Reference · LeakTrace Intelligence Team
HIPAA.
Health Insurance Portability and Accountability Act (45 CFR Parts 160, 162, and 164)
At a glance
- Jurisdiction
- US Federal
- Breach reporting deadline
- 60 days to affected individuals; 60 days to HHS for breaches of 500+
- Applies to
- Healthcare
- Authoritative source
- https://www.hhs.gov/hipaa/for-professionals/index.html
- Last updated
- August 5, 2026
## What it is
HIPAA is US federal law enacted in 1996 with regulations at 45 CFR Parts 160, 162, and 164. Enforced by the HHS Office for Civil Rights (OCR), it establishes national standards for the privacy, security, and breach notification of Protected Health Information (PHI) — individually identifiable health information held or transmitted by covered entities and business associates.
## Who it applies to
- **Covered entities:** Health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with HIPAA-standard transactions
- **Business associates:** Any person or entity that performs functions on behalf of a covered entity involving PHI (billing services, cloud storage, IT contractors, revenue cycle managers)
- **Subcontractors of business associates:** Same obligations flow downstream through Business Associate Agreements (BAAs)
## Key data protection requirements
- **Privacy Rule (45 CFR 164 Subpart E):** Governs use and disclosure of PHI; requires Notice of Privacy Practices, minimum necessary standard, patient access rights
- **Security Rule (45 CFR 164 Subpart C):** Requires administrative, physical, and technical safeguards for electronic PHI (ePHI); annual risk analysis is foundational
- **Breach Notification Rule (45 CFR 164 Subpart D):** Notification triggered by unauthorized acquisition, access, use, or disclosure of unsecured PHI
## Breach notification
Following discovery of a breach of unsecured PHI:
- **Individual notification:** Within 60 calendar days from discovery, first-class mail to affected individuals (or email if agreed)
- **HHS notification:**
- Breach of 500 or more individuals: notify HHS OCR concurrently with individuals (within 60 days)
- Breach of fewer than 500: log and report to HHS annually within 60 days of year-end
- **Media notification:** Breach of 500+ residents of any state or jurisdiction requires notice to prominent media outlets in that area
Business associates must notify covered entities without unreasonable delay, no later than 60 days from discovery (BAA typically shortens this).
## Penalties
Civil monetary penalties are tiered by culpability, indexed annually for inflation:
- **Tier 1 (no knowledge):** ~$137 to ~$68,928 per violation — [VERIFY 2026 indexed amounts]
- **Tier 2 (reasonable cause):** ~$1,379 to ~$68,928 per violation
- **Tier 3 (willful neglect — corrected):** ~$13,785 to ~$68,928 per violation
- **Tier 4 (willful neglect — not corrected):** ~$68,928 to ~$2,067,813 per violation
- **Annual cap per identical violation:** ~$2,067,813 per calendar year
Criminal penalties (18 USC 1320d-6) for knowing offences range from fines of up to $50,000 and one year imprisonment, escalating to $250,000 and 10 years for offences committed with intent to sell, transfer, or use for commercial advantage.
## How LeakTrace aligns
LeakTrace's continuous external-surface monitoring covers the exposures that most often lead to reportable HIPAA breaches — practitioner credential leaks, misconfigured cloud storage exposing ePHI, dark-web PHI listings, and business-associate posture drift. Evidence bundles are structured for HHS submission and follow-on litigation with chain-of-custody documentation.
Key provisions
- 45 CFR 164.502 — Minimum necessary standard
- Uses and disclosures of PHI must be limited to the minimum necessary to accomplish the intended purpose.
- 45 CFR 164.308 — Administrative safeguards
- Security management process, workforce security, access management, security awareness, contingency plans, evaluations.
- 45 CFR 164.312 — Technical safeguards
- Access control, audit controls, integrity, person or entity authentication, transmission security.
- 45 CFR 164.404 — Individual notification
- Notify affected individuals of a breach of unsecured PHI without unreasonable delay, no later than 60 calendar days.
- 45 CFR 164.408 — HHS notification
- Breaches of 500+ individuals reported concurrently with individual notification; smaller breaches logged annually.
- 45 CFR 164.410 — Business associate notification
- BAs notify covered entities without unreasonable delay, no later than 60 days from discovery.
Recent amendments & guidance
2024-04-26
HIPAA Privacy Rule to Support Reproductive Health Care Privacy — final rule strengthening protections for reproductive-health PHI. [VERIFY current litigation status].
2025-01-06
HIPAA Security Rule NPRM — proposed comprehensive Security Rule update with new technical safeguard requirements. [VERIFY final rule status].
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs