Skip to content

HIPAA Privacy Rule

What is HIPAA Privacy Rule?

HIPAA regulations that establish standards for the protection of individually identifiable health information held by covered entities and business associates.

Compliance and Regulatory

Each of these is named in at least one of the same controls as hipaa privacy rule. The number is how many controls name both.

What the standards actually require on hipaa privacy rule

Requirements naming hipaa privacy rule across 6 standards, quoted from the control text.

HITECH Act4 controls

HITECH coordination with HIPAA Privacy Rule + HIPAA Security Rule + 21st Century Cures Act + ONC. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - established 2000 + modified 2002 + significantly amended by HITECH 2009 + 2013 Omnibus Final Rule;

HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC · HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
MARS-E1 control

Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45...

MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E · MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

Implement policies authorizing access to ePHI consistent with applicable HIPAA Privacy Rule requirements. NIST recommends minimum necessary, role-based, and least-privilege access.

164.308(a)(4)(i) · Information Access Management (Standard)

Manage Business Associate relationships per HIPAA Security Rule 45 CFR 164.308(b) and HIPAA Privacy Rule 45 CFR 164.502(e). Obtain satisfactory assurances per a written contract or other arrangement (a Business Associate Agreement - BAA) that the business asso...

NISTSP66-4 · Business Associate Agreements (BAAs) and Third-Party ePHI Governance

Implement policies authorizing access to ePHI consistent with applicable HIPAA Privacy Rule requirements. NIST recommends minimum necessary, role-based, and least-privilege access.

164.308(a)(4)(i) · Information Access Management (Standard)

Handle privacy and sensitive content in logs + cloud/SaaS log considerations per NIST SP 800-92 Section 5.11 (Confidentiality and Privacy) + updates aligned with modern cloud-era practice + GDPR + CCPA + sectoral privacy law + HIPAA Privacy Rule.

NISTSP92-7 · Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations

Questions people ask about hipaa privacy rule

What is HIPAA Privacy Rule?
HIPAA regulations that establish standards for the protection of individually identifiable health information held by covered entities and business associates.
Why is HIPAA Privacy Rule important for compliance?
HIPAA Privacy Rule is a key concept in Compliance and Regulatory. Understanding hipaa privacy rule helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address HIPAA Privacy Rule?
HIPAA Privacy Rule appears in the requirement text of HITECH Act, MARS-E, HIPAA Security Rule, NIST SP 800-66, NIST SP 800-66 Rev 2. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about HIPAA Privacy Rule?
Explore our compliance framework pages to see how hipaa privacy rule applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how HIPAA Privacy Rule applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.