Getting Started with HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting the privacy and security of individually identifiable health information in the United States. HIPAA applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically) and their business associates. HIPAA compliance is enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Matproof maps HIPAA requirements to controls, policies, and evidence workflows so you can demonstrate compliance during OCR audits and respond to breach investigations.Activate HIPAA under Settings - Frameworks - HIPAA. Controls are pre-populated across the Privacy Rule, Security Rule, and Breach Notification Rule.
Am I in Scope?
HIPAA Rules in Matproof
Privacy Rule
Policies, ControlsGoverns the use and disclosure of PHI. Requires a Notice of Privacy Practices, patient rights (access, amendment, accounting of disclosures), and minimum necessary standards.
Security Rule
Controls, EvidenceRequires administrative, physical, and technical safeguards to protect electronic PHI (ePHI). Includes risk analysis, access controls, audit controls, transmission security, and encryption.
Breach Notification Rule
IncidentsRequires notification to affected individuals, HHS, and (for breaches affecting 500+ individuals) the media. Notification deadlines: 60 days for individuals and HHS, without unreasonable delay for business associates to covered entities.
Business Associate Agreements
Vendor RiskTrack BAAs with all business associates. Ensure agreements include required provisions for PHI handling, breach notification, and termination.
Security Rule Safeguards
The Security Rule organizes requirements into three categories:Administrative Safeguards
Physical Safeguards
Technical Safeguards
Recommended Implementation Plan
Penalties
Penalty amounts are adjusted annually for inflation. Criminal penalties (up to $250,000 and imprisonment) may apply for knowing misuse of PHI.
Next Steps
- Risk Management - conducting your HIPAA risk analysis
- Vendor Risk - managing Business Associate Agreements
- Incidents - configuring breach notification workflows
- People - workforce training tracking and access management