What Are the HIPAA Rules? Everything Healthcare Providers Must Know
- June 24, 2026
Table of Contents
pausing, and even fewer understand how those rules apply to every single person who touches patient data in their practice, including billing vendors, scribes, and virtual assistants.
The Health Insurance Portability and Accountability Act was originally introduced in 1996 to protect health insurance coverage for employees who lost or changed jobs. Over the decades, its scope expanded into the most consequential healthcare data compliance framework in the United States. Today, HIPAA governs every patient call your front desk answers, every chart entry your scribe completes, and every claim your billing team transmits. Getting it wrong, even unknowingly, carries penalties that can reach into the millions.
This guide breaks all three rules down plainly, practically, and completely.
The 3 Rules of HIPAA at a Glance
HIPAA’s regulatory framework hinges on three fundamental rules: the Privacy Rule, which puts patients in control of their health data by limiting unauthorized disclosure of Protected Health Information; the Security Rule, which targets electronic PHI specifically, demanding comprehensive safeguards across administrative, physical, and technical domains; and the Breach Notification Rule, which forces transparency when protection fails by requiring prompt notification to affected individuals, authorities, and sometimes the media.
These three rules are not separate obligations you manage in parallel; they are a chain. A lapse in security creates a breach. A breach activates notification requirements. A notification event almost always surfaces an underlying privacy violation. Every layer connects directly to the next.
Rule | What It Governs | Applies To |
Privacy Rule | All PHI – written, oral, and electronic | Covered entities and business associates |
Security Rule | Electronic PHI (ePHI) only | Covered entities and business associates |
Breach Notification Rule | Response obligations when PHI is exposed | Covered entities and business associates |
The HIPAA Privacy Rule: Patient Rights, PHI, and the Minimum Necessary Standard
The HIPAA Privacy Rule provides a federal floor of privacy standards that protects individuals’ health information by limiting the permissible uses and disclosure of such information by covered entities and business associates without authorization. It also gives individuals the rights to control how their health information is used and disclosed, to request copies of information maintained about them, and to request corrections when omissions or errors exist.
The Privacy Rule covers everything: a faxed referral, a verbal hallway conversation, an email that includes a patient’s name alongside an appointment date. PHI includes a wide range of sensitive data, such as social security numbers, credit card information, and medical history, including prescriptions, procedures, conditions, and diagnoses. If it identifies a patient and relates to their health, treatment, or payment for care, it is PHI regardless of what format it takes.
What the Minimum Necessary Standard Means in Practice
One of the most misunderstood Privacy Rule requirements is the minimum necessary standard. Covered entities must use, disclose, or request only the minimum necessary information for purposes such as treatment, payment, or required healthcare operations, and PHI must be disclosed only with the patient’s consent. A billing coordinator processing a cardiology claim does not need access to psychiatric records. A receptionist confirming a specialist referral does not need the patient’s full medication list.
This standard applies to every person interacting with PHI, in-house or remote. When a virtual medical assistant handles scheduling, call answering, or prior authorization follow-up, they are bound by the same minimum necessary requirements as your front desk staff. The difference is that well-trained VMAs arrive with those protocols documented from day one.
The Security Rule in HIPAA: Administrative, Physical, and Technical Safeguards
The Security Rule establishes a national set of security standards to protect certain health information that is maintained or transmitted in electronic form. A major goal of the Security Rule is to protect the security of individuals’ ePHI while allowing regulated entities to adopt new technologies that improve the quality and efficiency of healthcare.
Where the Privacy Rule governs all forms of PHI, the Security Rule is laser-focused on electronic data, anything stored in your EHR, transmitted through a patient portal, processed by billing software, or accessed remotely. The rule requires covered entities to implement three distinct categories of safeguards.
The three required safeguard categories under the HIPAA Security Rule:
- Administrative safeguards - Assign a privacy officer, manage workforce access controls, conduct regular HIPAA security training, establish incident response procedures, and maintain documented contingency plans
- Physical safeguards - Implement facility access controls, workstation use policies, and device and media disposal procedures to prevent unauthorized physical access to ePHI
- Technical safeguards - Enforce encryption, automatic logoff, audit controls, user authentication, and transmission security for all electronic systems containing ePHI
The Security Rule deliberately avoids mandating specific technologies. What it mandates is that all three safeguard categories exist, are documented, and are actively maintained and reviewed.
The Breach Notification Rule: When Something Goes Wrong
A HIPAA breach is any impermissible use or disclosure of PHI that compromises its privacy or security. Most providers picture ransomware attacks when they hear the word breach. The reality is far more routine. Common breach scenarios include:
- A fax containing patient information sent to the wrong number
- An unencrypted device like laptop, phone, USB drive, lost or stolen
- A staff member accessing records of a patient outside their assigned care
- An email with PHI copied to an unintended recipient
- A vendor's systems compromised without a signed BAA in place
Covered entities must notify the individuals whose unsecured PHI has been breached, and this notification must be provided without unreasonable delay in any case, no later than 60 days following the discovery of the breach. If a breach affects 500 or more individuals, the impacted organization must notify the Secretary of HHS within 60 days of discovery. If the breach affects 500 or more residents of a single state or jurisdiction, organizations must also notify prominent media outlets within 60 days of discovery.Â
Penalties range from $141 per violation for unknowing violations to a maximum annual cap of over $2.1 million for violations involving willful neglect that aren’t promptly corrected. “Unknowing” is not a defense that eliminates liability. It only determines which penalty tier applies.
The Privacy Rule and Security Rule Working Together
Together, the Privacy, Security, and Breach Notification Rules help to protect the privacy and security of protected health information. Most compliance failures do not start with a cyberattack. They start with a vendor who was never asked to sign a BAA. A staff member who wasn’t retrained after a workflow change. A system that was never audited after an EHR migration.
The 2013 Omnibus Rule extended direct liability for compliance with the Security Rule to business associates. That means your billing company, your transcription service, your EHR vendor, and your virtual assistant team are all independently accountable for HIPAA compliance, and so is your practice, for failing to verify and document theirs.Â
The Privacy Rule and Security Rule Working Together
Together, the Privacy, Security, and Breach Notification Rules help to protect the privacy and security of protected health information. Most compliance failures do not start with a cyberattack. They start with a vendor who was never asked to sign a BAA. A staff member who wasn’t retrained after a workflow change. A system that was never audited after an EHR migration.
The 2013 Omnibus Rule extended direct liability for compliance with the Security Rule to business associates. That means your billing company, your transcription service, your EHR vendor, and your virtual assistant team are all independently accountable for HIPAA compliance, and so is your practice, for failing to verify and document theirs.Â
How VirtualCare Assistants Protects Your Practice Under Every HIPAA Rule
Every VirtualCare Assistant is trained, documented, and audited before accessing a single piece of patient data. HIPAA compliance at VCA is not an onboarding checkbox; it is embedded into every workflow, every service, and every client engagement from day one.
Compliance Element | VirtualCare Assistants Standard |
HIPAA Training | 40+ hours per VMA, ongoing and documented |
Business Associate Agreement | Signed at onboarding – standard, not optional |
Compliance Oversight | Dedicated HIPAA Compliance Officer across all operations |
Working Environment | Secured environments with documented data protection protocols |
EHR Integration | Direct system access configured before a VMA’s first day |
Audit Cadence | Regular internal compliance audits across every service line |
Our VMAs operate under your practice’s minimum necessary protocols, follow your documented workflows, and handle patient data with the same standards your in-house staff is held to. No ramp-up on compliance. No assumptions about what your vendor may or may not have signed.
Ready to work with a HIPAA-compliant virtual medical assistant?
Frequently Asked Questions
The three rules are the Privacy Rule, the Security Rule, and the Breach Notification Rule. The Privacy Rule governs the use and disclosure of all PHI. The Security Rule governs protection of electronic PHI through administrative, physical, and technical safeguards. The Breach Notification Rule governs required notification when PHI is improperly accessed or disclosed.
The Privacy Rule covers all forms of PHI, including oral, written, and electronic, and focuses on patient rights and permissible disclosure. The Security Rule covers only electronic PHI and focuses specifically on the safeguards required to protect it. Both apply to covered entities and their business associates.
Covered entities, i.e., health plans, healthcare clearinghouses, and providers who transmit health information electronically and any business associate that creates, receives, maintains, or transmits PHI on their behalf. This includes billing companies, virtual medical assistants, EHR vendors, and transcription services.
Yes, without exception. Any VMA who accesses or handles PHI on behalf of your practice is a business associate under HIPAA. A signed BAA is legally required before they may begin any work involving patient data. At VirtualCare Assistants, a BAA is a standard component of every engagement, signed at onboarding.
The proposed updates eliminate the distinction between required and addressable safeguards, mandate encryption of ePHI at rest and in transit, require multi-factor authentication across all systems, and extend direct compliance liability to business associate subcontractors. Practices should begin assessing their current posture against these requirements now.
Dr. Shane Wilson
Table of Contents
- Follow Us
Let our experts handle scheduling, calls, documentation, and paperwork 24/7