RulesHIPAA rules, explained for choosing tools
- Business associate agreements (BAAs) →164.502(e), 164.504(e), 164.308(b)Any vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed BAA with it before it touches patient data. No BAA means you should not put PHI in that tool.
- De-identification →164.514(a), 164.514(b)How HIPAA de-identification works — the Safe Harbor list of 18 identifiers and Expert Determination — and what it means for analytics, AI and research use of health data.
- Emailing patients →164.522(b), 164.530(c)HIPAA allows providers to email patients, with reasonable safeguards. Patients may also ask to receive information by email; if they prefer unencrypted email after being warned of the risk, a provider may honor that.
- HIPAA authorization →164.508When you need a patient's written authorization to use or share their health information, what the form must contain to be valid, and how patients can revoke it.
- Minimum necessary →164.502(b), 164.514(d)What the HIPAA minimum necessary standard requires, when it does not apply, and how small practices put it into practice with role-based access and standard disclosure limits.
- Notice of Privacy Practices →164.520What the Notice of Privacy Practices must say, when and how a practice must provide it, where it must be posted, and what changed in 2026.
- Psychotherapy notes →164.501, 164.508(a)(2)What counts as psychotherapy notes under HIPAA, how they differ from progress notes, and the extra protection they get — for therapists choosing how to keep their notes.
- Right of access →164.524Patients' right to see and get copies of their health records: deadlines, formats, fees, third-party requests, and what a small practice needs in place.
- Access control and sign-in →164.312(a)(1), 164.312(d)Only the right people should reach ePHI, each under their own account, with a reliable way to confirm who is signing in. In practice: unique user accounts, strong authentication such as MFA, and automatic logoff.
- Audit controls and activity logs →164.312(b), 164.308(a)(1)(ii)(D)Systems holding ePHI must record activity so you can review who accessed what. When choosing a tool, check that you — not only the vendor — can see sign-ins and access to records, and for how long.
- Encryption of ePHI →164.312(a)(2)(iv), 164.312(e)(2)(ii)Encryption is "addressable", not optional: you either encrypt ePHI at rest and in transit, or document why not and use an equivalent safeguard. For email and cloud tools, encrypting is almost always the reasonable choice.
- HIPAA policies and procedures →164.316, 164.530(i)What written policies and procedures HIPAA requires, how to keep them current, and how long to keep them — for small practices and business associates.
- Security risk analysis →164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B)Every covered entity and business associate must document an accurate and thorough assessment of risks to the ePHI it holds — and then act on it. It is one of the most commonly missing pieces of HIPAA compliance, including in small practices.
- Business associate →160.103, 164.502(e)Who counts as a HIPAA business associate, common examples including SaaS and cloud vendors, subcontractors, and what business associates must do.
- Covered entity →160.103What makes an organization a HIPAA covered entity, the three types, how the provider test works, and what covered entities must do.
- HIPAA documentation retention →164.316(b)(2), 164.530(j)What HIPAA requires you to keep and for how long — six years for compliance documentation — and why medical record retention is a state-law question.
- HIPAA training requirements →164.530(b), 164.308(a)(5)Who must be trained under HIPAA, on what, how often, and how to document it — and what the rule does not actually require.
- PHI and ePHI →160.103What counts as protected health information under HIPAA, how ePHI differs, what is excluded, and practical examples for small practices and health tech companies.