Audit
Applicability
PHI Inventory
Privacy Controls
Risk Analysis
Administrative Safeguards
Physical Safeguards
Technical Safeguards
Business Associate Governance
Individual Rights
Incident & Breach Management
Continuous Monitoring

A GRC professional supporting HIPAA may:

  • Perform HIPAA applicability assessments.

  • maintain Covered Entity and Business Associate inventories.

  • maintain PHI and ePHI inventories.

  • maintain data-flow documentation.

  • coordinate HIPAA risk analysis.

  • track risk-treatment plans.

  • maintain safeguard mappings.

  • coordinate minimum-necessary reviews.

  • support workforce access reviews.

  • track HIPAA training.

  • maintain Business Associate registers.

  • review BAAs.

  • support breach assessments.

  • maintain individual-rights request records.

  • coordinate contingency-plan evidence.

  • test HIPAA controls.

  • track remediation.

  • prepare HIPAA dashboards.

  • support audit and regulatory requests.

GRC connects:

Privacy
Security
Legal
Clinical Operations
IT
IAM
Cloud
HR
Procurement
Business Associates
Internal Audit
HIPAA Policy
Training
Incident Response
PHI Inventory
Risk Analysis
BAA Register
Access Procedures
Control Testing
Risk Treatment
Audit Monitoring
Vendor Assurance
Automated Access Reviews
Central Logging
Continuous Risk Monitoring
Integrated Vendor Governance
Dynamic ePHI Discovery
Continuous Control Validation
Automated Evidence
Real-Time Risk Monitoring

For every healthcare system ask:

Does HIPAA apply?
Are we a Covered Entity
or Business Associate?
What PHI exists?
Where is ePHI stored?
Who can access it?
Is access minimum necessary?
How is access approved?
Are users individually identifiable?
Are actions logged?
Is transmission protected?
Have risks been analyzed?
Are backups tested?
Which vendors handle PHI?
Do they have appropriate BAAs?
What happens during an incident?
Could the event be a breach?
Can individuals exercise their rights?
Can we prove the controls operate?

For every vendor ask:

Will This Vendor
Create, Receive, Maintain,
or Transmit PHI?

For every user role ask:

What Is the Minimum PHI
This Role Actually Needs?

For every new healthcare technology ask:

How Does This Change
Our ePHI Risk?

That is the practical mindset behind HIPAA governance.

  • HIPAA is a U.S. healthcare privacy and security framework.

  • It does not apply to every organization handling health-related information.

  • Covered Entities include certain healthcare providers, health plans, and healthcare clearinghouses.

  • Business Associates perform certain functions or services involving PHI on behalf of Covered Entities.

  • PHI is individually identifiable health information within the applicable HIPAA relationship.

  • ePHI is PHI maintained or transmitted electronically.

  • The Privacy Rule governs uses, disclosures, individual rights, and minimum necessary.

  • The Security Rule protects ePHI through Administrative, Physical, and Technical Safeguards.

  • Risk analysis is a foundational HIPAA Security Rule activity.

  • Addressable implementation specifications are not simply optional.

  • Minimum Necessary limits access and disclosure to what is needed.

  • Business Associate Agreements are a major third-party governance control.

  • Audit controls help demonstrate access and activity involving ePHI.

  • HIPAA includes breach-notification requirements for applicable breaches of unsecured PHI.

  • Security incidents should undergo structured breach assessment.

  • De-identification can remove information from certain HIPAA PHI requirements when performed appropriately.

  • Cloud environments still require customer-side HIPAA security configuration and governance.

  • GRC coordinates risk analysis, safeguards, BAAs, evidence, testing, remediation, and assessment readiness.

Before continuing, make sure you can answer:

  1. What is HIPAA?

  2. Which organizations can be Covered Entities?

  3. What is a Business Associate?

  4. What is PHI?

  5. What is ePHI?

  6. What is the Privacy Rule?

  7. What is the Security Rule?

  8. What does Minimum Necessary mean?

  9. What are the three Security Rule safeguard categories?

  10. What is a HIPAA risk analysis?

  11. What are Administrative Safeguards?

  12. What are Physical Safeguards?

  13. What are Technical Safeguards?

  14. What is the difference between Required and Addressable?

  15. What is a BAA?

  16. Why do Business Associate subcontractors matter?

  17. What is a HIPAA breach?

  18. What is the purpose of breach risk assessment?

  19. What are the two common HIPAA de-identification methods?

  20. What role does GRC play in HIPAA compliance?

➡️ Next: 05 — CCPA / CPRA

In the next lesson, you will move from healthcare-specific privacy into the California consumer privacy framework built around the California Consumer Privacy Act (CCPA) and its amendment through the California Privacy Rights Act (CPRA).

You will examine:

Applicability
Consumer & Personal Information
Sensitive Personal Information
Business / Service Provider / Contractor
Notice at Collection
Consumer Rights
Access & Deletion
Correction
Opt-Out of Sale / Sharing
Limit Use of Sensitive PI
Service Provider Governance
Retention
Security
California Privacy Protection Agency

You will also build practical artifacts including a CCPA/CPRA Applicability Assessment, California Personal Information Inventory, Notice-at-Collection Register, Consumer Rights Register, Sale/Sharing Inventory, Sensitive PI Register, Service Provider Register, Retention Matrix, Privacy Request Tracker, and CCPA/CPRA Compliance Dashboard.