Skip to content
Clinician discussing paperwork with a patient

Privacy and Security Rules

HIPAA privacy and security in practice.

What the Privacy Rule permits, what the Security Rule requires you to safeguard, which vendors need an agreement, and what happens in the first seventy-two hours after a suspected breach.

Privacy Rule

Uses, disclosures and patient rights.

Treatment, payment and operations
PHI may be used and disclosed for these purposes without authorisation. Everything outside them generally requires a valid written authorisation, with defined exceptions such as public health reporting and disclosures required by law.
Minimum necessary
Except for treatment disclosures, you must limit use and disclosure to the minimum necessary to accomplish the purpose. In practice this means role-based access in your EHR, not one shared login with full rights.
Right of access
Individuals may inspect and obtain a copy of their designated record set, generally within thirty days, in the form and format requested where readily producible, subject to a reasonable cost-based fee. Access failures are among the most frequently enforced violations.
Notice of privacy practices
Must be provided at first service delivery, with a good faith effort to obtain written acknowledgement, prominently posted in your office and on your website.
Amendment and accounting
Individuals may request amendment of records and an accounting of certain disclosures. Both require a documented process and a response within defined timeframes.
Restriction on disclosure to health plans
Where an individual pays in full out of pocket for an item or service, you must honour a request to restrict disclosure of that information to their health plan.

Security Rule

Safeguarding electronic PHI.

The Security Rule is organised into administrative, physical and technical safeguards. Some specifications are required; others are addressable, meaning you must implement them or document why an alternative is reasonable.

Administrative safeguards
Security management process including the risk analysis and risk management plan, assigned security responsibility, workforce security and clearance, information access management, security awareness training, incident procedures, contingency planning and periodic evaluation.
Physical safeguards
Facility access controls, workstation use and security, and device and media controls covering disposal, re-use, accountability and backup. Server rooms, unattended reception workstations and departing staff laptops all fall here.
Technical safeguards
Unique user identification, emergency access procedure, automatic logoff, encryption and decryption, audit controls, integrity controls and transmission security. Encryption is addressable, but encrypted data that is lost may fall within the breach safe harbour.
Organisational requirements
Business associate contracts and, where applicable, requirements for group health plans. A vendor with access to PHI is a business associate whether or not anyone has signed anything.
Clinicians at a diagnostic imaging workstation

Business associates

Vendors that usually need an agreement.

  • Electronic health record and practice management vendors
  • Cloud hosting, backup and file storage providers
  • Billing companies and clearinghouses
  • Medical transcription services
  • Answering services and appointment reminder platforms
  • IT support and managed service providers
  • Document shredding and record storage companies
  • Email and secure messaging providers handling PHI
  • Collection agencies
  • Accountants, consultants and attorneys receiving PHI

Breach response

The first seventy-two hours.

  1. 01

    Contain and preserve

    Stop ongoing exposure, preserve logs and evidence, and record the timeline from the moment of discovery. Discovery starts the notification clock.

  2. 02

    Four-factor assessment

    Assess the nature and extent of the PHI, the unauthorised person involved, whether PHI was actually acquired or viewed, and the extent to which risk has been mitigated.

  3. 03

    Determine notification

    Unless there is a low probability of compromise, the incident is a breach. Notify affected individuals without unreasonable delay and no later than sixty days from discovery.

  4. 04

    Report and remediate

    Report to the Secretary — immediately for breaches affecting 500 or more individuals, annually for smaller ones — and document the corrective action taken.

Start with a security risk analysis.

It is the document most often missing and the one an investigator asks for first. We produce it with you, not for a filing cabinet.