HIPAA applies to every covered entity and business associate that creates, receives, maintains, or transmits electronic protected health information. There is no minimum threshold for application — a one-provider practice with one patient has the same obligations as a hospital system.
HIPAA is divided into three rules. The Privacy Rule governs how PHI may be used and disclosed. The Breach Notification Rule establishes what must happen when PHI is compromised. The Security Rule — which BoTech addresses — establishes the administrative, physical, and technical safeguards required to protect electronic PHI.
The Security Rule is organized into seven administrative standards — what most practitioners refer to as domains. Each domain contains specific implementation specifications designated as Required or Addressable. Required specifications must be implemented. Addressable specifications must be implemented if reasonable and appropriate, and the decision either way must be documented.
"Addressable" does not mean optional. OCR treats an undocumented decision not to implement an addressable specification as willful neglect of the rule itself.
Each domain page explains what OCR requires, what BoTech delivers, and every implementation specification with its Required or Addressable designation.
Risk analysis, risk management, sanction policy, and information system activity review. The foundation of the entire HIPAA program.
§164.308(a)(3–5) · Required + AddressableAuthorization, supervision, clearance procedures, termination, and annual security training for every workforce member who handles ePHI.
§164.312(a) · Required + AddressableUnique user identification, emergency access, automatic logoff, and encryption. Technical controls enforcing the minimum necessary standard.
§164.312(b) · All RequiredHardware, software, and procedural mechanisms for recording and reviewing ePHI system activity. All specifications required — none are addressable.
§164.308(b) · RequiredWritten BAA requirements with every vendor that has ePHI access. The most common gap in small practice OCR investigations.
§164.308(a)(6) · §164.400–414Security incident procedures plus the Breach Notification Rule — 60-day patient notification, HHS reporting, and local media requirements for 500+ breaches.
§164.310 · §164.312(c–e)Facility access, workstation use, device and media controls, transmission security, and integrity controls. Encryption in transit and at rest.
2024 penalty amounts per violation category per calendar year. Categories determined by level of culpability — not by breach size.
2024 penalty amounts adjusted for inflation under 45 CFR Part 102. Each violation category assessed separately per calendar year.
BoTech builds and maintains full HIPAA compliance programs for healthcare practices in the Kansas City metro. Contact us to discuss your situation.
Or call (913) 601-8810