HIPAA compliance, in plain operational terms
People say HIPAA as if it were one rule. It is several, stapled together over two decades, and it sits on top of state and other federal laws that can be stricter than the federal floor. This is the practitioner's map: the two rules you work with most, the rest of the web around them, and how Rote checks your program against all of it, citation by citation, anchored by a fixed-scope Security Risk Assessment.
One name, several rules — plus the law layered on top.
People say "HIPAA" as if it were a single regulation. It is actually several: chiefly the Privacy Rule and the Security Rule, with the Breach Notification Rule and the HITECH amendments alongside them. A working program also has to satisfy the law that sits on top — state privacy and breach statutes that often reach further than HIPAA, and, depending on the data you hold, other federal regimes. The two rules you work with most have full guides below; a Rote review reads your program against the rest of that landscape, not only the two.
The proposed 2026 overhaul in plain terms: whether it is real yet, the one change that matters most (addressable would become required), and the three moves worth making now.
Read the Security Rule guide →What it actually requires: permitted uses of PHI, the minimum necessary standard, the Notice of Privacy Practices, patient rights, and business associates.
Read the Privacy Rule guide →When PHI is exposed, this sets who you must notify, how fast, and what to document. Part of every HIPAA program, not an optional add-on.
How OCR investigates and penalizes, and the HITECH amendments that made business associates directly liable and raised the stakes.
HIPAA is a floor. State medical-privacy and breach-notification laws frequently go further, and where they do, they apply on top of it.
Depending on the data you hold: 42 CFR Part 2 for SUD records, the FTC Health Breach Notification Rule, and more.
Covered entities and their business associates.
HIPAA reaches two groups. Covered entities are health plans, health care clearinghouses, and health care providers — though a provider is only covered if it transmits health information electronically in connection with certain standard transactions, such as submitting a claim. Business associates are the vendors that create, receive, maintain, or transmit protected health information on a covered entity's behalf; the subcontractors they hand that data to are business associates as well. Both are directly liable for much of the rule, not just the terms of their contract.
That second group is where a lot of modern exposure sits. If you are a healthtech company handling PHI for a customer, you are almost certainly a business associate, and the agreement you signed has to meet 45 CFR 164.504(e). The relationship is governed by a business associate agreement on both sides.
One thing HIPAA does not have: an official certification. HHS does not certify anyone as HIPAA compliant. You demonstrate compliance through your own documented program, which is exactly what Rote's analysis is built to assess.
The Security Risk Assessment: the risk analysis the rule requires, priced up front.
Every covered entity and business associate is required to conduct a security risk analysis under 45 CFR 164.308(a)(1)(ii)(A). It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the artifact MIPS reporters attest to each year. It also covers your whole ePHI surface as it actually exists: OCR expects the analysis to address the AI tools in use, vendor AI access, and shadow AI alongside everything else, and this assessment does. Rote delivers it fixed-scope and priced up front, starting at $3,500: a practitioner's judgment on Rote's analysis engine, every finding evidence-cited, in 10 business days from complete intake. Each rung credits toward the next.
Enter where your program actually is:
| Offer | Price | What you get |
|---|---|---|
| HIPAA Self-Check | Free | Run the open-source HIPAA skills yourself, including the Risk Assessment skill, or start with the free Snapshot. A first read of your posture in your own environment. |
| HIPAA Security Risk Assessment | starting at $3,500 | The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), conducted by a practitioner on Rote's analysis engine: asset and ePHI inventory (including AI tools and vendor AI access, which OCR expects the analysis to address), reasonably anticipated threats and vulnerabilities, likelihood and impact scored with written rationale, a risk register you keep, a risk management plan with 30/60/90 actions, and an attestation-ready summary letter. Every finding evidence-cited. Single entity or site, 10 business days from complete intake. |
| Small-Organization SRA | starting at $1,750 | The same artifact set for single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff. Mostly automated on standard templates, ratified by the practitioner. If real complexity surfaces, the engagement routes to the full assessment with this fee credited. Nonprofit and public-entity discount applies. |
| Risk Management Project | starting at $8,000 | Implementation of the risk management plan per 45 CFR 164.308(a)(1)(ii)(B): corrected policies and procedures, safeguard documentation, BAA language, and an evidence log showing the analysis was acted on — including AI-specific gaps where the findings warrant it (AI use policy, governance charter, vendor-review process). Already have a risk analysis from another provider? Bring it, and the Project closes the gaps it surfaced. OCR's current enforcement pattern examines exactly this follow-through. |
| Maintenance | starting at $750/mo | The annual SRA refresh (MIPS requires a fresh analysis each performance period; OCR expects it reviewed as your environment changes), quarterly reviews, the annual SAFER Guide self-assessment for MIPS reporters, and a watch on the proposed Security Rule overhaul. The annual refresh alone is the $3,500 assessment. |
The 2026 attestation is two statements, and both point here.
For the Promoting Interoperability category, CMS requires a yes to both: a security risk analysis conducted or reviewed during the calendar year of the performance period (45 CFR 164.308(a)(1)(ii)(A)), and risk management activities that implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss the measure and the entire category scores zero, which puts the 75-point threshold, and up to a 9% adjustment on 2028 Medicare payments, in play.
The analysis must be unique to the performance period, conducted January 1 to December 31, and scoped to all ePHI you create, receive, maintain, or transmit, not only the EHR. The assessment above is built to that standard. Maintenance carries the annual refresh and the SAFER Guide self-assessment that reports alongside it.
Groups of 15 or fewer clinicians are automatically reweighted out of the category in 2026. The Security Rule obligation applies regardless of MIPS, and it is what OCR's Risk Analysis Initiative enforces.
Pricing is disclosed up front. Multi-site organizations are quoted per site. Business associates: the assessment includes a findings summary usable in enterprise security reviews. The skills beneath each rung are below.
For most organizations, AI findings route into the Risk Management Project like any other finding. If AI is central to what you build or buy, the same findings can instead seed a standing governance program: AI-specific policies, vendor review process, a governance charter, and ongoing monitoring. That is the enterprise AI governance engagement, and it starts from the assessment you already have.
See AI Governance →From the regulation to your documents.
Rote's skills map your existing documents to specific HIPAA sections so you see coverage, gaps, and the citation behind every finding. Open source, and available as services when you want a practitioner in the loop.
The engine under the Security Risk Assessment: threats and vulnerabilities scored on a 3x3 likelihood/impact matrix, mapped to HIPAA or any framework, with treatment recommendations.
Open skill →Maps policies and procedures against Security Rule and Privacy Rule requirements, with coverage status, confidence score, and CFR citation per control.
Open skill →Clause-by-clause analysis of a business associate agreement against the 45 CFR 164.504(e) required provisions, with recommended language.
Open skill →Individual safeguard scoring across HIPAA administrative, physical, and technical requirements, with evidence extraction and severity.
Open skill →A Seven Elements assessment producing a maturity stage, enterprise blocker flags, and a 30/60/90 day roadmap. The engine behind the free Snapshot.
Open skill →Common questions about HIPAA.
HIPAA is the Health Insurance Portability and Accountability Act. Its regulations at 45 CFR Part 164 set national standards for protecting health information. The two that drive most compliance work are the Privacy Rule (how protected health information may be used and disclosed) and the Security Rule (the safeguards required for electronic protected health information).
Covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates, the vendors that create, receive, maintain, or transmit protected health information on their behalf. Business associates are directly liable for much of the rule and must operate under a business associate agreement.
The Privacy Rule governs what you may do with protected health information in any form and the rights patients have over it. The Security Rule sets the administrative, physical, and technical safeguards for electronic protected health information specifically. Most organizations are subject to both.
No. HHS does not certify or endorse any organization as HIPAA compliant. Compliance is demonstrated through your own documented program: risk analysis, safeguards, policies, training, and business associate agreements. Third-party frameworks like HITRUST or SOC 2 can support that story but are not a HIPAA certification.
A proposed overhaul of the Security Rule is under review, the first major rewrite in over two decades. As of the last-reviewed date it is a proposed rule, not final, and not being enforced. The Privacy Rule core remains in effect. See the Security Rule update guide for what would change and what is worth doing now.
The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI your organization creates, receives, maintains, or transmits. It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the subject of OCR's ongoing Risk Analysis Initiative. Rote's fixed-scope Security Risk Assessment delivers it in 10 business days: asset and ePHI inventory, threat and vulnerability analysis with likelihood and impact scoring, a risk register, a risk management plan, and an attestation-ready summary letter, every finding evidence-cited.
Yes, for anyone reporting the Promoting Interoperability category. For the 2026 performance period, CMS requires attesting to two things: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Without both, the entire category scores zero. The analysis must be unique to the performance period and cover all ePHI, not only the EHR. Practices with 15 or fewer clinicians are automatically reweighted out of the category in 2026, but the underlying Security Rule obligation applies to every covered entity and business associate regardless of MIPS.
It can be. The ONC and OCR jointly publish the SRA Tool, and CMS points MIPS participants to it. It is a legitimate way to conduct the analysis if you have the staff time to work through it properly and document the results. What it does not supply is the time itself, findings cited to your actual documents, or a practitioner-signed report and risk management plan. If you have the capacity, use it, and run our free Self-Check alongside. If you do not, that is the gap the fixed-scope assessment fills.
Consultant-led assessments typically run $2,000 to $15,000 for small and mid-size organizations and considerably more at enterprise firms, usually behind a quote process. Software platforms run roughly $500 to $4,000 per year and leave the analysis work to you. Rote publishes its pricing: starting at $3,500 for the practitioner-conducted assessment, and starting at $1,750 for qualifying small single-site organizations, delivered in 10 business days, priced up front. The fee credits in full toward the Risk Management Project.
It has to. The analysis must address risks to all ePHI your organization creates, receives, maintains, or transmits, and OCR has made clear that includes AI tools in use, vendor AI access, and unsanctioned staff AI use. Rote's assessment inventories your AI surface as part of the standard scope. If the findings warrant a standing AI governance program rather than point fixes, that is the AI Governance engagement, built from the same assessment.
With an honest read of where you stand. The free Readiness Snapshot places you on a maturity matrix and points to the thin spots across HIPAA, without a sales call attached.
See where your HIPAA program stands.
The Readiness Snapshot is free. It places your organization on Rote's compliance maturity matrix and shows where your documentation is thin against HIPAA, within one week. Diagnostic, not a sales call.