HIPAAHealthcareUnited StatesHealthcare

Health Insurance Portability and Accountability Act

U.S. law protecting sensitive patient health information. Applies to healthcare providers, health plans, and healthcare clearinghouses. Civil penalties up to $1.5M per violation category per year.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

HIPAA164.312(b)A record of accessSpotting the abnormal

Audit Controls

Covered entities MUST implement hardware, software, and/or procedural mechanisms that record and examine activity in systems containing ePHI.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

Coverage is per-query against tables classified as holding ePHI, so the examine-activity duty is satisfied from the classification rather than from a hand-maintained table list.

HIPAA164.308(a)(1)(ii)(D)Patching, hardening, and exposureA record of access

Activity Review

MUST implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

HIPAA164.312(c)(1)The files under the databaseLeast privilege and privileged use

Integrity Controls

MUST implement policies and procedures to protect ePHI from improper alteration or destruction.

Datafiles, redo and WAL logs, backups and exports, configuration files, binaries, keystores, and scheduled jobs are hashed and baselined, so a change to any of them is detected with the permission and ownership context around it. The differentiator is attribution: because the same platform holds the query trail, a modified datafile is correlated with the session and statements running at that moment — who and why, not only what and when.

HIPAA164.308(a)(6)Routing and evidencing the response

Security Incident Procedures

MUST implement policies and procedures to identify, respond to, and mitigate security incidents.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

What HIPAA covers

45 CFR 160.103; de-identification at 45 CFR 164.514(b)

Protected health information — individually identifiable health information held or transmitted by a covered entity or business associate.

In scope

  • Information relating to past, present or future physical or mental health
  • Provision of health care to an individual
  • Past, present or future payment for health care
  • Any of the above where it identifies the individual or could reasonably be used to

What falls outside

De-identified data leaves scope entirely, by one of two routes: expert determination under 164.514(b)(1), or Safe Harbor under 164.514(b)(2), which requires all eighteen identifiers to be removed — including dates more precise than a year, all geographic subdivisions smaller than a state, and any element over 89 years of age.

The eighteen Safe Harbor identifiers are only health data in context. A name and address in a medical record must be stripped to de-identify it; the same two columns in a retail database are not health information at all, and citing HIPAA against them everywhere would be wrong.

45 CFR 164.514 · as at 2026-08

How HIPAA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by HHS Office for Civil Rights civilly; the Department of Justice criminally.

Published maximumChargedAs at
USD 145 to USD 73,011per violation, across the four culpability tiers2026-01
USD 2,190,294calendar-year cap for violations of an identical provision2026-01

Civil penalties run in four tiers keyed to culpability, from no knowledge through wilful neglect that was never corrected. The figures are adjusted for inflation annually; the amounts here took effect on 28 January 2026. Criminal referrals go to the Department of Justice and target people, not the covered entity.

OCR continues to apply a 2019 enforcement discretion policy that lowers the annual caps for the first three tiers below the published figure.

Who is personally on the hook

Who can be charged
Any person who knowingly obtains or discloses protected health information — employees, executives, and contractors alike. Prosecuted by the Department of Justice, not by OCR
For what
knowingly obtaining or disclosing protected health information without authorisation
Maximum
Up to USD 50,000 and 1 year. Up to USD 100,000 and 5 years where the offence is committed under false pretences. Up to USD 250,000 and 10 years where there is intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm
Brought by
The US Department of Justice, on referral from OCR
PrisonPersonal fineNot indemnifiable

Uncapped exposure that sits outside this instrument

These come from company law rather than from HIPAA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

The Security Rule requires a designated security official under 45 CFR 164.308(a)(2), and the risk analysis and risk management specifications at 164.308(a)(1)(ii)(A) and (B) are where a decision not to remediate has to be recorded and justified. The top penalty tier is wilful neglect NOT corrected, so the provision treats the moment of knowing as the start of a clock.

The insurance position

Cyber policies typically cover regulatory defence costs, and fines only where insurable by law. OCR resolution amounts are often characterised as settlements rather than fines, which commonly helps; criminal fines under 42 U.S.C. Sec. 1320d-6 are never insurable and never indemnifiable.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for HIPAA,
not configured for it afterwards

Policy Template

PHI Access Audit Policy

Track all access to tables containing patient health information

Policy Template

Minimum Necessary Monitoring

Detect access patterns exceeding minimum necessary standard

Report

HIPAA Audit Trail Report

164.312(b) compliant audit evidence with examiner notes

Classification

PHI Data Patterns

Detect MRN, diagnosis codes, medications, insurance IDs

Alert

PHI Breach Detection

Real-time detection of unauthorized PHI access

Walk into the HIPAA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment