04 HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a major U.S. healthcare privacy and security framework.
HIPAA governs how certain organizations and their service providers handle:
Protected Health Information
Electronic Protected Health Information
Healthcare Operations
Patient Information
Security of Health SystemsA practical HIPAA governance model looks like:
Applicability ↓Covered Entity / Business Associate ↓PHI Identification ↓Privacy Rule ↓Security Rule ↓Safeguards ↓Minimum Necessary ↓Individual Rights ↓Business Associate Governance ↓Risk Analysis ↓Breach Management ↓Documentation & EvidenceThe central question is:
Can the organization demonstrate that Protected Health Information is used, disclosed, accessed, stored, and protected in accordance with HIPAA requirements?
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain HIPAA.
-
Understand HIPAA applicability.
-
Identify Covered Entities.
-
Identify Business Associates.
-
Define PHI.
-
Define ePHI.
-
Understand the Privacy Rule.
-
Understand the Security Rule.
-
Understand Administrative Safeguards.
-
Understand Physical Safeguards.
-
Understand Technical Safeguards.
-
Understand the Minimum Necessary standard.
-
Understand individual rights.
-
Understand Business Associate Agreements.
-
Understand HIPAA risk analysis.
-
Understand breach notification.
-
Understand workforce access.
-
Understand security incident procedures.
-
Build HIPAA compliance artifacts.
-
Support HIPAA assessments and audits.
1. What Is HIPAA?
Section titled “1. What Is HIPAA?”HIPAA is a U.S. federal law originally enacted in:
1996It includes provisions relating to:
Healthcare Portability
Administrative Simplification
Privacy
Security
Breach NotificationFor GRC professionals, the most important areas are typically:
Privacy Rule
Security Rule
Breach Notification Rule2. HIPAA Is Not a General Privacy Law
Section titled “2. HIPAA Is Not a General Privacy Law”HIPAA does not apply to every organization simply because it handles health-related information.
Applicability depends heavily on:
Entity Type
Role
Healthcare Transaction
Business Relationship
Type of Information3. HIPAA Applicability
Section titled “3. HIPAA Applicability”Start with:
01 HIPAA Applicability AssessmentAsk:
Are we a Covered Entity?
Are we a Business Associate?
Do we create, receive, maintain,or transmit PHI?
Do we provide servicesto a Covered Entity?4. Covered Entities
Section titled “4. Covered Entities”Covered Entities generally fall into three major categories:
Health Plans
Healthcare Clearinghouses
Certain Healthcare Providers5. Healthcare Providers
Section titled “5. Healthcare Providers”Examples may include:
Hospitals
Clinics
Physicians
Pharmacies
Dentistswhere they meet applicable HIPAA conditions.
6. Health Plans
Section titled “6. Health Plans”Examples include certain:
Health Insurance Plans
HMOs
Government Health Programs
Employer-Sponsored Health Plansdepending on structure and scope.
7. Healthcare Clearinghouses
Section titled “7. Healthcare Clearinghouses”These entities process healthcare information into standardized formats or perform related transaction functions.
8. Business Associates
Section titled “8. Business Associates”A:
Business Associateis generally an organization or person that performs certain functions or services for a Covered Entity involving PHI.
9. Business Associate Examples
Section titled “9. Business Associate Examples”Examples can include:
Cloud Service Provider
Billing Company
IT Managed Service Provider
Analytics Provider
Legal Service Provider
Backup Providerwhen PHI is involved in the service.
10. Business Associate Chain
Section titled “10. Business Associate Chain”A common model:
Covered Entity ↓Business Associate ↓SubcontractorCertain subcontractors can also have HIPAA obligations.
11. Build HIPAA Entity Register
Section titled “11. Build HIPAA Entity Register”Create:
02 HIPAA Entity & Relationship RegisterUse:
| Entity | Role | Service | PHI Access | Agreement |
|---|
12. Protected Health Information
Section titled “12. Protected Health Information”PHI generally means:
Individually IdentifiableHealth Informationthat is created or received by a Covered Entity or Business Associate and relates to areas such as:
Health Condition
Healthcare Provision
Payment for Healthcare13. PHI Examples
Section titled “13. PHI Examples”Examples may include:
Patient Name + Diagnosis
Patient Email + Treatment
Medical Record Number
Insurance Information
Prescription Information
Billing Information14. Health Information Is Not Automatically PHI
Section titled “14. Health Information Is Not Automatically PHI”A fitness application may contain:
Heart Rate
Weight
Exercise Databut whether HIPAA applies depends on the relationship and entity involved.
15. Electronic PHI
Section titled “15. Electronic PHI”Electronic Protected Health Information is commonly called:
ePHIIt refers to PHI maintained or transmitted electronically.
Examples:
Electronic Health Record
Cloud Database
Email
Backup
Mobile Application
API16. PHI Inventory
Section titled “16. PHI Inventory”Create:
03 PHI / ePHI InventoryUse:
| Data | PHI? | ePHI? | System | Owner | Location |
|---|
17. PHI Data Flow
Section titled “17. PHI Data Flow”A practical flow:
Patient ↓Hospital Application ↓EHR ↓Billing Provider ↓Insurance PlanEach step should be governed.
18. Build PHI Data Flow Register
Section titled “18. Build PHI Data Flow Register”Create:
04 HIPAA PHI Data Flow RegisterUse:
| Source | Destination | PHI | Purpose | Protection |
|---|
19. HIPAA Privacy Rule
Section titled “19. HIPAA Privacy Rule”The Privacy Rule governs:
Uses
Disclosures
Individual Rights
Minimum Necessary
Privacy Practicesrelating to PHI.
20. Permitted Uses and Disclosures
Section titled “20. Permitted Uses and Disclosures”HIPAA allows certain uses and disclosures without individual authorization in specified circumstances.
A major operational category is:
Treatment
Payment
Healthcare Operationsoften abbreviated:
TPO21. Treatment
Section titled “21. Treatment”Example:
Doctor ↓Specialistsharing information for treatment.
22. Payment
Section titled “22. Payment”Example:
Hospital ↓Insurance Planfor billing and payment activities.
23. Healthcare Operations
Section titled “23. Healthcare Operations”Examples may include:
Quality Assessment
Training
Auditing
Business Planningsubject to applicable HIPAA requirements.
24. Authorization
Section titled “24. Authorization”Some uses or disclosures require individual authorization.
Do not assume:
We Have PHI ↓We Can Use Itfor Any Business Purpose25. Privacy Notice
Section titled “25. Privacy Notice”Covered Entities generally provide a:
Notice of Privacy Practicesor:
NPP26. Notice of Privacy Practices
Section titled “26. Notice of Privacy Practices”The notice explains areas such as:
How PHI May Be Used
Individual Rights
Organization Responsibilities
Contact Information27. Build HIPAA Notice Register
Section titled “27. Build HIPAA Notice Register”Create:
05 Notice of Privacy Practices RegisterUse:
| Notice | Audience | Version | Effective Date | Owner |
|---|
28. Minimum Necessary
Section titled “28. Minimum Necessary”One of HIPAA’s most important operational concepts is:
Minimum NecessaryOrganizations should generally limit certain uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose.
29. Minimum Necessary Example
Section titled “29. Minimum Necessary Example”Billing employee needs:
Patient Name
Insurance Details
Billing CodeThey may not need:
Complete Clinical Notes30. Minimum Necessary vs Least Privilege
Section titled “30. Minimum Necessary vs Least Privilege”These concepts overlap.
Least Privilegeis primarily a security concept.
Minimum Necessaryis a HIPAA privacy requirement.
Together:
User ↓Only Necessary PHI ↓Only Necessary Access31. Build Minimum Necessary Matrix
Section titled “31. Build Minimum Necessary Matrix”Create:
06 Minimum Necessary Access MatrixUse:
| Role | PHI Needed | Purpose | Access Level | Approval |
|---|
32. Workforce Access
Section titled “32. Workforce Access”Access to PHI should align with:
Job Role
Business Need
Minimum Necessary
Security Controls33. Access Lifecycle
Section titled “33. Access Lifecycle”Hire ↓Role Assignment ↓PHI Access ↓Review ↓Role Change ↓Termination34. Workforce Training
Section titled “34. Workforce Training”Workforce members should receive appropriate HIPAA training.
Training topics may include:
PHI
Permitted Uses
Minimum Necessary
Security
Incident Reporting
Patient Rights35. Individual Rights
Section titled “35. Individual Rights”HIPAA provides individuals with several rights relating to PHI.
Examples include rights to:
Access
Copies
Amendment
Accounting of Disclosures
Restrictions in Certain Cases
Confidential Communications36. Right of Access
Section titled “36. Right of Access”Individuals generally have rights to access PHI maintained in a designated record set, subject to applicable limitations.
37. Access Request Workflow
Section titled “37. Access Request Workflow”Request ↓Identity Verification ↓Locate Records ↓Review ↓Provide Access / Copy ↓Record Completion38. Build Individual Rights Register
Section titled “38. Build Individual Rights Register”Create:
07 HIPAA Individual Rights RegisterUse:
| Request | Type | Received | Due | Completed | Owner |
|---|
39. Amendment
Section titled “39. Amendment”An individual may request amendment of certain PHI.
The organization should have a process to:
Receive
Review
Approve / Deny
Document40. Accounting of Disclosures
Section titled “40. Accounting of Disclosures”Certain disclosures may need to be tracked so individuals can receive an accounting when applicable.
41. HIPAA Security Rule
Section titled “41. HIPAA Security Rule”The Security Rule applies specifically to:
ePHIand requires administrative, physical, and technical safeguards.
42. Three Safeguard Categories
Section titled “42. Three Safeguard Categories”Administrative Safeguards
Physical Safeguards
Technical Safeguards43. Administrative Safeguards
Section titled “43. Administrative Safeguards”These focus on:
Governance
Risk Management
Workforce Security
Policies
Incident Response
Contingency Planning44. Security Management Process
Section titled “44. Security Management Process”A key component is:
Risk Analysis ↓Risk Management45. Risk Analysis
Section titled “45. Risk Analysis”Organizations should identify risks to ePHI across:
Systems
Applications
Networks
Facilities
People
Third Parties46. HIPAA Risk Analysis Register
Section titled “46. HIPAA Risk Analysis Register”Create:
08 HIPAA Risk Analysis RegisterUse:
| Asset | Threat | Vulnerability | Likelihood | Impact | Risk |
|---|
47. Risk Analysis Should Be Enterprise-Wide
Section titled “47. Risk Analysis Should Be Enterprise-Wide”Weak:
Only EHR ReviewedStrong:
EHR
Cloud
Email
Backups
Mobile Devices
Network
Third Parties48. Risk Management
Section titled “48. Risk Management”After identifying risk:
Risk ↓Control
Mitigation
Owner
Due Date49. Assigned Security Responsibility
Section titled “49. Assigned Security Responsibility”Organizations should assign responsibility for development and implementation of security policies.
50. Workforce Security
Section titled “50. Workforce Security”Processes should help ensure:
Authorized Workforce ↓Appropriate Access51. Information Access Management
Section titled “51. Information Access Management”Access should be authorized based on:
Role
Need
Approval52. Security Awareness and Training
Section titled “52. Security Awareness and Training”Security awareness may address:
Passwords
Phishing
Malware
Incident Reporting
Device Security53. Security Incident Procedures
Section titled “53. Security Incident Procedures”Organizations should establish procedures to:
Identify
Respond
Mitigate
Documentsecurity incidents.
54. Contingency Planning
Section titled “54. Contingency Planning”HIPAA Security Rule governance includes planning for:
Backup
Disaster Recovery
Emergency Operations
Testing55. Backup
Section titled “55. Backup”ePHI should have appropriate backup protection.
Example:
EHR ↓Encrypted Backup ↓Separate Recovery Environment56. Disaster Recovery
Section titled “56. Disaster Recovery”Organizations should plan how to restore critical ePHI systems after disruption.
57. Emergency Mode Operations
Section titled “57. Emergency Mode Operations”Critical healthcare operations may need continuity during:
Cyberattack
Outage
Disaster
Infrastructure Failure58. Physical Safeguards
Section titled “58. Physical Safeguards”Physical safeguards protect:
Facilities
Workstations
Devices
Media59. Facility Access Controls
Section titled “59. Facility Access Controls”Control access to locations containing systems processing ePHI.
Examples:
Data Center
Server Room
Records Facility60. Workstation Use
Section titled “60. Workstation Use”Define appropriate use of workstations accessing ePHI.
61. Workstation Security
Section titled “61. Workstation Security”Controls may include:
Screen Lock
Device Encryption
Physical Positioning
Endpoint Security62. Device and Media Controls
Section titled “62. Device and Media Controls”Organizations should govern:
Laptop
USB Drive
Hard Disk
Backup Mediathat may contain ePHI.
63. Disposal
Section titled “63. Disposal”Before disposal:
ePHI ↓Securely Removed64. Media Reuse
Section titled “64. Media Reuse”Before a storage device is reused:
Previous ePHI ↓Securely Cleared65. Technical Safeguards
Section titled “65. Technical Safeguards”Technical safeguards protect ePHI using technology.
Key areas include:
Access Control
Audit Controls
Integrity
Authentication
Transmission Security66. Access Control
Section titled “66. Access Control”Technical systems should allow access only to authorized users.
Controls may include:
Unique User IDs
MFA
Role-Based Access
Emergency Access67. Unique User Identification
Section titled “67. Unique User Identification”Weak:
Shared Account:nurseStronger:
nurse-alice
nurse-bobsupporting accountability.
68. Emergency Access
Section titled “68. Emergency Access”Healthcare systems may require:
Emergency Access Procedurefor urgent situations.
69. Automatic Logoff
Section titled “69. Automatic Logoff”Automatic session termination may help reduce unauthorized access.
70. Encryption
Section titled “70. Encryption”HIPAA’s Security Rule includes encryption-related implementation considerations.
Organizations should evaluate encryption based on risk and applicable implementation requirements.
71. Audit Controls
Section titled “71. Audit Controls”Systems processing ePHI should support mechanisms to:
Record
Examine
Monitorsystem activity.
72. Audit Example
Section titled “72. Audit Example”User:doctor-a
Action:Viewed Patient Record
Time:10:0473. Build Audit Coverage Matrix
Section titled “73. Build Audit Coverage Matrix”Create:
09 HIPAA Audit Logging MatrixUse:
| System | Audit Enabled | Events | Retention | Owner |
|---|
74. Integrity Controls
Section titled “74. Integrity Controls”Protect ePHI against:
Improper Modification
Unauthorized Alteration
Destruction75. Authentication
Section titled “75. Authentication”Systems should verify that individuals or entities seeking access are who they claim to be.
76. Transmission Security
Section titled “76. Transmission Security”Protect ePHI transmitted over:
Internet
VPN
API
Email
Internal Networksas appropriate.
77. Example
Section titled “77. Example”Weak:
PHI ↓Unencrypted EmailStronger:
Secure Messaging
Encrypted Email
Secure Portaldepending on context.
78. Build HIPAA Safeguard Matrix
Section titled “78. Build HIPAA Safeguard Matrix”Create:
10 HIPAA Safeguard MatrixUse:
| Safeguard | Control | System | Owner | Evidence |
|---|
79. Required vs Addressable
Section titled “79. Required vs Addressable”HIPAA Security Rule implementation specifications are often categorized as:
Required
Addressable80. Addressable Does Not Mean Optional
Section titled “80. Addressable Does Not Mean Optional”A common mistake is:
Addressable=IgnoreWrong.
The organization should assess whether the specification is:
Reasonable and Appropriateand either:
Implement Itor document an appropriate alternative where permitted.
81. Documentation
Section titled “81. Documentation”For addressable specifications, maintain:
Risk Analysis
Decision
Alternative Control
Rationale82. Business Associate Agreements
Section titled “82. Business Associate Agreements”A Covered Entity engaging a Business Associate generally needs an appropriate:
Business Associate Agreementor:
BAA83. BAA Purpose
Section titled “83. BAA Purpose”A BAA defines obligations relating to:
Permitted PHI Use
Security
Breach Reporting
Subcontractors
Return / Destruction
Compliance84. Build Business Associate Register
Section titled “84. Build Business Associate Register”Create:
11 Business Associate RegisterUse:
| Business Associate | Service | PHI | BAA | Owner | Review |
|---|
85. Cloud Providers
Section titled “85. Cloud Providers”A cloud provider maintaining ePHI may be a Business Associate even when the provider cannot routinely view the encrypted information.
The role should be assessed based on service and applicable HIPAA guidance.
86. SaaS Provider Example
Section titled “86. SaaS Provider Example”Hospital ↓Cloud Scheduling Platform ↓Patient DataReview:
Business Associate Status
BAA
Security Controls
Incident Process87. Subcontractors
Section titled “87. Subcontractors”Business Associates should govern subcontractors that handle PHI.
Example:
Hospital ↓Billing Company ↓Cloud Hosting Provider88. Third-Party Risk
Section titled “88. Third-Party Risk”Vendor review should consider:
PHI Access
Security Controls
Breach History
Encryption
IAM
Audit Logs
Backup
Subcontractors89. Breach Notification Rule
Section titled “89. Breach Notification Rule”HIPAA also includes requirements relating to breaches of unsecured PHI.
90. Breach Definition
Section titled “90. Breach Definition”A breach generally involves impermissible:
Acquisition
Access
Use
Disclosureof PHI that compromises privacy or security, subject to applicable exceptions and assessment.
91. Breach Example
Section titled “91. Breach Example”Employee Laptop ↓Unencrypted ↓Contains 4,000 Patient Records ↓StolenThis requires structured breach assessment.
92. Breach Risk Assessment
Section titled “92. Breach Risk Assessment”Organizations should evaluate factors such as:
Nature of PHI
Unauthorized Person
Whether PHI Was Actually Acquired or Viewed
Extent of Mitigation93. Build Breach Assessment Register
Section titled “93. Build Breach Assessment Register”Create:
12 HIPAA Breach Assessment RegisterUse:
| Incident | PHI | Individuals | Risk | Notification | Status |
|---|
94. Breach Notification
Section titled “94. Breach Notification”Depending on the breach:
Individuals
HHS
Mediamay need notification under applicable HIPAA rules and thresholds.
95. Breach vs Security Incident
Section titled “95. Breach vs Security Incident”Not every:
Security Incidentautomatically becomes a:
Reportable HIPAA BreachPerform a documented assessment.
96. Security Incident Workflow
Section titled “96. Security Incident Workflow”Incident ↓Contain ↓PHI Involved? ↓Breach Assessment ↓Notification Decision ↓Remediation ↓Evidence97. Ransomware
Section titled “97. Ransomware”Ransomware affecting ePHI requires careful assessment.
Ask:
Was ePHI encrypted by attacker?
Was data accessed?
Was data exfiltrated?
Was availability affected?
What evidence exists?98. Email Misdelivery
Section titled “98. Email Misdelivery”Example:
Patient Report ↓Sent to Wrong PersonThis may be a privacy incident requiring HIPAA breach assessment.
99. De-Identification
Section titled “99. De-Identification”HIPAA provides pathways for de-identifying health information.
Once appropriately de-identified, information is treated differently under HIPAA.
100. De-Identification Approaches
Section titled “100. De-Identification Approaches”HIPAA recognizes methods commonly known as:
Safe Harbor
Expert Determination101. Safe Harbor
Section titled “101. Safe Harbor”Safe Harbor requires removal of specified identifiers and no actual knowledge that remaining information could identify the individual.
102. Expert Determination
Section titled “102. Expert Determination”A qualified expert applies statistical or scientific principles to determine that re-identification risk is very small.
103. De-Identification Register
Section titled “103. De-Identification Register”Create:
13 HIPAA De-Identification RegisterUse:
| Dataset | Method | Reviewer | Date | Intended Use |
|---|
104. HIPAA and Cloud Security
Section titled “104. HIPAA and Cloud Security”Cloud environments processing ePHI should be assessed across:
IAM
Encryption
Logging
Networking
Backup
Monitoring
Configuration105. Cloud Shared Responsibility
Section titled “105. Cloud Shared Responsibility”Example:
Cloud Provider→ Physical Infrastructure
Healthcare Organization→ IAM
Healthcare Organization→ Encryption Configuration
Healthcare Organization→ Security Groups
Healthcare Organization→ Application Controls106. HIPAA Does Not Make Cloud Secure Automatically
Section titled “106. HIPAA Does Not Make Cloud Secure Automatically”Weak:
Cloud ProviderHas HIPAA Offering ↓We Are CompliantWrong.
The customer remains responsible for its configuration and operations.
107. Mobile Devices
Section titled “107. Mobile Devices”Healthcare staff may access ePHI from:
Laptop
Tablet
Mobile PhoneEvaluate:
Encryption
MDM
Screen Lock
Remote Wipe
Application Security108. Email
Section titled “108. Email”Email containing PHI should be governed through:
Encryption
Approved Platform
Recipient Validation
Minimum Necessary109. Messaging Platforms
Section titled “109. Messaging Platforms”Do not assume consumer messaging applications are suitable for PHI.
Evaluate:
Security
Retention
Access
BAA
Audit Capability110. Backup and Recovery
Section titled “110. Backup and Recovery”Backups containing ePHI should be:
Encrypted
Access Controlled
Tested
Recoverable111. Backup Testing
Section titled “111. Backup Testing”Create evidence showing:
Backup Completed
Restore Tested
Recovery Time
Issues112. Contingency Plan
Section titled “112. Contingency Plan”Create:
14 HIPAA Contingency Plan RegisterUse:
| System | Backup | Recovery | Emergency Mode | Last Test |
|---|
113. Security Risk Analysis Example
Section titled “113. Security Risk Analysis Example”Asset:
EHRThreat:
Credential TheftVulnerability:
No MFAImpact:
Unauthorized Accessto Patient RecordsRisk:
High114. Risk Treatment
Section titled “114. Risk Treatment”Correction:
Enable MFACorrective action:
Enterprise Authentication Standard
Continuous MFA Monitoring115. HIPAA Compliance Evidence
Section titled “115. HIPAA Compliance Evidence”Typical evidence includes:
Policies
Risk Analysis
Access Reviews
Training
BAAs
Audit Logs
Incident Records
Backup Tests
Security Assessments
Rights Requests116. Build HIPAA Evidence Register
Section titled “116. Build HIPAA Evidence Register”Create:
15 HIPAA Evidence RegisterUse:
| Control | Evidence | Source | Owner | Frequency |
|---|
117. HIPAA Control Testing
Section titled “117. HIPAA Control Testing”A GRC analyst may test:
Risk Analysis
Access Controls
Training
Audit Logs
BAAs
Incident Procedures
Backup
Individual Rights
Minimum Necessary118. Test — Access Control
Section titled “118. Test — Access Control”Population:
150 EHR UsersSample:
30Verify:
Role
Approval
Access Level
MFA
Employment Status119. Test — Termination
Section titled “119. Test — Termination”Population:
40 Departed EmployeesResult:
38 Disabled Same Day
2 Disabled After 5 DaysPotential:
Workforce Security Gap120. Test — Minimum Necessary
Section titled “120. Test — Minimum Necessary”Billing role currently has:
Full Clinical Record AccessAsk:
Is Full Access Necessary?If not:
Minimum Necessary Gap121. Test — Audit Logging
Section titled “121. Test — Audit Logging”EHR servers:
12Central logging:
10Gap:
2 SystemsNot Logging Centrally122. Test — BAA
Section titled “122. Test — BAA”Critical vendors:
20Valid BAAs:
18Potential:
Business AssociateGovernance Gap123. Test — Risk Analysis
Section titled “123. Test — Risk Analysis”Last enterprise HIPAA risk analysis:
3 Years AgoSince then:
Cloud Migration
New EHR
New Mobile AppPotential:
Risk AnalysisOutdated124. Test — Backup
Section titled “124. Test — Backup”Policy:
Quarterly Restore TestEvidence:
Q1 ✓
Q2 ✓
Q3 ✗
Q4 ✓Potential:
Contingency Control Gap125. Test — Training
Section titled “125. Test — Training”Workforce:
500Completed required training:
462Potential:
38 Workforce MembersWithout Required Training126. HIPAA Gap Register
Section titled “126. HIPAA Gap Register”Create:
16 HIPAA Compliance Gap RegisterUse:
| Gap | HIPAA Area | Risk | Severity | Owner | Due |
|---|
127. Root Cause Example — Missing BAA
Section titled “127. Root Cause Example — Missing BAA”Problem:
Cloud VendorHandles ePHI
No BAAWhy?
Vendor PurchasedDirectly by DepartmentWhy?
Procurement HasNo HIPAA TriggerRoot cause:
Vendor onboarding does not identify suppliers that create, receive, maintain, or transmit PHI.
128. Correction
Section titled “128. Correction”Execute Appropriate BAA129. Corrective Action
Section titled “129. Corrective Action”Add HIPAA Screeningto Procurement Workflow130. Root Cause Example — Excessive EHR Access
Section titled “130. Root Cause Example — Excessive EHR Access”Problem:
Billing StaffCan Access Clinical NotesWhy?
Role TemplateGrants Full RecordRoot cause:
EHR access roles were designed around technical convenience rather than minimum necessary requirements.
131. Corrective Action
Section titled “131. Corrective Action”Redesign Access Roles
Perform Full Access Review
Monitor Privileged Access132. HIPAA Dashboard
Section titled “132. HIPAA Dashboard”Track:
| Metric | Target |
|---|---|
| ePHI Systems Inventoried | 100% |
| Critical Risks With Treatment | 100% |
| Workforce Training | 100% |
| Business Associates With BAA | 100% |
| Privileged MFA Coverage | 100% |
| Required Audit Logging | 100% |
| Overdue High Risks | 0 |
| Restore Tests Completed | 100% |
133. HIPAA KPI — Training
Section titled “133. HIPAA KPI — Training”Percentage of workforcecompleting requiredHIPAA training134. HIPAA KPI — BAA
Section titled “134. HIPAA KPI — BAA”Percentage of Business Associateswith current appropriateagreements135. HIPAA KRI — Access
Section titled “135. HIPAA KRI — Access”Users with PHI accessbeyond role requirement136. HIPAA KRI — Risk
Section titled “136. HIPAA KRI — Risk”High-risk HIPAA findingspast remediation target137. HIPAA KRI — Logging
Section titled “137. HIPAA KRI — Logging”ePHI systemswithout requiredaudit coverage138. HIPAA KRI — Vendor
Section titled “138. HIPAA KRI — Vendor”Critical vendorshandling PHIwithout appropriate BAA139. Practical Activity — HIPAA Applicability
Section titled “139. Practical Activity — HIPAA Applicability”Use fictional organization:
HealthCloudServices:
Cloud Hosting
Patient Portal
Analytics
Backup
BillingDetermine:
Covered Entity?
Business Associate?
Subcontractor?
No HIPAA Role?for each relevant organization.
140. Practical Activity — PHI Inventory
Section titled “140. Practical Activity — PHI Inventory”Classify:
Patient Name
Diagnosis
Medical Record Number
IP Address
Insurance Number
Appointment Date
Employee PayrollDetermine:
PHI?
ePHI?
Why?141. Practical Activity — Minimum Necessary
Section titled “141. Practical Activity — Minimum Necessary”Roles:
Doctor
Nurse
Billing Specialist
IT Administrator
ReceptionistDefine appropriate PHI access for each.
142. Practical Activity — Risk Analysis
Section titled “142. Practical Activity — Risk Analysis”System:
Patient PortalThreats:
Credential Theft
API Attack
Misconfiguration
Data LeakageBuild:
Threat
Vulnerability
Likelihood
Impact
Risk
Control143. Practical Activity — Business Associate Review
Section titled “143. Practical Activity — Business Associate Review”Vendor:
Cloud Backup ProviderStores encrypted ePHI.
Assess:
BA Status
BAA
Encryption
IAM
Logging
Subcontractors
Incident Notification144. Practical Activity — Breach
Section titled “144. Practical Activity — Breach”Scenario:
Unencrypted Laptop ↓Stolen ↓8,000 Patient RecordsAssess:
PHI
Risk
Containment
Breach Analysis
Notification
Remediation145. Practical Activity — Cloud Misconfiguration
Section titled “145. Practical Activity — Cloud Misconfiguration”A storage bucket containing:
Patient Lab Reportsis accidentally made public for:
6 HoursDetermine:
Incident Classification
Affected Individuals
Evidence
Containment
Breach Analysis
Corrective Action146. Practical Activity — Individual Access Request
Section titled “146. Practical Activity — Individual Access Request”Patient requests:
Give Me a Copyof My Medical RecordBuild:
Identity Verification ↓Record Discovery ↓Review ↓Response ↓Evidence147. Practical Activity — Audit Log Review
Section titled “147. Practical Activity — Audit Log Review”User:
nurse-04viewed:
347 Patient Recordsin:
20 MinutesDetermine:
Legitimate Workflow?
Minimum Necessary?
Account Compromise?
Privacy Incident?HIPAA Operational Checklist
Section titled “HIPAA Operational Checklist”Applicability
Section titled “Applicability”-
Covered Entity status assessed.
-
Business Associate status assessed.
-
subcontractor relationships identified.
-
applicable HIPAA functions documented.
-
PHI inventory maintained.
-
ePHI systems identified.
-
PHI data flows documented.
-
storage locations known.
Privacy Rule
Section titled “Privacy Rule”-
permitted uses documented.
-
authorization process defined.
-
NPP maintained.
-
minimum necessary implemented.
-
individual rights supported.
Workforce
Section titled “Workforce”-
workforce access approved.
-
role-based access defined.
-
termination access removed.
-
workforce training completed.
-
sanctions process defined.
Risk Analysis
Section titled “Risk Analysis”-
ePHI systems assessed.
-
threats identified.
-
vulnerabilities identified.
-
risks rated.
-
treatment plans assigned.
-
analysis updated after major change.
Administrative Safeguards
Section titled “Administrative Safeguards”-
security responsibility assigned.
-
access management established.
-
awareness program operating.
-
incident procedures established.
-
contingency plan maintained.
Physical Safeguards
Section titled “Physical Safeguards”-
facility access controlled.
-
workstation use governed.
-
devices protected.
-
media disposal controlled.
-
media reuse controlled.
Technical Safeguards
Section titled “Technical Safeguards”-
unique IDs implemented.
-
access controls enforced.
-
audit controls enabled.
-
authentication implemented.
-
transmission security addressed.
-
integrity controls assessed.
Business Associates
Section titled “Business Associates”-
Business Associates identified.
-
BAAs maintained.
-
subcontractors considered.
-
security reviewed.
-
incident responsibilities defined.
Breach Management
Section titled “Breach Management”-
breach process documented.
-
incidents assessed.
-
notification decisions recorded.
-
corrective action tracked.
Contingency
Section titled “Contingency”-
backups maintained.
-
restore tests performed.
-
disaster recovery documented.
-
emergency operations considered.
Evidence
Section titled “Evidence”-
policies retained.
-
risk analysis retained.
-
training evidence retained.
-
BAAs retained.
-
access-review evidence retained.
-
audit logs retained.
-
incident records retained.
148. Common HIPAA Mistakes
Section titled “148. Common HIPAA Mistakes”Mistake 1 — Any Health Data Equals HIPAA
Section titled “Mistake 1 — Any Health Data Equals HIPAA”HIPAA applicability depends on entity and relationship.
Mistake 2 — Business Associate Means Ordinary Vendor
Section titled “Mistake 2 — Business Associate Means Ordinary Vendor”Business Associate status depends on functions and PHI involvement.
Mistake 3 — Security Rule Covers All PHI
Section titled “Mistake 3 — Security Rule Covers All PHI”The Security Rule specifically focuses on ePHI.
Mistake 4 — Addressable Means Optional
Section titled “Mistake 4 — Addressable Means Optional”Addressable implementation specifications require documented evaluation.
Mistake 5 — Encryption Alone Equals HIPAA Compliance
Section titled “Mistake 5 — Encryption Alone Equals HIPAA Compliance”HIPAA also requires governance, risk analysis, access control, training, contingency planning, and other safeguards.
Mistake 6 — Risk Analysis Is Only a Vulnerability Scan
Section titled “Mistake 6 — Risk Analysis Is Only a Vulnerability Scan”Risk analysis must consider broader risks to ePHI.
Mistake 7 — Minimum Necessary Is Ignored
Section titled “Mistake 7 — Minimum Necessary Is Ignored”Users receive excessive access.
Mistake 8 — Vendor Has Security Certification, So No BAA Needed
Section titled “Mistake 8 — Vendor Has Security Certification, So No BAA Needed”Contractual HIPAA requirements still matter.
Mistake 9 — All Security Incidents Are Automatically Breaches
Section titled “Mistake 9 — All Security Incidents Are Automatically Breaches”A documented breach assessment is needed.
Mistake 10 — HIPAA Is Treated as Annual Audit Work
Section titled “Mistake 10 — HIPAA Is Treated as Annual Audit Work”Security and privacy controls must operate continuously.
149. Weak HIPAA Program
Section titled “149. Weak HIPAA Program”HIPAA Policy
Annual Training
Wait for Audit150. Strong HIPAA Program
Section titled “150. Strong HIPAA Program”Applicability ↓PHI Inventory ↓Privacy Controls ↓Risk Analysis ↓Administrative Safeguards ↓Physical Safeguards ↓Technical Safeguards ↓Business Associate Governance ↓Individual Rights ↓Incident & Breach Management ↓Continuous Monitoring151. GRC Analyst Responsibilities
Section titled “151. GRC Analyst Responsibilities”A GRC professional supporting HIPAA may:
-
Perform HIPAA applicability assessments.
-
maintain Covered Entity and Business Associate inventories.
-
maintain PHI and ePHI inventories.
-
maintain data-flow documentation.
-
coordinate HIPAA risk analysis.
-
track risk-treatment plans.
-
maintain safeguard mappings.
-
coordinate minimum-necessary reviews.
-
support workforce access reviews.
-
track HIPAA training.
-
maintain Business Associate registers.
-
review BAAs.
-
support breach assessments.
-
maintain individual-rights request records.
-
coordinate contingency-plan evidence.
-
test HIPAA controls.
-
track remediation.
-
prepare HIPAA dashboards.
-
support audit and regulatory requests.
GRC connects:
Privacy
Security
Legal
Clinical Operations
IT
IAM
Cloud
HR
Procurement
Business Associates
Internal Audit152. HIPAA Maturity Model
Section titled “152. HIPAA Maturity Model”Level 1 — Reactive
Section titled “Level 1 — Reactive”HIPAA Policy
Training
Incident ResponseLevel 2 — Documented
Section titled “Level 2 — Documented”PHI Inventory
Risk Analysis
BAA Register
Access ProceduresLevel 3 — Governed
Section titled “Level 3 — Governed”Control Testing
Risk Treatment
Audit Monitoring
Vendor AssuranceLevel 4 — Integrated
Section titled “Level 4 — Integrated”Automated Access Reviews
Central Logging
Continuous Risk Monitoring
Integrated Vendor GovernanceLevel 5 — Continuous HIPAA Assurance
Section titled “Level 5 — Continuous HIPAA Assurance”Dynamic ePHI Discovery
Continuous Control Validation
Automated Evidence
Real-Time Risk Monitoring153. HIPAA Mindset
Section titled “153. HIPAA Mindset”For every healthcare system ask:
Does HIPAA apply?
Are we a Covered Entityor Business Associate?
What PHI exists?
Where is ePHI stored?
Who can access it?
Is access minimum necessary?
How is access approved?
Are users individually identifiable?
Are actions logged?
Is transmission protected?
Have risks been analyzed?
Are backups tested?
Which vendors handle PHI?
Do they have appropriate BAAs?
What happens during an incident?
Could the event be a breach?
Can individuals exercise their rights?
Can we prove the controls operate?For every vendor ask:
Will This VendorCreate, Receive, Maintain,or Transmit PHI?For every user role ask:
What Is the Minimum PHIThis Role Actually Needs?For every new healthcare technology ask:
How Does This ChangeOur ePHI Risk?That is the practical mindset behind HIPAA governance.
Key Takeaways
Section titled “Key Takeaways”-
HIPAA is a U.S. healthcare privacy and security framework.
-
It does not apply to every organization handling health-related information.
-
Covered Entities include certain healthcare providers, health plans, and healthcare clearinghouses.
-
Business Associates perform certain functions or services involving PHI on behalf of Covered Entities.
-
PHI is individually identifiable health information within the applicable HIPAA relationship.
-
ePHI is PHI maintained or transmitted electronically.
-
The Privacy Rule governs uses, disclosures, individual rights, and minimum necessary.
-
The Security Rule protects ePHI through Administrative, Physical, and Technical Safeguards.
-
Risk analysis is a foundational HIPAA Security Rule activity.
-
Addressable implementation specifications are not simply optional.
-
Minimum Necessary limits access and disclosure to what is needed.
-
Business Associate Agreements are a major third-party governance control.
-
Audit controls help demonstrate access and activity involving ePHI.
-
HIPAA includes breach-notification requirements for applicable breaches of unsecured PHI.
-
Security incidents should undergo structured breach assessment.
-
De-identification can remove information from certain HIPAA PHI requirements when performed appropriately.
-
Cloud environments still require customer-side HIPAA security configuration and governance.
-
GRC coordinates risk analysis, safeguards, BAAs, evidence, testing, remediation, and assessment readiness.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is HIPAA?
-
Which organizations can be Covered Entities?
-
What is a Business Associate?
-
What is PHI?
-
What is ePHI?
-
What is the Privacy Rule?
-
What is the Security Rule?
-
What does Minimum Necessary mean?
-
What are the three Security Rule safeguard categories?
-
What is a HIPAA risk analysis?
-
What are Administrative Safeguards?
-
What are Physical Safeguards?
-
What are Technical Safeguards?
-
What is the difference between Required and Addressable?
-
What is a BAA?
-
Why do Business Associate subcontractors matter?
-
What is a HIPAA breach?
-
What is the purpose of breach risk assessment?
-
What are the two common HIPAA de-identification methods?
-
What role does GRC play in HIPAA compliance?
What’s Next?
Section titled “What’s Next?”➡️ Next: 05 — CCPA / CPRA
In the next lesson, you will move from healthcare-specific privacy into the California consumer privacy framework built around the California Consumer Privacy Act (CCPA) and its amendment through the California Privacy Rights Act (CPRA).
You will examine:
Applicability ↓Consumer & Personal Information ↓Sensitive Personal Information ↓Business / Service Provider / Contractor ↓Notice at Collection ↓Consumer Rights ↓Access & Deletion ↓Correction ↓Opt-Out of Sale / Sharing ↓Limit Use of Sensitive PI ↓Service Provider Governance ↓Retention ↓Security ↓California Privacy Protection AgencyYou will also build practical artifacts including a CCPA/CPRA Applicability Assessment, California Personal Information Inventory, Notice-at-Collection Register, Consumer Rights Register, Sale/Sharing Inventory, Sensitive PI Register, Service Provider Register, Retention Matrix, Privacy Request Tracker, and CCPA/CPRA Compliance Dashboard.