HIPAA Compliance: Rules, Requirements, and Penalties (2026 Guide)

By Agrima Dwivedi
🗒️ Key Highlights
- HIPAA applies to covered entities (health plans, health care clearinghouses, and health care providers that conduct standard electronic transactions) and to the business associates that handle protected health information (PHI) for them.
- Its core rules are the Privacy Rule, the Security Rule for electronic PHI, the Breach Notification Rule, and the Enforcement Rule.
- Civil penalties now run from $145 to $73,011 per violation for the lowest tier, with a $2,190,294 calendar-year cap for identical violations, under the 2025 inflation adjustment published in January 2026.
- HHS proposed a major Security Rule update in January 2025; as of October 2026 it is still a proposal, and the current Security Rule remains in force.
Quick answer: HIPAA compliance means following the federal rules that protect patients' health information. If you are a health plan, a health care clearinghouse, a health care provider that bills or transacts electronically, or a vendor that handles PHI for one of them, you must limit how PHI is used and shared, protect electronic PHI with administrative, physical, and technical safeguards, notify patients and HHS of breaches, and sign business associate agreements with vendors that handle PHI.
This guide explains who HIPAA covers, what counts as PHI, the four main rules, current penalties, and the changes that took effect in 2025 and 2026.
What is HIPAA Compliance?
HIPAA compliance means following the national standards for protecting sensitive patient health information from disclosure without patient consent or knowledge.
For businesses handling healthcare data, this translates to implementing specific security measures, policies, and practices that safeguard electronic, physical, and oral patient information.
The requirements stem from real privacy concerns and affect real patients who trust healthcare providers with their most sensitive information. But what does this mean for your business operations?
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 and its rules apply to:
- Covered entities: health plans, health care clearinghouses, and health care providers that electronically conduct transactions covered by HIPAA standards, such as billing an insurer
- Business associates: people or organizations outside the covered entity's workforce that create, receive, maintain, or transmit PHI on its behalf, such as billing companies, cloud hosting providers, and IT or identity verification vendors with access to PHI, plus their subcontractors
Covered entities must have a written business associate agreement (BAA) with each business associate. A software vendor with no access to PHI is generally not a business associate.
What Counts as Protected Health Information?
PHI is individually identifiable health information held or transmitted by a covered entity or business associate: information about a person's health, care, or payment for care that identifies them or could reasonably be used to identify them. HIPAA's de-identification standard lists 18 identifiers that must be removed for data to be treated as de-identified under the "safe harbor" method:
- Name
- Address
- All dates related to an individual (except year)
- Telephone numbers
- Fax number
- Email address
- Social Security Number
- Medical record number
- Health plan beneficiary number
- Account number
- Certificate or license number
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URL
- Internet Protocol (IP) Address
- Finger or voice print
- Photographic image
- Any other characteristic that could uniquely identify the individual
In short, health information becomes PHI when it is linked to any of these identifiers and held by a covered entity or business associate. That includes billing records, appointment details, and lab results, in paper, electronic, or spoken form. Employment records that a covered entity holds in its role as an employer, and education records covered by FERPA, are excluded.
Now that you know what you need to handle, let’s see how you need to handle – the compliance requirements.
HIPAA Compliance Requirements
HIPAA comprises four main key provisions. These key rules work together to create a comprehensive framework for protecting patient information.
The Privacy Rule
This foundational rule establishes national standards for protecting medical records and personal health information. Healthcare providers must secure PHI across all forms – written, oral, and electronic.
Covered entities can use and disclose PHI for treatment, payment, and health care operations without the patient's authorization, but most other uses, such as marketing, need written authorization. They must give patients a Notice of Privacy Practices and let patients access their records, generally within 30 days of a request, with one 30-day extension allowed.
The rule also establishes the “minimum necessary” standard – meaning staff should only access the specific information needed for their job functions.
The Security Rule
This rule specifically addresses electronic PHI with three distinct safeguard categories.
- Administrative safeguards require organizations to have security management processes, including risk analysis and employee training.
- Physical safeguards mandate facility access controls and workstation security.
- Technical safeguards require access controls, audit trails, data integrity verification, and transmission security.
Each category includes both “required” and “addressable” specifications, allowing some flexibility in implementation based on organization size and capabilities.
The Enforcement Rule
The rule sets out how HHS's Office for Civil Rights (OCR) investigates complaints and compliance reviews and how it determines penalties. It defines four culpability tiers, with per-violation penalties adjusted for inflation each year (see the penalty table below).
OCR considers factors like the violation’s duration, the organization’s compliance history, and the number of affected individuals when determining penalties. Organizations have the right to challenge findings through formal hearings.
The Breach Notification Rule
The Breach Notification Rule requires healthcare organizations and their business associates to notify affected individuals, the U.S. Department of Health and Human Services (HHS), and, in some cases, the media, when a breach compromises unsecured protected health information (PHI).
Notices to individuals must go out without unreasonable delay and no later than 60 calendar days after the breach is discovered, and explain what happened, what data was involved, and what people can do to protect themselves.
Breaches affecting 500 or more people must also be reported to HHS within the same 60 days, and to prominent media outlets when more than 500 residents of a state or jurisdiction are affected. Breaches affecting fewer than 500 people can be logged and reported to HHS within 60 days after the end of the calendar year. Business associates must notify the covered entity no later than 60 days after discovering a breach.

HIPAA Violation Penalties
OCR enforces HIPAA's civil penalties, and the Department of Justice handles criminal cases. HHS published its 2025 inflation adjustment in January 2026, and those amounts apply through 2026 because the federal government canceled the 2026 adjustment.
| Culpability tier | Penalty per violation (2025-adjusted) | Calendar-year cap for identical violations |
|---|---|---|
| Did not know, and would not have known with reasonable diligence | $145 – $73,011 | $2,190,294 |
| Reasonable cause, not willful neglect | $1,461 – $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 – $73,011 | $2,190,294 |
| Willful neglect, not corrected within 30 days | $73,011 – $2,190,294 | $2,190,294 |
Under a 2019 notice of enforcement discretion, HHS applies lower annual caps to the first three tiers, originally $25,000, $100,000, and $250,000 and adjusted for inflation since. OCR also weighs the nature and extent of the violation, the harm caused, and the organization's compliance history. A single incident can involve many violations.
In severe cases, the Department of Justice may pursue criminal charges. These penalties break down into three tiers:
| Tier Level | Violation Type | Financial Penalty | Prison Term |
|---|---|---|---|
| Tier 1 | Knowingly obtaining or disclosing PHI | Up to $50,000 | Up to 1 year |
| Tier 2 | Obtaining PHI under false pretenses | Up to $100,000 | Up to 5 years |
| Tier 3 | Obtaining PHI for commercial advantage, personal gain, or malicious harm | Up to $250,000 | Up to 10 years |
What Changed in HIPAA in 2025 and 2026
- Security Rule update (proposed): HHS proposed a major overhaul of the Security Rule, published January 6, 2025, with more specific, documented, and regularly tested cybersecurity requirements. As of October 2026 it has not been finalized, and the existing Security Rule still applies.
- Reproductive health privacy rule vacated: a federal court in Texas vacated most of the 2024 reproductive health care privacy rule on June 18, 2025. Some Notice of Privacy Practices updates from that rule were left in place, with a February 16, 2026 compliance date.
- 42 CFR Part 2 alignment: compliance with the 2024 rule aligning substance use disorder record protections more closely with HIPAA was required by February 16, 2026.
- Risk analysis enforcement: OCR's Risk Analysis Initiative continues to produce settlements, many following ransomware attacks. In April 2026, OCR announced four ransomware settlements totaling $1.165 million. An accurate, thorough, and up-to-date risk analysis is the first thing OCR asks for.
Next steps
Identity verification can support several HIPAA safeguards, especially when patients access records or telehealth remotely. Signzy's tools that fit health care workflows include:
- Identity Verification API: confirms a patient's identity at registration or before record access, with an audit trail of each check.
- Face Match and Liveness Check APIs: add biometric checks for remote access to patient portals and telemedicine, helping prevent account takeover and impersonation.
- Criminal Screening API: supports background checks on staff who will have access to patient information.
If a verification vendor receives or handles PHI on your behalf, it is a business associate and you need a BAA in place. Book a demo to discuss your workflow.
FAQ
Who has to comply with HIPAA?
What's considered a HIPAA breach?
How long do you have to report a HIPAA breach?
What are the HIPAA penalties in 2026?
Do we need a HIPAA compliance officer?
Does an identity verification vendor need a business associate agreement?

Agrima Dwivedi
Agrima is an Associate Product Marketer at Signzy, currently working in the B2B fintech space. She brings over two years of experience in copywriting and content writing, which laid the foundation for product marketing. Today, she leverages both creative and strategic skills to drive go-to-market efforts and build user-focused marketing strategies.
Related Blogs
View all
What Is Biometric Verification? How It Works and How Secure It Is (2026)

Selfie Identity Verification: How It Works and Why Liveness Matters

Digital Identity in Financial Services: A Complete Guide (2026)

What Is a Customer Identification Program (CIP)? Requirements (2026)
The best in business
The global API marketplace for KYC, KYB, & AML
Explore the end-to-end verification stack trusted by 1,000 businesses.
Get in touch





