HIPAA Privacy Rule
HIPAA Privacy Rule standards for the use and disclosure of protected health information, individual privacy rights, and covered entity administrative requirements.
HIPAA Privacy Rule is a compliance framework from United States with 5 domains and 25 controls. The largest domains are Administrative requirements (164.530) – HIPAA Privacy Rule (9 controls), Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule (9 controls), Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Administrative requirements (164.530) – HIPAA Privacy Rule
| Code | Title |
|---|---|
| hipaa-privacy-rule::164.530a | Designation of a privacy official and a contact person |
| hipaa-privacy-rule::164.530b | Workforce training |
| hipaa-privacy-rule::164.530c | Appropriate administrative, technical and physical safeguards |
| hipaa-privacy-rule::164.530d | Complaints |
| hipaa-privacy-rule::164.530e | Sanctions for workforce non-compliance |
| hipaa-privacy-rule::164.530f | Mitigation |
| hipaa-privacy-rule::164.530gh | No intimidating or retaliatory acts; no waiver of rights as a condition of treatment, payment, enrollment or eligibility |
| hipaa-privacy-rule::164.530i | Policies and procedures |
| hipaa-privacy-rule::164.530j | Documentation and record retention (six years) |
Business associate contracts (164.502(e), 164.504(e)) – HIPAA Privacy Rule
| Code | Title |
|---|---|
| hipaa-privacy-rule::baa | Business associate contracts and other arrangements |
Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule
| Code | Title |
|---|---|
| hipaa-privacy-rule::164.522a | Right to request restriction of uses and disclosures |
| hipaa-privacy-rule::164.522b | Right to request confidential communications |
| hipaa-privacy-rule::164.524 | Right of access to inspect and obtain a copy of PHI |
| hipaa-privacy-rule::164.526 | Right to request amendment of PHI |
| hipaa-privacy-rule::164.528 | Right to an accounting of disclosures |
Notice of privacy practices (164.520) – HIPAA Privacy Rule
| Code | Title |
|---|---|
| hipaa-privacy-rule::164.520 | Notice of privacy practices |
Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule
| Code | Title |
|---|---|
| hipaa-privacy-rule::164.502a | General rule: PHI may be used or disclosed only as the Privacy Rule permits or requires, or with written authorization |
| hipaa-privacy-rule::164.502b | Minimum necessary standard |
| hipaa-privacy-rule::164.502g | Personal representatives |
| hipaa-privacy-rule::164.506 | Uses and disclosures for treatment, payment and health care operations (TPO) |
| hipaa-privacy-rule::164.508 | Authorization required for uses and disclosures not otherwise permitted |
| hipaa-privacy-rule::164.510 | Uses and disclosures requiring an opportunity to agree or object |
| hipaa-privacy-rule::164.512 | Uses and disclosures for which authorization or opportunity to agree or object is not required |
| hipaa-privacy-rule::164.514d | De-identification of protected health information |
| hipaa-privacy-rule::164.514h | Verification of identity and authority before certain disclosures |
What is HIPAA Privacy Rule and who does it apply to?
HIPAA Privacy Rule is a compliance framework from United States with 5 domains and 25 controls. HIPAA Privacy Rule standards for the use and disclosure of protected health information, individual privacy rights, and covered entity administrative requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does HIPAA Privacy Rule actually require?
HIPAA Privacy Rule has 25 controls organised across 5 domains. The largest domains are Administrative requirements (164.530) – HIPAA Privacy Rule (9 controls), Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule (9 controls), Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of HIPAA Privacy Rule do I already cover?
HIPAA Privacy Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement HIPAA Privacy Rule?
Start your HIPAA Privacy Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HIPAA Privacy Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.
Get Started Free →Free forever — no credit card required