{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:q-hipaa-compliance",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/package/us:q-hipaa-compliance)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-10",
    "fingerprint": "ewai:se:fc57cb",
    "proof": "sha256:a4e86352bc06c16bcae3aa1cabe2b517f10b4407cbad9725d13b169f69a3b57c",
    "jurisdiction": "se",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "package",
  "object_id": "package:us:q-hipaa-compliance",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/package",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:q-hipaa-compliance",
  "source": "NovaCopilot",
  "item": {
    "question": "What must a US company do to comply with HIPAA?",
    "answer": "A covered entity must conduct a risk analysis and implement administrative, physical and technical safeguards, and sign business associate agreements. After a breach of unsecured health information it must notify affected individuals within 60 days, notify HHS, and notify the media when more than 500 residents of a state are affected (45 CFR 164.308 and 164.404 to 164.410).",
    "obligation": "obligation:us:hipaa-art-164-308-covered-entity",
    "exceptions": [],
    "deadline": null,
    "timeline": {
      "in_application": false,
      "next_milestone": null,
      "relative_deadlines": [
        "60 days",
        "60 days",
        "60 days",
        "60 days"
      ]
    },
    "source": {
      "title": "45 CFR 164.308 (HIPAA Security Rule)",
      "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C"
    },
    "contract": "frozen_core_v1",
    "frozen_fields": [
      "question",
      "answer",
      "obligation",
      "exceptions",
      "deadline",
      "timeline",
      "source"
    ],
    "complete_kit": {
      "kit_type": "flagship_question",
      "obligations": [
        {
          "id": "obligation:us:hipaa-art-164-308-covered-entity",
          "role": "covered-entity",
          "provision": "45 CFR 164.308 (HIPAA Security Rule)",
          "duty": "Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information.",
          "deadline": null,
          "source_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C"
        },
        {
          "id": "obligation:us:hipaa-art-164-404-covered-entity",
          "role": "covered-entity",
          "provision": "45 CFR 164.404 (HIPAA Breach Notification Rule)",
          "duty": "Notify each affected individual of a breach of unsecured protected health information without unreasonable delay.",
          "deadline": "60 days",
          "source_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D"
        },
        {
          "id": "obligation:us:hipaa-art-164-406-covered-entity",
          "role": "covered-entity",
          "provision": "45 CFR 164.406 (HIPAA Breach Notification Rule)",
          "duty": "Notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction.",
          "deadline": "60 days",
          "source_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D"
        },
        {
          "id": "obligation:us:hipaa-art-164-408-covered-entity",
          "role": "covered-entity",
          "provision": "45 CFR 164.408 (HIPAA Breach Notification Rule)",
          "duty": "Notify the Secretary of HHS of breaches of unsecured protected health information.",
          "deadline": "60 days",
          "source_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D"
        },
        {
          "id": "obligation:us:hipaa-art-164-410-business-associate",
          "role": "business-associate",
          "provision": "45 CFR 164.410 (HIPAA Breach Notification Rule)",
          "duty": "Notify the covered entity following discovery of a breach of unsecured protected health information.",
          "deadline": "60 days",
          "source_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D"
        }
      ],
      "sanctions": [
        {
          "id": "sanction:us:hipaa-art-1320d-5",
          "type": "civil_penalty",
          "authority": "HHS Office for Civil Rights",
          "max_amount": "USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3)",
          "max_turnover_pct": null,
          "provision": "42 U.S.C. § 1320d-5",
          "source_url": "https://www.law.cornell.edu/uscode/text/42/1320d-5"
        }
      ],
      "exceptions": [],
      "checklist": [
        "1. Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information (45 CFR 164.308 (HIPAA Security Rule)).",
        "2. Notify each affected individual of a breach of unsecured protected health information without unreasonable delay (45 CFR 164.404 (HIPAA Breach Notification Rule)).",
        "3. Notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction (45 CFR 164.406 (HIPAA Breach Notification Rule)).",
        "4. Notify the Secretary of HHS of breaches of unsecured protected health information (45 CFR 164.408 (HIPAA Breach Notification Rule)).",
        "5. Notify the covered entity following discovery of a breach of unsecured protected health information (45 CFR 164.410 (HIPAA Breach Notification Rule))."
      ],
      "leading_cases": [
        "us:iowa-25-2197-2026-10-02",
        "us:calctapp-e086667m-2026-09-23",
        "us:txctapp10-10-24-00353-cv-2026-09-17"
      ],
      "sme_kit": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/us:hipaa",
      "fetches_saved": 10,
      "note": "Everything needed to answer is embedded. Follow links only to verify."
    },
    "risk_level": "medium",
    "risk_reason": "Breach of 45 CFR 164.308 (HIPAA Security Rule): Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information.",
    "risk_consequence": "civil_penalty up to USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3) (HHS Office for Civil Rights)",
    "risk_source": {
      "provision": "42 U.S.C. § 1320d-5",
      "authority": "HHS Office for Civil Rights",
      "url": "https://www.law.cornell.edu/uscode/text/42/1320d-5"
    },
    "verification_state": "verified",
    "verified_at": "2026-08-31",
    "verified_sources": [
      "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C",
      "https://www.law.cornell.edu/uscode/text/42/1320d-5"
    ],
    "note": null,
    "related_packages": [
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-404-covered-entity",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-406-covered-entity",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-410-business-associate"
    ],
    "related_obligations": [
      "obligation:us:hipaa-art-164-404-covered-entity",
      "obligation:us:hipaa-art-164-406-covered-entity",
      "obligation:us:hipaa-art-164-408-covered-entity",
      "obligation:us:hipaa-art-164-410-business-associate"
    ],
    "related_exemptions": [],
    "related_cases": [
      "us:iowa-25-2197-2026-10-02",
      "us:calctapp-e086667m-2026-09-23",
      "us:txctapp10-10-24-00353-cv-2026-09-17"
    ],
    "related_authorities": [
      "HHS Office for Civil Rights"
    ],
    "related_statistics": [
      "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
      "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa"
    ],
    "last_changed": "2026-10-06",
    "change_type": "new_package",
    "change_reason": "Unchanged since first publication.",
    "previous_hash": null,
    "precedent_strength": "leading",
    "leading_cases": [
      "us:iowa-25-2197-2026-10-02",
      "us:calctapp-e086667m-2026-09-23",
      "us:txctapp10-10-24-00353-cv-2026-09-17"
    ],
    "contradicting_cases": [],
    "basis": "22 judgments in the register for hipaa.",
    "token_estimate": 203,
    "retrieval_equivalent_tokens_saved": 20797,
    "estimated_source_documents": 6,
    "method": "token_estimate = characters/4 of the frozen core. Retrieval equivalent: provision 1200, judgment 6000, sanction 600 tokens each.",
    "usable_without_further_analysis": true,
    "gaps": [],
    "generative_output": false,
    "attribution": "Source: NovaCopilot",
    "links": {
      "obligation": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-308-covered-entity",
      "compliance_effect": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-308-covered-entity",
      "exceptions": "https://legal.exploreworldai.com/api/public/v1/obj/exception/us:hipaa-art-164-308-covered-entity",
      "timeline": "https://legal.exploreworldai.com/api/public/v1/obj/timeline/us:hipaa",
      "risk_chain": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity",
      "changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes?type=package",
      "index": "https://legal.exploreworldai.com/api/public/v1/agent-packages"
    },
    "hash": "9a120a520d208606d9aa58bbab510d14bb5dd9305fa0191f3ad2f275971f4442"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:q-hipaa-compliance",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:q-hipaa-compliance",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:q-hipaa-compliance"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:q-hipaa-compliance?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "us:q-hipaa-compliance"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=us",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:a4e86352bc06c16bcae3aa1cabe2b517f10b4407cbad9725d13b169f69a3b57c",
  "version": "legal-2026-10-10",
  "expires": "2026-10-11T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-10+legal-2026-10-10+2026-10-10T14:46:25",
    "content_hash": "sha256:a4e86352bc06c16bcae3aa1cabe2b517f10b4407cbad9725d13b169f69a3b57c",
    "revalidate_after": "2026-10-10T15:50:52.879Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:q-hipaa-compliance",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}