Screenata

Beyond SOC 2

What are the three rules under HIPAA?

August 18, 20263 min read

What are the three rules under HIPAA?

The three main rules are the Privacy Rule, the Security Rule, and the Breach Notification Rule. The Privacy Rule governs how protected health information may be used and disclosed in any form, including paper and spoken. The Security Rule applies specifically to electronic PHI and requires administrative, physical, and technical safeguards. The Breach Notification Rule governs what you must do, and within what deadlines, once PHI has been exposed.

The three, and what each one governs

RuleScopeCore requirement
Privacy RulePHI in any formLimits on use and disclosure, minimum necessary standard, patient rights of access
Security RuleElectronic PHI onlyAdministrative, physical, and technical safeguards, plus risk analysis
Breach Notification RuleUnsecured PHI after exposureNotify individuals without unreasonable delay and no later than 60 days; notify HHS; notify media for breaches affecting 500 or more people in a state

The two that are often counted as well

  • Enforcement Rule. Investigation procedures, hearings, and the civil monetary penalty tiers.
  • Omnibus Rule (2013). Extended direct liability to business associates and their subcontractors, which is why a vendor handling PHI now signs a BAA and carries obligations of its own rather than only contractual ones.

Counting these gives five rules. Three is the usual answer because Privacy, Security, and Breach Notification are the ones that impose day-to-day obligations.

The safeguards question

The Security Rule defines three safeguard categories:

  • Administrative: risk analysis, workforce training, access management, contingency planning
  • Physical: facility access, workstation use and security, device and media controls
  • Technical: access control, audit controls, integrity controls, transmission security

Some sources answer "four safeguards" by adding organisational requirements, which the rule does list separately, alongside policies, procedures, and documentation requirements. Both counts are defensible, which is why the question returns inconsistent answers. The three-category version is the one the rule structures itself around.

What this means for a compliance program

HIPAA has no certification. There is no HIPAA certificate to obtain, and any vendor selling one is selling an attestation of their own making. What organisations do instead is demonstrate compliance through a documented risk analysis, implemented safeguards, signed business associate agreements, and evidence that all of it operates.

That is why HIPAA work overlaps heavily with SOC 2. The Security Rule safeguards map closely onto the SOC 2 Common Criteria, particularly CC6 for access control and CC7 for operations, so evidence collected once frequently satisfies both.

If you are working out whether the rules apply to you and what the safeguards mean in practice, see HIPAA compliance for startups. To check which of the tools you already use will sign a BAA, see BAA status by tool.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.