GRC Careers

HomeResourcesHIPAA

CS-108 · Compliance & Frameworks

HIPAA

The U.S. law that governs the privacy and security of protected health information.

Executive Summary

HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law that sets national standards for protecting sensitive health information. Its rules are enforced by the U.S. Department of Health and Human Services (HHS). The Privacy Rule governs how protected health information can be used and disclosed, and the Security Rule sets requirements for safeguarding health information held or transmitted in electronic form.

What It Is

HIPAA is a set of U.S. regulations that protect the confidentiality and security of health information. It applies to covered entities, which generally include health plans, health care clearinghouses, and most health care providers that transmit health information electronically, as well as to their business associates, which are vendors that handle protected health information on their behalf. Protected health information, often abbreviated PHI, is individually identifiable health information, and when it is in electronic form it is referred to as ePHI. The two rules most relevant to security and compliance professionals are the Privacy Rule, which sets limits on how PHI may be used and shared, and the Security Rule, which requires administrative, physical, and technical safeguards for ePHI. The Breach Notification Rule requires notifying affected individuals and regulators after certain breaches.

Why It Matters

Health data is highly sensitive and highly targeted, and mishandling it carries legal, financial, and reputational consequences. HIPAA violations can lead to significant penalties and mandatory public reporting of large breaches, and business associate obligations mean the law reaches far beyond hospitals into technology vendors, billing companies, and cloud providers. For organizations that touch health data, HIPAA compliance is a condition of doing business. For professionals, HIPAA expertise is in demand across health care, health technology, and any vendor in the health supply chain, and it pairs naturally with broader security and privacy skills.

How It Works

Compliance starts with determining whether an organization is a covered entity or a business associate and mapping where PHI and ePHI live and flow. The Security Rule is risk-based: organizations must perform a risk analysis, then apply administrative safeguards (such as workforce training and access management), physical safeguards (such as facility and device controls), and technical safeguards (such as access controls, audit logging, and protections for data in transit and at rest). The Privacy Rule constrains how PHI may be used and disclosed and grants individuals rights over their information. Business associate agreements bind vendors to protect the PHI they handle. When a reportable breach occurs, the Breach Notification Rule sets out who must be told and when. Because the environment changes, the risk analysis and safeguards must be reviewed and updated over time.

Architecture Diagram

Scope: covered entities and business associates
Administrative safeguards (training, access, risk analysis)
Physical safeguards (facilities and devices)
Technical safeguards (access control, audit logging, encryption)
Privacy Rule limits and Breach Notification Rule
HIPAA safeguards protect PHI through administrative, physical, and technical layers, bound together by agreements and breach notification.

Visual Workflow

Determine whether the organization is a covered entity, a business associate, or both.Map where PHI and ePHI are created, stored, transmitted, and disposed of.Perform a risk analysis of threats to ePHI and document it.Apply administrative, physical, and technical safeguards to address the risks.Put business associate agreements in place with every vendor that handles PHI.Maintain training, monitor for breaches, and follow the Breach Notification Rule when required.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

GRC platform
Tracks HIPAA safeguards, risk analysis, and evidence
Access management and audit logging
Enforces least privilege and records who touched PHI
Encryption tools
Protects ePHI on devices and in transit
Vendor and BAA management system
Tracks business associates and their agreements

Industry Standards

HIPAA Security Rule
Requires administrative, physical, and technical safeguards for ePHI
HIPAA Privacy Rule
Governs permitted uses and disclosures of PHI and individual rights
NIST guidance on securing health information
Widely referenced help for implementing the Security Rule

Career Relevance

HIPAA is a core competency for GRC analysts, compliance analysts, security auditors, and CISOs in health care and health technology, who run risk analyses, implement safeguards, manage business associate agreements, and prepare for audits. Privacy officers and vendor risk teams also rely on it. For the privacy and AI governance professionals AI-Governance-Jobs.com serves, HIPAA is a leading example of how sensitive data is regulated and a template for governing health-related AI systems responsibly.

Interview Questions

Related Certifications

ISC2 HCISPP ISACA CISA Certified in Healthcare Privacy and Security (CHPS)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Does HIPAA apply to technology vendors?

Often yes. A vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is generally a business associate and must comply with applicable HIPAA requirements, usually under a business associate agreement.

What is the difference between PHI and ePHI?

PHI is protected health information, meaning individually identifiable health information in any form. ePHI is that same information in electronic form. The Security Rule specifically addresses safeguarding ePHI.

Is there a HIPAA certification for organizations?

HIPAA is a legal requirement rather than a formal government certification like some standards. Organizations demonstrate compliance through their risk analysis, safeguards, agreements, and documentation, and various third parties offer assessments, but there is no single official HIPAA certificate that guarantees compliance.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

ISC2 HCISPPISACA CISACertified in Healthcare Privacy and Security (CHPS)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: HIPAA
  3. Go deeper: GDPR
  4. Go deeper: PCI DSS
  5. Validate it: work toward ISC2 HCISPP
  6. Find the role: browse current openings

Related sheets

More in Compliance & Frameworks

Share this LinkedIn Facebook X Email