Skip to main content

Getting Started with HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting the privacy and security of individually identifiable health information in the United States. HIPAA applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically) and their business associates. HIPAA compliance is enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Matproof maps HIPAA requirements to controls, policies, and evidence workflows so you can demonstrate compliance during OCR audits and respond to breach investigations.
Activate HIPAA under Settings - Frameworks - HIPAA. Controls are pre-populated across the Privacy Rule, Security Rule, and Breach Notification Rule.

Am I in Scope?

If you handle Protected Health Information (PHI) for a US healthcare organization - even as a technology vendor or cloud provider - you are likely a business associate and must comply with HIPAA.

HIPAA Rules in Matproof

Privacy Rule

Policies, ControlsGoverns the use and disclosure of PHI. Requires a Notice of Privacy Practices, patient rights (access, amendment, accounting of disclosures), and minimum necessary standards.

Security Rule

Controls, EvidenceRequires administrative, physical, and technical safeguards to protect electronic PHI (ePHI). Includes risk analysis, access controls, audit controls, transmission security, and encryption.

Breach Notification Rule

IncidentsRequires notification to affected individuals, HHS, and (for breaches affecting 500+ individuals) the media. Notification deadlines: 60 days for individuals and HHS, without unreasonable delay for business associates to covered entities.

Business Associate Agreements

Vendor RiskTrack BAAs with all business associates. Ensure agreements include required provisions for PHI handling, breach notification, and termination.

Security Rule Safeguards

The Security Rule organizes requirements into three categories:

Administrative Safeguards

Physical Safeguards

Technical Safeguards



Penalties

Penalty amounts are adjusted annually for inflation. Criminal penalties (up to $250,000 and imprisonment) may apply for knowing misuse of PHI.

Next Steps

  • Risk Management - conducting your HIPAA risk analysis
  • Vendor Risk - managing Business Associate Agreements
  • Incidents - configuring breach notification workflows
  • People - workforce training tracking and access management