Managed security and compliance for regulated small businesses — Kansas City metro and nationally · (913) 601-8810
45 CFR Parts 160 and 164 · HIPAA Security Rule

HIPAA Security Rule — what it requires and what happens if it does not.

HIPAA applies to every covered entity and business associate that creates, receives, maintains, or transmits electronic protected health information. There is no minimum threshold for application — a one-provider practice with one patient has the same obligations as a hospital system.

The framework

Three rules. Seven domains. All required.

HIPAA is divided into three rules. The Privacy Rule governs how PHI may be used and disclosed. The Breach Notification Rule establishes what must happen when PHI is compromised. The Security Rule — which BoTech addresses — establishes the administrative, physical, and technical safeguards required to protect electronic PHI.

The Security Rule is organized into seven administrative standards — what most practitioners refer to as domains. Each domain contains specific implementation specifications designated as Required or Addressable. Required specifications must be implemented. Addressable specifications must be implemented if reasonable and appropriate, and the decision either way must be documented.

"Addressable" does not mean optional. OCR treats an undocumented decision not to implement an addressable specification as willful neglect of the rule itself.

Who must comply

If you touch ePHI, you are covered.

🏥
Healthcare Providers
Any provider who transmits health information electronically in connection with a covered transaction — billing, referrals, claims. Includes single-provider practices.
🏦
Health Plans
Insurers, HMOs, employer health plans with 50 or more participants, and government health programs. Self-insured plans administered by a third party included.
💻
Business Associates
Any entity that creates, receives, maintains, or transmits ePHI on behalf of a covered entity — IT providers, billing companies, EHR vendors, cloud storage, and practice management software.
Healthcare industry page →
The seven domains

Every domain explained. With citations.

Each domain page explains what OCR requires, what BoTech delivers, and every implementation specification with its Required or Addressable designation.

Civil Monetary Penalties

What non-compliance actually costs.

2024 penalty amounts per violation category per calendar year. Categories determined by level of culpability — not by breach size.

TIER 1
Did Not Know
$141–$71,162
Violation unknown despite reasonable diligence. Cap: $71,162/year per violation.
TIER 2
Reasonable Cause
$1,424–$71,162
Should have known with reasonable diligence. Not willful neglect. Cap: $71,162/year.
TIER 3
Willful — Corrected
$14,241–$71,162
Willful neglect corrected within 30 days. Cap: $71,162/year per violation.
TIER 4
Willful — Not Corrected
$71,162–$2,134,831
Willful neglect not corrected. OCR may also refer to DOJ for criminal prosecution.

2024 penalty amounts adjusted for inflation under 45 CFR Part 102. Each violation category assessed separately per calendar year.

Start the conversation

Build your HIPAA program with BoTech.

BoTech builds and maintains full HIPAA compliance programs for healthcare practices in the Kansas City metro. Contact us to discuss your situation.

Or call (913) 601-8810