<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the three rules under HIPAA?"
title: "What Are the Three Rules Under HIPAA"
seoTitle: "The 3 HIPAA Rules: Privacy, Security, Breach Notification"
summary: "The three main HIPAA rules are the Privacy Rule, the Security Rule, and the Breach Notification Rule. Privacy governs how protected health information may be used and disclosed in any form. Security governs electronic PHI specifically, through administrative, physical, and technical safeguards. Breach Notification governs what you must do, and how fast, once PHI is exposed. Two further rules, Enforcement and Omnibus, are often counted alongside them."
publishedAt: "2026-08-18"
keywords:
  - "three rules under HIPAA"
  - "HIPAA privacy security breach notification"
  - "HIPAA rules explained"
  - "HIPAA safeguards"
  - "four safeguards HIPAA"
  - "5 steps towards HIPAA compliance"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the three main HIPAA rules?"
    answer: "The Privacy Rule, the Security Rule, and the Breach Notification Rule. Privacy covers use and disclosure of protected health information in any form, Security covers electronic PHI specifically, and Breach Notification covers what happens after an exposure."
  - question: "Are there only three HIPAA rules?"
    answer: "Three are the main ones, but the Enforcement Rule (penalties and investigations) and the Omnibus Rule of 2013 (which extended direct liability to business associates) are commonly counted, giving five."
  - question: "What are the HIPAA safeguards?"
    answer: "The Security Rule sets three safeguard categories: administrative, physical, and technical. Some sources count four by adding organisational requirements, which the rule lists separately alongside policies, procedures, and documentation requirements."
---

## What are the three rules under HIPAA?

The three main rules are the **Privacy Rule**, the **Security Rule**, and the **Breach Notification Rule**. The Privacy Rule governs how protected health information may be used and disclosed in any form, including paper and spoken. The Security Rule applies specifically to electronic PHI and requires administrative, physical, and technical safeguards. The Breach Notification Rule governs what you must do, and within what deadlines, once PHI has been exposed.

### The three, and what each one governs

| Rule | Scope | Core requirement |
|---|---|---|
| **Privacy Rule** | PHI in any form | Limits on use and disclosure, minimum necessary standard, patient rights of access |
| **Security Rule** | Electronic PHI only | Administrative, physical, and technical safeguards, plus risk analysis |
| **Breach Notification Rule** | Unsecured PHI after exposure | Notify individuals without unreasonable delay and no later than 60 days; notify HHS; notify media for breaches affecting 500 or more people in a state |

## The two that are often counted as well

- **Enforcement Rule.** Investigation procedures, hearings, and the civil monetary penalty tiers.
- **Omnibus Rule (2013).** Extended direct liability to business associates and their subcontractors, which is why a vendor handling PHI now signs a BAA and carries obligations of its own rather than only contractual ones.

Counting these gives five rules. Three is the usual answer because Privacy, Security, and Breach Notification are the ones that impose day-to-day obligations.

## The safeguards question

The Security Rule defines **three safeguard categories**:

- **Administrative:** risk analysis, workforce training, access management, contingency planning
- **Physical:** facility access, workstation use and security, device and media controls
- **Technical:** access control, audit controls, integrity controls, transmission security

Some sources answer "four safeguards" by adding **organisational requirements**, which the rule does list separately, alongside policies, procedures, and documentation requirements. Both counts are defensible, which is why the question returns inconsistent answers. The three-category version is the one the rule structures itself around.

## What this means for a compliance program

HIPAA has no certification. There is no HIPAA certificate to obtain, and any vendor selling one is selling an attestation of their own making. What organisations do instead is demonstrate compliance through a documented risk analysis, implemented safeguards, signed business associate agreements, and evidence that all of it operates.

That is why HIPAA work overlaps heavily with SOC 2. The Security Rule safeguards map closely onto the SOC 2 Common Criteria, particularly CC6 for access control and CC7 for operations, so evidence collected once frequently satisfies both.

If you are working out whether the rules apply to you and what the safeguards mean in practice, see [HIPAA compliance for startups](/solutions/hipaa). To check which of the tools you already use will sign a BAA, see [BAA status by tool](/hipaa).
