Medinformics
Compliance

March 2026 · 8 min read

HIPAA in 2026:
What Every Health IT Professional Actually Needs to Know

HIPAA compliance is one of those topics where almost everyone in healthcare has heard the acronym, passed the annual training module, and still isn't sure what the law actually requires of them. The training-as-checkbox culture has created a workforce that knows the word "HIPAA" but struggles to apply it when a colleague asks whether they can share a patient list in a Slack channel.

This is a practical guide — not a legal opinion, but a working reference for health IT professionals who need to make real decisions, not just pass audits.

HIPAA is not just a checkbox

The Health Insurance Portability and Accountability Act was enacted in 1996 and has been updated significantly since, most notably through the HITECH Act (2009) and the Omnibus Rule (2013). It is a federal law with enforcement teeth: OCR (Office for Civil Rights) has levied penalties totalling hundreds of millions of dollars, including multi-million-dollar settlements against organisations that had policies on paper but not in practice.

The practical implication: compliance isn't achieved by having a policy. It's achieved by having controls that work, staff who understand them, and systems configured to enforce them.

The three rules

HIPAA has three primary rules that health IT professionals need to understand:

  • Privacy Rule — governs who can access, use, and disclose protected health information (PHI). Establishes patient rights over their own data.
  • Security Rule — applies specifically to electronic PHI (ePHI). Requires administrative, physical, and technical safeguards.
  • Breach Notification Rule — requires covered entities to notify patients, HHS, and (in large breaches) the media within specified timeframes when unsecured PHI is compromised.

What counts as PHI — the 18 identifiers

Protected Health Information (PHI) is health information that can be linked to a specific individual. HIPAA defines 18 categories of identifiers that, when combined with health information, create PHI:

  • Names and geographic data smaller than state
  • Dates (other than year) directly related to an individual
  • Phone numbers, fax numbers, email addresses
  • Social security numbers, medical record numbers, health plan beneficiary numbers
  • Account numbers, certificate and licence numbers
  • Vehicle identifiers, device identifiers and serial numbers
  • Web URLs, IP addresses, biometric identifiers
  • Full-face photographs and comparable images
  • Any other unique identifying number or code

The practical implication: a spreadsheet with patient names and appointment dates is PHI. A dataset with diagnoses but no names may still be PHI if the combination of remaining data points could re-identify individuals.

The Minimum Necessary standard

The Privacy Rule requires that covered entities make reasonable efforts to use, disclose, and request only the minimum amount of PHI needed to accomplish the intended purpose. This is not just a privacy principle — it is a legal requirement with enforcement implications.

In practice: if a billing department needs a diagnosis code, it does not need a full clinical note. If a researcher needs outcome data, it may not need patient names. System design and access controls should reflect this standard — not just be mentioned in a policy document.

Business Associate Agreements (BAAs)

A Business Associate is any organisation that handles PHI on behalf of a covered entity — cloud providers, analytics vendors, EHR hosting companies, IT contractors. Every Business Associate must sign a BAA before being given access to PHI.

A BAA is not just a formality. It establishes legal accountability: the Business Associate takes on HIPAA compliance obligations for the data they handle. If they breach those obligations, they — not just your organisation — face enforcement action.

What this means for vendor selection

Before putting any PHI into a third-party tool, confirm that they will sign a BAA. Many consumer-grade tools — including popular productivity apps — will not. Using them for PHI is a HIPAA violation regardless of what the tool does with the data.

Common HIPAA mistakes in 2026

The most common violations health IT teams encounter today are not from malicious actors — they're from convenience:

  • Cloud storage without a BAA — uploading patient lists to personal Google Drive or Dropbox
  • Consumer messaging apps — sharing clinical information via WhatsApp or standard SMS, which are not HIPAA-compliant channels
  • AI tools without evaluation — pasting patient data into general-purpose AI assistants that do not have a BAA and may use inputs for training
  • Inadequate access controls — staff with broader EHR access than their role requires

HIPAA vs GDPR — key differences

Organisations operating internationally often need to navigate both HIPAA and the EU's General Data Protection Regulation (GDPR). The key differences:

  • HIPAA applies to covered entities and their business associates; GDPR applies to any organisation processing EU personal data regardless of where the organisation is based
  • GDPR requires a lawful basis for processing; HIPAA defines permitted uses and disclosures
  • GDPR's breach notification window is 72 hours; HIPAA requires notification within 60 days
  • GDPR fines can reach €20 million or 4% of global turnover; HIPAA penalties are tiered up to $1.9 million per violation category per year

The Health Informatics Fundamentals track on Medinformics covers HIPAA, GDPR, and information governance in depth — including practical exercises in identifying PHI, reviewing BAAs, and designing compliant data workflows.

Ready to go from reading to doing?

Start your first health informatics module — free, no card required.

Start for free
← Back to blog

We use essential cookies to keep you logged in. Analytics cookies are optional. Learn more