NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
What Is HIPAA Compliance? Covered Entities and BAAs
Learn

What Is HIPAA Compliance? Covered Entities and BAAs

·Alexander Sverdlov
The HIPAA scope test: covered entity, business associate, PHI and the BAA

Answering what HIPAA compliance means in practice starts with a simple idea: US federal law sets minimum standards for how protected health information is used, shared and secured, and it holds both the organisations that create that data and the vendors who process it accountable. This guide is written for compliance managers, CISOs and founders who need to know whether HIPAA applies to them, what obligations follow, and what happens when the rules are broken. It covers the two regulated parties, the three core rules, the four-tier penalty structure, and a practical programme you can actually run. It also explains why an EU-based software vendor can find itself squarely in scope.

What HIPAA is

HIPAA is the Health Insurance Portability and Accountability Act of 1996, a US federal statute administered by the Department of Health and Human Services (HHS). Its privacy and security requirements are implemented through regulations found in Title 45 of the Code of Federal Regulations, Parts 160 and 164. Enforcement sits with the HHS Office for Civil Rights (OCR). When people say "HIPAA compliance" they are usually referring to four connected rules.

  • The Privacy Rule governs how protected health information (PHI) may be used and disclosed, and gives individuals rights over their own records, including the right to access and request corrections.
  • The Security Rule sets standards for safeguarding electronic PHI (ePHI) through administrative, physical and technical measures.
  • The Breach Notification Rule requires notification when unsecured PHI is compromised.
  • The Enforcement Rule sets out how OCR investigates complaints, conducts compliance reviews and imposes penalties.

PHI is individually identifiable health information held or transmitted by a regulated party, in any form: paper, electronic or spoken. It includes obvious data such as diagnoses and test results, but also identifiers tied to a person's care, such as names, dates, contact details and account numbers when linked to health information.

Who must comply with HIPAA

HIPAA does not apply to every organisation that touches health data. It regulates two categories of party, and understanding which one you are is the single most important scoping question you can answer.

Covered entities

A covered entity is one of three defined types of organisation:

  • Health plans, including health insurers, HMOs, employer-sponsored group health plans and government programmes that pay for care.
  • Healthcare clearinghouses, which process health information from one format into another, for example billing services that convert data into standard electronic claims.
  • Healthcare providers who transmit any health information electronically in connection with a covered transaction, such as claims, eligibility checks or referrals. This is the key qualifier: a provider is only a covered entity if it conducts these electronic transactions. Most hospitals, clinics, pharmacies and physician practices do.

Business associates

A business associate is a person or organisation that performs a function or service for a covered entity that involves creating, receiving, maintaining or transmitting PHI. This is where most technology companies land. Cloud hosting providers, SaaS platforms, analytics vendors, medical billing companies, e-prescribing gateways, data storage firms and IT contractors are all commonly business associates. Subcontractors that a business associate uses to handle PHI are themselves business associates, so the obligations flow down the supply chain.

The mechanism that binds a business associate is the Business Associate Agreement (BAA). A covered entity must have a written BAA in place before allowing a business associate to handle PHI, and a business associate must have BAAs with its own subcontractors. The BAA sets out the permitted uses of PHI, requires the business associate to safeguard it, obliges it to report breaches, and requires the return or destruction of PHI when the relationship ends. Importantly, since the HITECH Act, business associates are directly liable for many HIPAA requirements, not merely contractually liable to the covered entity. OCR can act against them directly.

Venvera crosswalk reusing HIPAA and GDPR evidence across frameworks
Evidence entered once maps across HIPAA, GDPR and the frameworks they overlap.

Why an EU vendor can be in scope

HIPAA is US law, but it does not stop at the US border. Its obligations attach to the role you play, not to where you are located. If a company based in the European Union processes PHI on behalf of a US covered entity, it is a business associate and must sign a BAA and meet the applicable requirements. That means an EU software provider serving US healthcare customers carries HIPAA duties alongside its GDPR ones. The two regimes are not identical, but they overlap heavily on access control, encryption, breach reporting and vendor management, which is why a single platform that handles both can remove a lot of duplicated work.

What HIPAA requires

The obligations differ by rule, but they interlock. The Privacy Rule defines what you may do with PHI; the Security Rule defines how you must protect the electronic version of it; and the Breach Notification Rule defines what you must do when protection fails.

Under the Privacy Rule, a regulated party may only use or disclose PHI as permitted, and must apply the "minimum necessary" principle to most uses, meaning you limit access and disclosure to what is needed for the task. Individuals gain enforceable rights, including access to their records, the ability to request amendments, and an accounting of certain disclosures. Covered entities must also publish a Notice of Privacy Practices.

The Security Rule is organised into three families of safeguards, and this structure is worth memorising because it frames almost every compliance conversation:

  • Administrative safeguards: risk analysis and risk management, a designated security official, workforce training, access management and incident response procedures. The required risk analysis is the foundation of the whole rule.
  • Physical safeguards: facility access controls, workstation security and rules for the use and disposal of devices and media that hold ePHI.
  • Technical safeguards: access controls, audit logs, integrity controls, authentication and transmission security such as encryption.

The Security Rule labels some specifications as "required" and others as "addressable". Addressable does not mean optional; it means you must implement the safeguard, or document why it is not reasonable and appropriate and put an equivalent alternative in place. That documentation is itself part of compliance.

The HIPAA rules: Privacy, Security and Breach Notification

The Breach Notification Rule applies when unsecured PHI is acquired, accessed, used or disclosed in a way not permitted by the Privacy Rule. A regulated party must notify affected individuals without unreasonable delay and no later than 60 days after discovery. It must also notify HHS. For a breach affecting 500 or more residents of a state or jurisdiction, prominent local media must be notified as well, and HHS is notified without unreasonable delay. Smaller breaches are logged and reported to HHS on an annual basis. A business associate that discovers a breach must notify the covered entity so the covered entity can meet its own notification duties.

Penalties and enforcement

OCR investigates complaints, conducts audits and can impose civil monetary penalties. The Enforcement Rule sets four tiers based on the degree of culpability, and each tier carries a higher minimum per-violation amount, subject to an annual cap for all violations of an identical requirement. The tiers are:

  • Tier 1: the entity did not know, and by exercising reasonable diligence would not have known, of the violation.
  • Tier 2: the violation was due to reasonable cause and not wilful neglect.
  • Tier 3: wilful neglect that was corrected within the required period.
  • Tier 4: wilful neglect that was not corrected.

The specific dollar figures are adjusted for inflation over time, so you should confirm the current amounts against the official source rather than relying on a fixed number. Beyond civil penalties, the Department of Justice can pursue criminal charges for knowing misuse of PHI, and many resolutions include a corrective action plan that OCR monitors for years. In practice, the pattern OCR punishes most heavily is a failure to perform a proper risk analysis, followed by inaction after a known problem, which is why documentation and timely correction matter as much as the underlying controls.

How to actually comply

  1. Determine your role. Confirm in writing whether you are a covered entity, a business associate, or neither, because this decides which obligations apply.
  2. Map your PHI. Inventory where PHI is created, received, stored and transmitted, across systems, subcontractors and physical locations.
  3. Run a formal risk analysis. Assess threats and vulnerabilities to ePHI, and record the results. This is a required Security Rule step and the one OCR checks first.
  4. Remediate through a risk management plan. Prioritise and fix the gaps the analysis found, and track them to closure.
  5. Put the safeguards in place. Implement administrative, physical and technical controls, and document decisions on addressable specifications.
  6. Sign BAAs everywhere PHI flows. Ensure every vendor and subcontractor that touches PHI has a current, compliant agreement.
  7. Write and adopt policies. Cover privacy practices, access management, minimum necessary use, and sanctions for violations.
  8. Train your workforce. Provide role-appropriate training and refresh it, keeping records of who completed it.
  9. Prepare an incident and breach response. Define detection, assessment, notification timelines and roles before you need them.
  10. Review annually and after change. Repeat the risk analysis when systems, vendors or threats change, and keep an audit trail of the whole programme.
Mapping one control across HIPAA and other frameworks in one evidence library
One control, mapped across every framework it satisfies.

If you want to see the requirements mapped to concrete controls, evidence and BAAs in one place, read how Venvera handles HIPAA, or start with a free compliance check to see where you stand today.

HIPAA by the numbers: the 60-day breach deadline, safeguards and penalty tiers

Frequently Asked Questions

Is there such a thing as HIPAA certification?

No. HHS does not certify organisations as HIPAA compliant, and no official HIPAA certificate exists. Third parties offer assessments and training that can demonstrate diligence, but they do not grant government-recognised status. Compliance is an ongoing obligation measured by whether you actually meet the rules, not by holding a badge.

What is the difference between a covered entity and a business associate?

A covered entity is a health plan, healthcare clearinghouse or a healthcare provider that transmits health information electronically. A business associate is a vendor that handles PHI on a covered entity's behalf, such as a cloud host or SaaS platform. The two are linked by a Business Associate Agreement, and since the HITECH Act business associates are directly liable for many HIPAA requirements.

When do you have to report a HIPAA breach?

Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI, and HHS must be notified as well. Breaches affecting 500 or more people in a state or jurisdiction also require notice to prominent local media. Smaller breaches are logged and reported to HHS annually.

Does HIPAA apply to companies outside the United States?

Yes, when they act as business associates. HIPAA obligations attach to the role you play with US PHI, not to your physical location. An EU-based vendor processing PHI for a US covered entity must sign a BAA and meet the applicable requirements, which is why HIPAA and GDPR obligations often need to be managed together.

What does the HIPAA Security Rule actually require?

It requires administrative, physical and technical safeguards for electronic PHI, anchored by a documented risk analysis and a risk management plan. Some specifications are required and others are addressable, meaning you either implement them or document why an equivalent alternative is reasonable and appropriate. Access controls, audit logging, authentication and transmission security are all part of it.

How much can a HIPAA violation cost?

Civil monetary penalties follow four tiers based on culpability, from a lack of knowledge up to uncorrected wilful neglect, with higher minimums at each tier and an annual cap per identical requirement. The exact amounts are adjusted for inflation, so confirm current figures with OCR. Serious cases can also carry corrective action plans and, for knowing misuse, criminal charges.

Primary sources

  • HHS.gov HIPAA for Professionals - the official summaries of the Privacy, Security and Breach Notification Rules, published by the Department of Health and Human Services. hhs.gov/hipaa.
  • eCFR 45 CFR Part 160 - the general administrative requirements, including definitions and the Enforcement Rule. eCFR Part 160.
  • eCFR 45 CFR Part 164 - the Security and Privacy Rules and Breach Notification requirements in full regulatory text. eCFR Part 164.

Scope note. This article summarises the HIPAA rules at a general level and is not legal advice. Confirm specific requirements, current penalty amounts and their application to your situation against the official HHS guidance and the regulatory text, and seek qualified counsel where needed.

Run HIPAA and GDPR from one workspace

Venvera maps the Privacy, Security and Breach Notification Rules to concrete controls, tracks your BAAs and evidence, and reuses the same controls for GDPR, all on EU data residency for flat pricing from EUR 399/month. See the HIPAA module.

By Alexander Sverdlov, CEO and Founder, Venvera. Published 20 July 2026 - Last reviewed 20 July 2026.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS