HIPAA
Healthcare data protection and privacy
HIPAA establishes requirements for protecting the privacy and security of protected health information. Thalorin provides comprehensive HIPAA compliance with risk analysis automation, policy management, and business associate oversight that addresses both the Security and Privacy Rules.
HIPAA is three rules that behave differently. The Privacy Rule governs uses and disclosures of protected health information. The Security Rule governs safeguards for electronic PHI. The Breach Notification Rule governs what happens after. Most compliance failures that reach enforcement involve the Security Rule, and most of those trace to one thing: no adequate risk analysis.
The Security Rule's structure is widely misread. Implementation specifications are either required or addressable, and addressable does not mean optional. It means the organisation must assess whether the specification is reasonable and appropriate, implement it if so, and if not, document why and implement an equivalent alternative. Skipping an addressable specification without that documented reasoning is a finding.
A substantial overhaul has been proposed but is not law. The Notice of Proposed Rulemaking published on 6 January 2025 would remove the addressable designation entirely, mandating encryption of ePHI at rest and in transit, multi-factor authentication, annual penetration testing, and 72-hour incident reporting. HHS received over 4,000 comments and, in the Fall 2026 Unified Agenda, moved the amendments to long-term actions with anticipated final action in July 2027.
Until then the existing Security Rule remains fully enforceable. Thalorin binds each safeguard to the risk analysis finding that justifies it, so the required-versus-addressable reasoning is recorded where an investigator would look for it.
Framework compliance requires sustained effort
Risk analysis is the recurring finding
The Security Rule requires an accurate and thorough assessment of risks to ePHI across the whole organisation. Enforcement actions repeatedly cite risk analyses that were scoped too narrowly, performed once, or never done at all.
Addressable is misread as optional
An addressable specification requires an assessment, a decision, and documentation — including an equivalent alternative where the specification is not implemented. Omission without that record is a deficiency.
Business associate exposure
Business associates are directly liable, and covered entities carry responsibility for the agreements. Subcontractor chains extend obligations further than most BAA inventories reflect.
A proposed rule that would change the baseline
The January 2025 NPRM would remove addressable designations and mandate encryption, MFA, annual penetration testing, and 72-hour incident reporting. Final action is anticipated July 2027, so planning horizons should account for it without pre-empting it.
How Thalorin helps
Security Rule compliance
Track administrative, physical, and technical safeguards against the systems and workflows that handle ePHI, recording the required-versus-addressable determination for each implementation specification with its justification and any equivalent alternative.
Privacy Rule documentation
Hold the Privacy Rule record — notice of privacy practices, minimum necessary determinations, permitted uses and disclosures, and the accounting individuals can request — as maintained documentation rather than a binder.
Risk analysis automation
Run the risk analysis as a maintained, organisation-wide record rather than a periodic document, since this is the most cited deficiency in enforcement.
Business associate management
Maintain the business associate inventory and agreement status, including subcontractor relationships.
Breach assessment support
Carry breach risk assessments and notification timelines as workflow rather than as an after-the-fact reconstruction.
Workforce training tracking
Track training completion by role and the sanctions policy behind it, and model the proposed Security Rule requirements alongside current obligations so the gap to a future baseline is visible.
HIPAA: common questions
Did the HIPAA Security Rule update take effect?
No. The Notice of Proposed Rulemaking published 6 January 2025 remains proposed. HHS received more than 4,000 comments during the 60-day period and, in the Fall 2026 Unified Agenda, moved the amendments to its long-term actions list with July 2027 identified as the anticipated timeframe for final action. The existing Security Rule remains fully enforceable in the meantime.
What would the proposed Security Rule change?
It would remove the addressable designation, making implementation specifications mandatory. Headline requirements include encryption of ePHI at rest and in transit, multi-factor authentication for systems accessing ePHI, annual penetration testing, 72-hour incident reporting, and expanded business associate oversight. Because it is not final, the specifics may change before adoption.
Does addressable mean optional?
No, and this is the most consequential misreading of the Security Rule. Addressable requires you to assess whether the specification is reasonable and appropriate for your environment, implement it where it is, and where it is not, document that determination and implement an equivalent alternative measure. Doing none of these is a deficiency.
Who counts as a business associate?
Any person or entity that creates, receives, maintains, or transmits protected health information on behalf of a covered entity in performing a covered function — billing services, cloud hosting, analytics providers, shredding services. Subcontractors of business associates that handle PHI are themselves business associates, which is where inventories most often fall short.
Is there a HIPAA certification?
No. HHS does not certify, endorse, or accredit compliance, and any vendor claiming to make you HIPAA certified is describing something that does not exist. Organisations demonstrate compliance through their risk analysis, safeguards, policies, training records, and business associate agreements — and, if investigated, through evidence that those things were real.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about HIPAA.
See how one evidence artifact satisfies HIPAA requirements alongside every other framework you carry.