> ## Documentation Index
> Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with HIPAA

> A practical guide to meeting HIPAA requirements for covered entities and business associates using Matproof.

# Getting Started with HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting the privacy and security of individually identifiable health information in the United States. HIPAA applies to **covered entities** (health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically) and their **business associates**.

HIPAA compliance is enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Matproof maps HIPAA requirements to controls, policies, and evidence workflows so you can demonstrate compliance during OCR audits and respond to breach investigations.

<Note>
  Activate HIPAA under **Settings - Frameworks - HIPAA**. Controls are pre-populated across the Privacy Rule, Security Rule, and Breach Notification Rule.
</Note>

***

## Am I in Scope?

| Entity Type            | Definition                                                                                    | Key Obligations                                                                            |
| ---------------------- | --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
| **Covered Entity**     | Health plans, healthcare clearinghouses, healthcare providers who transmit PHI electronically | Full compliance with Privacy, Security, and Breach Notification Rules                      |
| **Business Associate** | Any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity  | Security Rule compliance, breach notification, Business Associate Agreement (BAA) required |

<Warning>
  If you handle Protected Health Information (PHI) for a US healthcare organization - even as a technology vendor or cloud provider - you are likely a business associate and must comply with HIPAA.
</Warning>

***

## HIPAA Rules in Matproof

<CardGroup cols={2}>
  <Card title="Privacy Rule" icon="lock">
    **Policies, Controls**

    Governs the use and disclosure of PHI. Requires a Notice of Privacy Practices, patient rights (access, amendment, accounting of disclosures), and minimum necessary standards.
  </Card>

  <Card title="Security Rule" icon="shield-halved">
    **Controls, Evidence**

    Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI). Includes risk analysis, access controls, audit controls, transmission security, and encryption.
  </Card>

  <Card title="Breach Notification Rule" icon="bell">
    **Incidents**

    Requires notification to affected individuals, HHS, and (for breaches affecting 500+ individuals) the media. Notification deadlines: 60 days for individuals and HHS, without unreasonable delay for business associates to covered entities.
  </Card>

  <Card title="Business Associate Agreements" icon="file-contract">
    **Vendor Risk**

    Track BAAs with all business associates. Ensure agreements include required provisions for PHI handling, breach notification, and termination.
  </Card>
</CardGroup>

***

## Security Rule Safeguards

The Security Rule organizes requirements into three categories:

### Administrative Safeguards

| Standard                         | Requirement                                                                               | Matproof Control          |
| -------------------------------- | ----------------------------------------------------------------------------------------- | ------------------------- |
| Security Management Process      | Risk analysis, risk management, sanction policy, information system activity review       | Risk Management, Controls |
| Assigned Security Responsibility | Designate a security official                                                             | People                    |
| Workforce Security               | Authorization, supervision, clearance procedures, termination procedures                  | People, Controls          |
| Information Access Management    | Access authorization, access establishment and modification                               | Controls                  |
| Security Awareness and Training  | Security reminders, malicious software protection, log-in monitoring, password management | People, Controls          |
| Security Incident Procedures     | Response and reporting                                                                    | Incidents                 |
| Contingency Plan                 | Data backup, disaster recovery, emergency mode operations, testing, criticality analysis  | Policies, Controls        |
| Evaluation                       | Periodic technical and nontechnical evaluation                                            | Audit Programs            |

### Physical Safeguards

| Standard                  | Requirement                                                                                        |
| ------------------------- | -------------------------------------------------------------------------------------------------- |
| Facility Access Controls  | Contingency operations, facility security plan, access control and validation, maintenance records |
| Workstation Use           | Policies for workstation use and security                                                          |
| Workstation Security      | Physical safeguards for workstations accessing ePHI                                                |
| Device and Media Controls | Disposal, media re-use, accountability, data backup and storage                                    |

### Technical Safeguards

| Standard                        | Requirement                                                                                         |
| ------------------------------- | --------------------------------------------------------------------------------------------------- |
| Access Control                  | Unique user identification, emergency access procedure, automatic logoff, encryption and decryption |
| Audit Controls                  | Mechanisms to record and examine activity in information systems containing ePHI                    |
| Integrity                       | Mechanisms to authenticate ePHI and protect against improper alteration or destruction              |
| Person or Entity Authentication | Verify the identity of persons seeking access to ePHI                                               |
| Transmission Security           | Integrity controls and encryption for ePHI transmitted over networks                                |

***

## Recommended Implementation Plan

<Steps>
  ### Step 1 - Conduct a risk analysis

  The Security Rule requires a thorough risk analysis as the foundation for all other safeguards:

  1. Go to **Risk Management - New Risk Assessment**
  2. Identify all systems that create, receive, maintain, or transmit ePHI
  3. Identify threats and vulnerabilities to each system
  4. Assess the likelihood and impact of each threat
  5. Document current safeguards and identify gaps
  6. Determine the risk level for each threat-vulnerability combination

  <Warning>
    Risk analysis is the single most common HIPAA deficiency cited in OCR enforcement actions. It must be thorough, documented, and updated regularly - not a one-time checkbox exercise.
  </Warning>

  ### Step 2 - Generate HIPAA policies

  Go to **Policies - Generate** and create the required HIPAA policy set:

  * Privacy Policy (Notice of Privacy Practices)
  * Information Security Policy
  * Access Control Policy
  * Incident Response and Breach Notification Policy
  * Business Continuity and Disaster Recovery Policy
  * Workforce Security and Training Policy
  * Device and Media Controls Policy

  Assign each policy to an owner and ensure management approval is documented.

  ### Step 3 - Implement Security Rule safeguards

  Work through the controls in **Controls - HIPAA**:

  1. Implement administrative safeguards (risk management, workforce security, access management, training)
  2. Implement physical safeguards (facility access, workstation security, device controls)
  3. Implement technical safeguards (access controls, audit logging, encryption, transmission security)
  4. For each control, document the implementation and link supporting evidence

  ### Step 4 - Business Associate management

  1. Go to **Vendor Risk** and identify all business associates (any entity handling PHI on your behalf)
  2. Ensure a signed BAA is in place for each business associate
  3. Upload BAAs as evidence against the relevant controls
  4. Conduct periodic assessments of business associate security practices
  5. Track BAA renewal dates and maintain a current register

  ### Step 5 - Workforce training

  1. Go to **People - Training**
  2. Assign HIPAA privacy and security training to all workforce members with access to PHI
  3. Provide role-specific training for staff with elevated access
  4. Track completion and document refresher training schedules
  5. Link training records as evidence against the Security Awareness and Training controls

  ### Step 6 - Breach notification setup

  Configure your breach response workflow:

  1. Go to **Incidents** and set up HIPAA breach classification criteria
  2. Define the breach risk assessment methodology (the four-factor test for determining if notification is required)
  3. Establish notification templates and workflows for individuals, HHS, and media (for breaches of 500+ records)
  4. Document the process for the annual submission of breaches affecting fewer than 500 individuals

  ### Step 7 - Audit and evaluation

  1. Go to **Audit Programs - New Audit - HIPAA**
  2. Conduct a periodic evaluation of your security safeguards (required by the Evaluation standard)
  3. Review audit log data from systems containing ePHI
  4. Document findings as Corrective Actions with remediation timelines
  5. Update your risk analysis based on audit findings and environmental changes
</Steps>

***

## Penalties

| Tier | Violation Type                             | Penalty per Violation | Annual Maximum |
| ---- | ------------------------------------------ | --------------------- | -------------- |
| 1    | Lack of knowledge                          | $137 - $68,928        | \$2,067,813    |
| 2    | Reasonable cause                           | $1,379 - $68,928      | \$2,067,813    |
| 3    | Willful neglect (corrected within 30 days) | $13,785 - $68,928     | \$2,067,813    |
| 4    | Willful neglect (not corrected)            | \$68,928+             | \$2,067,813    |

Penalty amounts are adjusted annually for inflation. Criminal penalties (up to \$250,000 and imprisonment) may apply for knowing misuse of PHI.

***

## Next Steps

* [Risk Management](/features/risk-management) - conducting your HIPAA risk analysis
* [Vendor Risk](/features/vendor-risk) - managing Business Associate Agreements
* [Incidents](/features/incidents) - configuring breach notification workflows
* [People](/features/people) - workforce training tracking and access management
