Back to Frameworks

HIPAA Privacy Rule

United States
v2013
5 domains
25 controls

HIPAA Privacy Rule standards for the use and disclosure of protected health information, individual privacy rights, and covered entity administrative requirements.

Verified

HIPAA Privacy Rule is a compliance framework from United States with 5 domains and 25 controls. The largest domains are Administrative requirements (164.530) – HIPAA Privacy Rule (9 controls), Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule (9 controls), Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Administrative requirements (164.530) – HIPAA Privacy Rule

9 controls
Controls in the Administrative requirements (164.530) – HIPAA Privacy Rule domain of HIPAA Privacy Rule — 9 controls
CodeTitle
hipaa-privacy-rule::164.530aDesignation of a privacy official and a contact person
hipaa-privacy-rule::164.530bWorkforce training
hipaa-privacy-rule::164.530cAppropriate administrative, technical and physical safeguards
hipaa-privacy-rule::164.530dComplaints
hipaa-privacy-rule::164.530eSanctions for workforce non-compliance
hipaa-privacy-rule::164.530fMitigation
hipaa-privacy-rule::164.530ghNo intimidating or retaliatory acts; no waiver of rights as a condition of treatment, payment, enrollment or eligibility
hipaa-privacy-rule::164.530iPolicies and procedures
hipaa-privacy-rule::164.530jDocumentation and record retention (six years)

Business associate contracts (164.502(e), 164.504(e)) – HIPAA Privacy Rule

1 controls
Controls in the Business associate contracts (164.502(e), 164.504(e)) – HIPAA Privacy Rule domain of HIPAA Privacy Rule — 1 controls
CodeTitle
hipaa-privacy-rule::baaBusiness associate contracts and other arrangements

Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule

5 controls
Controls in the Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule domain of HIPAA Privacy Rule — 5 controls
CodeTitle
hipaa-privacy-rule::164.522aRight to request restriction of uses and disclosures
hipaa-privacy-rule::164.522bRight to request confidential communications
hipaa-privacy-rule::164.524Right of access to inspect and obtain a copy of PHI
hipaa-privacy-rule::164.526Right to request amendment of PHI
hipaa-privacy-rule::164.528Right to an accounting of disclosures

Notice of privacy practices (164.520) – HIPAA Privacy Rule

1 controls
Controls in the Notice of privacy practices (164.520) – HIPAA Privacy Rule domain of HIPAA Privacy Rule — 1 controls
CodeTitle
hipaa-privacy-rule::164.520Notice of privacy practices

Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule

9 controls
Controls in the Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule domain of HIPAA Privacy Rule — 9 controls
CodeTitle
hipaa-privacy-rule::164.502aGeneral rule: PHI may be used or disclosed only as the Privacy Rule permits or requires, or with written authorization
hipaa-privacy-rule::164.502bMinimum necessary standard
hipaa-privacy-rule::164.502gPersonal representatives
hipaa-privacy-rule::164.506Uses and disclosures for treatment, payment and health care operations (TPO)
hipaa-privacy-rule::164.508Authorization required for uses and disclosures not otherwise permitted
hipaa-privacy-rule::164.510Uses and disclosures requiring an opportunity to agree or object
hipaa-privacy-rule::164.512Uses and disclosures for which authorization or opportunity to agree or object is not required
hipaa-privacy-rule::164.514dDe-identification of protected health information
hipaa-privacy-rule::164.514hVerification of identity and authority before certain disclosures

What is HIPAA Privacy Rule and who does it apply to?

HIPAA Privacy Rule is a compliance framework from United States with 5 domains and 25 controls. HIPAA Privacy Rule standards for the use and disclosure of protected health information, individual privacy rights, and covered entity administrative requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does HIPAA Privacy Rule actually require?

HIPAA Privacy Rule has 25 controls organised across 5 domains. The largest domains are Administrative requirements (164.530) – HIPAA Privacy Rule (9 controls), Permitted and required uses and disclosures of PHI (164.502, 164.506, 164.508, 164.510, 164.512, 164.514) – HIPAA Privacy Rule (9 controls), Individual rights (164.522, 164.524, 164.526, 164.528) – HIPAA Privacy Rule (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of HIPAA Privacy Rule do I already cover?

HIPAA Privacy Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement HIPAA Privacy Rule?

Start your HIPAA Privacy Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HIPAA Privacy Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.

Get Started Free →

Free forever — no credit card required