What Is HIPAA and Why Does It Matter?

AegisPro HIPAA Rule Infographic

A plain-English guide to the law protecting patient health information, who it applies to, and what your business needs to know

Published September 7, 2026 | By Nick Turner, AegisPro CyberShield TX

‍ ‍

TL;DR

HIPAA is the federal law that governs how patient health information is handled, stored, and shared. If your business touches healthcare data in any way, it almost certainly applies to you.

▪ HIPAA is built on three core rules: the Privacy Rule, the Security Rule, and the Breach Notification Rule.
▪ It doesn't just apply to doctors and hospitals. Health plans, clearinghouses, and any business associate handling protected health information (PHI) must comply.
▪ Patients have specific rights under HIPAA, including the right to access their records, request corrections, and know who their data has been shared with.
▪ Penalties for violations range from $145 per incident up to $2.19 million annually, with criminal penalties including prison time for the most serious offenses.

The bottom line: HIPAA isn't optional, and "we didn't know" isn't a defense. Understanding the basics is the first step toward protecting your business and your patients.


HIPAA in 30 Seconds

HIPAA stands for the Health Insurance Portability and Accountability Act, signed into law in 1996. While the "portability" part originally focused on helping people keep health insurance between jobs, the law is best known today for its privacy and security provisions.

At its core, HIPAA protects Protected Health Information (PHI), which is any information about a patient's health status, treatment, or payment for healthcare that can be tied to a specific individual. That includes obvious things like medical records and diagnoses, but also billing information, insurance details, appointment histories, and even a patient's name combined with their date of service.

What counts as PHI? Any information about a patient's health, treatment, or payment that can be tied to a specific person. Medical records and diagnoses are obvious, but PHI also includes billing info, insurance details, appointment histories, and even a patient's name combined with their date of service. If it identifies a patient and relates to their care or payment, it's PHI.

The Three Rules of HIPAA

Think of HIPAA's requirements as three interconnected layers. Each one addresses a different part of how health information should be handled.

1. The Privacy Rule

Governs who can access PHI and how it can be used or shared. It sets the ground rules for when patient authorization is required, when information can be disclosed without it (such as for treatment or public health purposes), and what rights patients have over their own data. This is the rule that requires every healthcare provider to hand you a Notice of Privacy Practices.

2. The Security Rule

Focuses specifically on electronic protected health information (ePHI) and requires three categories of safeguards:

Administrative safeguards: Policies, procedures, risk assessments, workforce training, and designated security personnel
Physical safeguards: Facility access controls, workstation security, and device management (including what happens to old hard drives and laptops)
Technical safeguards: Access controls, audit logs, encryption, and transmission security

3. The Breach Notification Rule

Spells out exactly what happens when something goes wrong. If unsecured PHI is accessed, used, or disclosed in a way that violates the Privacy Rule, the covered entity must notify:

Affected individuals without unreasonable delay (no later than 60 days after discovery)
HHS (the Department of Health and Human Services) through the OCR breach portal
The media if the breach affects 500 or more residents of a state or jurisdiction

Who Has to Follow HIPAA?

This is where many small businesses get surprised. HIPAA doesn't just apply to hospitals and large medical systems. It applies to two broad categories:

Covered Entities

Healthcare providers who transmit health information electronically: doctors, dentists, chiropractors, psychologists, clinics, pharmacies, nursing homes
Health plans: insurance companies, HMOs, employer-sponsored health plans, Medicare, Medicaid, military and veterans health programs
Healthcare clearinghouses: organizations that process or convert health information between standard and nonstandard formats

Business Associates

This is the category that catches people off guard. A business associate is any person or organization that performs a function involving PHI on behalf of a covered entity. Examples include:

▪ IT companies that maintain or have access to systems storing patient data
▪ Billing and coding services ▪ Cloud storage providers hosting ePHI
▪ Accounting firms with access to patient billing records
▪ Shredding companies that destroy paper records containing PHI
▪ Consultants who need access to patient information

If your business provides services to a healthcare provider and you touch PHI in any way, you are a business associate. You need a Business Associate Agreement (BAA) in place, and you are directly liable for HIPAA compliance.

Not sure if your business qualifies as a business associate? If you provide any service to a healthcare provider and your work involves access to patient data — even indirectly through IT systems, billing platforms, or cloud storage — HIPAA almost certainly applies to you. AegisPro's Compliance Gap Analysis can determine exactly where you stand.

Patient Rights Under HIPAA

HIPAA gives patients meaningful control over their health information. These aren't suggestions; they're enforceable rights.

Right to access their records. Patients can request copies of their medical records, and providers must respond within 30 days (a proposed update would shorten this to 15 days).
Right to request amendments. If a patient believes their records contain errors, they can request corrections.
Right to know who received their data. Patients can request an accounting of disclosures covering the previous six years.
Right to request restrictions. Patients can ask that certain uses or disclosures of their PHI be limited, including preventing insurers from learning about treatments paid for out of pocket.
Right to choose how they're contacted. Patients can specify how and where a provider communicates with them about health matters.
Right to a privacy notice. Every covered entity must provide a clear explanation of how patient information may be used.
Right to breach notification. If their data is compromised, patients must be informed about what happened, what information was involved, and what steps they should take.

What Violations Actually Cost

HIPAA enforcement has teeth. The Office for Civil Rights (OCR) resumed its audit program in March 2025, and penalty amounts were adjusted upward in January 2026.

Violation Level Fine Per Violation Annual Maximum
Did not know (and wouldn't have known) $145 – $36,505 $36,505
Reasonable cause (not willful neglect) $1,461 – $73,011 $146,053
Willful neglect, corrected within 30 days $14,602 – $73,011 $365,052
Willful neglect, not corrected $73,011 – $2,190,294 $2,190,294

Criminal penalties go further: up to 1 year in prison for basic violations, up to 5 years for obtaining PHI under false pretenses, and up to 10 years when personal gain or malicious intent is involved.

"Lack of knowledge" does not exempt you from penalties. It only determines which tier applies. The OCR resumed its audit program in March 2025 — meaning practices are being actively reviewed, not just investigated after a complaint.

Why This Matters for Small Businesses in Texas

If you're a small medical practice, dental office, optometry clinic, or any business that handles patient data, HIPAA applies to you at the same standard it applies to a major hospital system. The rules don't scale down based on company size.

Texas adds another layer. SB 2610 provides a cybersecurity safe harbor for businesses that maintain a recognized cybersecurity framework, but that protection only works if your framework actually accounts for HIPAA requirements where applicable. A cybersecurity program that ignores the Security Rule's safeguards isn't complete, and it won't hold up when it matters most.

The good news: you don't need a massive compliance department to get this right. You need a clear understanding of the rules, a security program that addresses them, and someone who can help you identify the gaps before a regulator or a breach does it for you.

Want to know where your practice stands on HIPAA?

AegisPro's Compliance Gap Analysis reviews your current security posture against HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule — and maps out exactly what's covered, what's missing, and what to do about it. Combined with an SB 2610 safe harbor assessment, you'll know whether your practice is protected on both fronts.

Learn more about Compliance Gap Analysis →

Find Out Where Your Practice Stands.

AegisPro will come to your location for 30 minutes, review how your practice handles patient data, and give you an honest read on your HIPAA and cybersecurity readiness. No cost, no contract, no obligation.

Schedule Free Walkthrough

Or call AegisPro directly at (817) 993-9427

AegisPro CyberShield TX
Cybersecurity Built for Texas Small Businesses

Sources Referenced

Next
Next

Texas New “Safe Harbor” Law