What HIPAA Privacy Rule requires
The HIPAA Privacy Rule establishes national standards governing the use and disclosure of protected health information (PHI) by covered entities and their business associates. General rules articulated within 45 CFR § 164.502 mandate the implementation of appropriate safeguards and require formal business associate agreements for any third-party handling PHI. A foundational principle is the minimum necessary standard, enforced pursuant to 45 CFR § 164.514, which limits PHI use or disclosure to the minimum required for a specific purpose. Specific authorizations from individuals are mandated under 45 CFR § 164.508 for certain uses, including nearly all marketing communications, while the unauthorized sale of PHI is strictly prohibited. The regulation further grants individuals significant rights over their health information. Covered entities must provide a clear Notice of Privacy Practices as specified in 45 CFR § 164.520. Individuals have a right to access their designated record set, with such provision required within a maximum of 30 days per 45 CFR § 164.524. An accounting of disclosures must also be furnished upon request within 60 days, according to 45 CFR § 164.528. Entities have up to 60 days to act upon an individual’s amendment request. Compliance requires appointing a privacy officer, conducting workforce training, and retaining all related documentation for a period of six years.
Pillar: Data Protection & Privacy · Authority: HHS Office for Civil Rights · Version: 1.1.0 · Last updated:
Primary source: https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
SHA-256 integrity: cb85728b1295ea47575d342af55bcdacca79a8ff940a7997d8eb078aa8608b09
Primary Citations — 7 traced to source
- 45 CFR § 164.502 - Uses and disclosures of protected health information: General rules.
- 45 CFR § 164.508 - Uses and disclosures for which an authorization is required.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/hipaa-privacy-rule.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/hipaa-privacy-rule.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/hipaa-privacy-rule
- Back to registry: Browse all 10,085 compliance nodes