How Does HIPAA Regulate Electronic Medical Records?

HIPAA regulates electronic medical records through three connected federal rules. The Security Rule requires healthcare organizations and their vendors to protect electronic protected health information (ePHI) with administrative, physical, and technical safeguards. The Privacy Rule limits who can access or share that information and for what purposes. The Breach Notification Rule forces disclosure when something goes wrong. Together, these rules also give you enforceable rights to see, copy, correct, and track disclosures of your electronic records.

Who Has to Follow HIPAA

HIPAA reaches two groups. The first is “covered entities”: healthcare providers who transmit information electronically, health plans (including Medicare and Medicaid), and healthcare clearinghouses.1HHS.gov. Covered Entities and Business Associates The second is “business associates,” meaning any vendor that handles ePHI on a covered entity’s behalf, including cloud storage providers, billing companies, IT consultants, and shredding services. Since the HITECH Act of 2009, business associates face direct federal liability for HIPAA violations, not just contractual liability to the provider that hired them.2HHS.gov. Direct Liability of Business Associates

A cash-only provider that never bills electronically is technically outside HIPAA’s scope, but this is rare in practice. If you receive care and a claim is filed, the records are covered.

What the Security Rule Requires for Electronic Records

The Security Rule is the piece of HIPAA that speaks directly to electronic records. It requires covered entities and business associates to protect the confidentiality, integrity, and availability of all ePHI they create, receive, store, or transmit.3eCFR. 45 CFR Part 164 – Security and Privacy The rule is deliberately flexible so it can fit both a two-physician practice and a large hospital system, but every organization must document the specific safeguards it has chosen and why.

Administrative Safeguards

Administrative safeguards are the policies and management practices behind the technology. Every covered entity must conduct a risk analysis identifying where ePHI is vulnerable, train workforce members on security awareness, appoint a designated security official, and maintain a contingency plan for emergencies like system failures.3eCFR. 45 CFR Part 164 – Security and Privacy Most enforcement actions begin here: an organization that cannot produce documentation of its risk analysis is already in trouble before regulators examine anything technical.

Physical Safeguards

Physical safeguards protect the hardware and facilities where ePHI actually lives. Covered entities must control physical access to spaces holding servers, workstations, and storage devices using measures such as key-card entry and surveillance. Policies must also govern how devices containing ePHI are disposed of or reused; an old hard drive cannot simply be thrown away, and the data must be wiped or the device destroyed.3eCFR. 45 CFR Part 164 – Security and Privacy

Technical Safeguards

Technical safeguards cover the technology-side protections. Every user needs a unique username and password. Systems must log who accessed which records and when. Data moving across networks must be protected in transit.3eCFR. 45 CFR Part 164 – Security and Privacy

Encryption sits in an odd spot in the current rules. It is classified as “addressable” rather than “required,” which many organizations mistake for optional. It is not optional. An addressable specification means the entity must implement it, implement an equally effective alternative, or document in writing why neither is reasonable given its environment.4HHS.gov. What Is the Difference Between Addressable and Required Implementation Specifications Regulators tend to view unencrypted ePHI unfavorably. A proposed rule published in January 2025 would remove the ambiguity by making encryption of ePHI at rest and in transit a hard requirement and would also mandate documented risk assessments at least once every 12 months.5Federal Register. HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information As of early 2026, that rule has not been finalized.

What the Privacy Rule Allows and Restricts

The Privacy Rule governs who can access or share your health information, whether the records are electronic or paper. Its central principle is minimum necessary: a covered entity should use or disclose only the smallest amount of information needed for the task. Exceptions apply for treatment (where clinicians need full information), disclosures directly to the patient, and disclosures the patient has specifically authorized.6HHS.gov. Minimum Necessary Requirement

Three broad categories of disclosure do not require your written permission: treatment (a hospital sharing records with a specialist), payment (submitting a claim to your insurer), and healthcare operations (quality improvement, training, and administration).6HHS.gov. Minimum Necessary Requirement Most other uses require your written authorization.

Marketing is a sharp line. A covered entity generally needs your written authorization before using your health information to send communications that promote a product or service, and if a third party is paying for the communication, the authorization must disclose that arrangement. Providers cannot sell patient lists or share health data with a marketing partner for the partner’s own promotional purposes without individual consent. Face-to-face conversations and promotional gifts of nominal value are the narrow exceptions.7HHS.gov. Marketing

One boundary worth knowing: HIPAA stops protecting health data once it has been properly de-identified. Under the “safe harbor” method, an organization must strip 18 categories of identifiers, including names, addresses more specific than state, most dates, phone numbers, email addresses, Social Security numbers, medical record numbers, device serial numbers, photos, and biometric data, and must have no actual knowledge that the remaining information could still identify someone.8HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information Data that clears that bar can be used freely for research and analytics without HIPAA’s restrictions.

Your Rights Over Your Electronic Records

HIPAA gives you several specific rights that every provider must describe in a Notice of Privacy Practices.9eCFR. 45 CFR 164.520 – Notice of Privacy Practices for Protected Health Information

Access and Copies

You have the right to inspect and obtain a copy of your medical and billing records, and you can request an electronic format. The provider must act within 30 days. A single 30-day extension is permitted, but only if the provider notifies you in writing with a reason and a completion date. The right covers most of your designated record set. Psychotherapy notes and information compiled for legal proceedings are excluded.10eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Fees are limited. A provider can charge for labor to copy the records, supplies like a USB drive, and postage. It cannot charge for search-and-retrieval, overhead, or the cost of maintaining its records system. For electronic copies of electronically stored records, HHS has said providers can charge a flat fee of no more than $6.50 as a simplified alternative to calculating actual costs.11HHS.gov. $6.50 Flat Rate Option Is Not a Cap on Fees These limits apply to your own requests. State laws may set different limits for records requested by attorneys or other third parties.

Amendments

If you find an error in your records, you can submit a written request for correction. The provider is not required to agree if it believes the record is accurate or if the information was not created by that provider. But it must respond in writing, and if it denies the amendment, you have the right to attach a statement of disagreement that anyone reviewing the record later will see.9eCFR. 45 CFR 164.520 – Notice of Privacy Practices for Protected Health Information

Accounting of Disclosures

You can request a report listing entities your health information has been shared with over the past six years and why. The report excludes disclosures for treatment, payment, and healthcare operations, disclosures you authorized, and several other categories including national security and correctional institutions.12eCFR. 45 CFR 164.528 – Accounting of Disclosures of Protected Health Information What you mainly see are disclosures to public health authorities, researchers, or law enforcement, not routine insurance claims.

Restrictions on Sharing

You can ask a provider to restrict how your information is used or shared, and in most cases the provider is not required to agree. One exception is meaningful: if you pay for a service entirely out of pocket and ask the provider not to share that information with your health plan, the provider must honor the request.13eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information This helps when you want to keep a sensitive treatment out of your insurer’s records, but it only works if you cover the full cost yourself and the disclosure isn’t otherwise required by law.

What Happens When Records Are Breached

When unsecured ePHI is improperly accessed or disclosed, the Breach Notification Rule sets deadlines for telling people. Any impermissible use or disclosure is presumed reportable unless the covered entity can show, through a documented risk assessment, that there is a low probability the information was actually compromised.14HHS.gov. Breach Notification Rule

If the event has to be reported, the covered entity must notify each affected individual within 60 calendar days of discovering the breach. Notices go by first-class mail, or by email if you previously agreed to electronic communication, and must explain what happened, what information was involved, and what steps you can take to protect yourself.14HHS.gov. Breach Notification Rule

Larger breaches trigger additional obligations. If 500 or more people are affected, the entity must simultaneously notify HHS and prominent media outlets serving the affected area, and HHS lists the breach on its public portal. For breaches affecting fewer than 500 individuals, the entity logs each one and reports them together to HHS within 60 days of the end of the calendar year.14HHS.gov. Breach Notification Rule

Enforcement, Penalties, and What You Can (and Can’t) Do

The Office for Civil Rights (OCR) within HHS enforces HIPAA through complaint investigations and audits.15HHS.gov. HIPAA Enforcement Civil penalties are tiered by the entity’s level of fault, from unknowing violations at the low end up to willful neglect that goes uncorrected at the top, with a calendar-year cap of $2,190,294 for all violations of the same provision. The dollar amounts are adjusted annually for inflation.16Federal Register. Annual Civil Monetary Penalties Inflation Adjustment When someone knowingly and intentionally misuses health information, especially for commercial gain or to cause harm, the Department of Justice can also pursue criminal charges carrying prison time.17Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

A boundary that surprises many people: HIPAA does not give you a right to sue. Federal courts have consistently held that individuals cannot bring a private lawsuit under HIPAA itself. If your health information is improperly disclosed, your federal remedy is a complaint to OCR, which may investigate and impose penalties on the entity. You will not receive personal compensation through that process. Patients who want damages typically pursue state-law claims for invasion of privacy, breach of confidentiality, or negligence.

How State Laws and Information Blocking Fit In

HIPAA is a federal floor, not a ceiling. When state law directly conflicts with HIPAA, HIPAA generally preempts it, but state laws that are more stringent, meaning they provide greater privacy protections or broader patient rights, override the federal standard.18eCFR. 45 CFR Part 160, Subpart B – Preemption of State Law A state that requires breach notice within 30 days, for example, takes precedence over HIPAA’s 60-day window inside that state. Providers operating in multiple states have to apply the most protective standard state by state.

A separate law addresses the opposite problem: providers who refuse to share electronic records when they should. The 21st Century Cures Act, enacted in 2016, prohibits “information blocking” by healthcare providers, health IT developers, and health information exchanges. Federal regulations recognize exceptions for practices that prevent harm, protect privacy, maintain security, or are genuinely infeasible, but the burden is on the provider to show one of them applies.19HealthIT.gov. Information Blocking For patients, this reinforces the expectation that your electronic records should be able to move to the providers you choose, not stay locked inside one system.