What Is HIPAA? A Plain-English Guide for Practices

HIPAA (Health Insurance Portability and Accountability Act): The Law Behind Healthcare IT

If your business touches patient health information in any way, HIPAA is the federal law that governs how you handle, store and share it. It applies to medical and dental practices, and also to the vendors who work with them, including IT providers.

HIPAA dates to 1996, which makes it ancient in tech years. It is still the main privacy and security law in U.S. healthcare, regulators still enforce it, and its Security Rule is in the middle of a proposed update. If you run a practice or work with one, here is what HIPAA actually asks of your IT.

What does HIPAA stand for?

Health Insurance Portability and Accountability Act. The "portability" part was originally about letting people keep health coverage between jobs. The "accountability" part is where IT lives: rules about how health information is protected, who can access it and what happens when it is breached.

The simple way to think about it

Picture every piece of patient information as certified mail. HIPAA sets the rules for who may open it, how it must be sealed, who is responsible if it goes missing and what happens if it lands in the wrong hands. Those rules apply not only to the practice but to everyone who handles the mail on its behalf: IT companies, billing services, cloud storage vendors and more.

The rules that matter for IT

The Privacy Rule defines protected health information (PHI) and who may use or disclose it. PHI is health information linked to anything that could identify a patient: name, dates, address, Social Security number, account numbers and similar details.

The Security Rule sets the administrative, physical and technical safeguards for electronic PHI (ePHI). Encryption, access controls, audit logs, backup and recovery, device management and workforce training all flow from here.

The Breach Notification Rule says who you must notify, how quickly and what to document when unsecured PHI is compromised.

Who has to comply?

Covered entities are healthcare providers that bill electronically (doctors, dentists, clinics, hospitals), health plans and healthcare clearinghouses.

Business associates are vendors that create, receive, maintain or transmit PHI for a covered entity. A Managed Service Provider (MSP) that manages systems holding ePHI is a business associate, and HIPAA applies to it directly.

Covered entities and business associates must sign a Business Associate Agreement (BAA), a contract that spells out each party's responsibilities for protecting PHI. Sharing PHI with a vendor without a BAA is itself a compliance problem, before anything else goes wrong.

What HIPAA requires on the IT side

The Security Rule groups safeguards into three buckets:

  • Administrative safeguards: a documented risk analysis, risk management, a designated security official, access management procedures and a security awareness and training program. Training is a required standard, though some of its implementation details are "addressable."
  • Physical safeguards: controlling physical access to systems and workstations, and handling device reuse and disposal properly.
  • Technical safeguards: unique user IDs, access controls, automatic logoff, audit controls, integrity controls and protecting data in transit. Encryption is currently an "addressable" specification, which means you must implement it or document why an equivalent measure is reasonable. In practice, most practices should encrypt.

HIPAA describes outcomes rather than specific products. That gives you flexibility, but it also means you can't buy one tool and declare yourself done. Implementation and documentation both count, and HIPAA documentation must be kept for 6 years.

The proposed Security Rule update

In January 2025, HHS published a proposed rule to update the Security Rule. Among other changes, it would make MFA and encryption explicit requirements and remove the "addressable" distinction for most specifications. As of this writing it is a proposal, not a final rule, so treat it as a strong signal of where expectations are heading rather than current law.

The "HIPAA certified" myth

There is no such thing as "HIPAA certified." No government agency or private body issues an official HIPAA certification. The Office for Civil Rights (OCR) at HHS investigates complaints and breaches and enforces the rules, but there is no exam and no seal. A vendor that says it is "HIPAA certified" usually means it completed a third-party review or training program, which can be useful but isn't the same thing. What matters is whether you can show your safeguards and documentation.

What happens when HIPAA is violated?

OCR can impose civil money penalties, which are tiered by level of culpability (from "did not know" up to uncorrected willful neglect) and adjusted for inflation each year. Many cases end in resolution agreements with multi-year corrective action plans. Criminal penalties are possible for knowing misuse of PHI, and state attorneys general can also enforce HIPAA.

Breach notification in brief

  • Individuals: notify affected patients without unreasonable delay and no later than 60 days after discovering a breach.
  • HHS: for breaches affecting 500 or more people, notify HHS within the same 60-day window. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year.
  • Media: breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets there.
  • Business associates: a business associate that discovers a breach must notify the covered entity, within 60 days unless the BAA sets a shorter deadline.

Florida's breach law, the Florida Information Protection Act (FIPA), can also apply to the same incident.

How this connects to managed IT services

An IT provider working with a healthcare client is a business associate with legal obligations. In practice that means:

  • Signing a BAA before any work involving ePHI
  • Encrypting data at rest and in transit
  • Keeping audit logs of who accessed what and when
  • Supporting the practice's risk analysis
  • Maintaining documented incident response procedures
  • Training staff who work with ePHI

Retention also shapes your IT. HIPAA requires its own documentation to be kept for 6 years, and Florida has separate medical and dental record retention rules that vary by profession. Check with your licensing board or counsel for the period that applies to your records. Either way, backup and disaster recovery systems need to handle long retention windows, and immutable storage (such as WORM storage) helps protect retained records from tampering.

NerdSquad helps practices put these controls and the supporting documentation in place. Practices in Collier County can see our approach to HIPAA compliance support in Naples.

How HIPAA fits with other frameworks

  • NIST SP 800-66 is NIST's guide to implementing the HIPAA Security Rule. If you follow NIST frameworks, much of the work lines up.
  • SOC 2 shares many technical controls with HIPAA.
  • Florida FIPA adds state breach notification and data security requirements.
  • PCI DSS applies if your practice takes card payments.

Quick reference

  • PHI: health information tied to an identifiable patient. ePHI is the electronic subset.
  • Covered entity: providers, health plans, clearinghouses.
  • Business associate: vendors that handle PHI for a covered entity, including IT providers.
  • BAA: required before PHI changes hands with a vendor.
  • Security Rule update: proposed January 2025, not final as of this writing.
  • "HIPAA certified": not an official designation.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT support for medical and dental practices