Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the agents

HIPAA, Protected health information

45 CFR Part 164, Subpart C

What this page is
HIPAA, Protected health information
Checked against the official source
2026-08-15Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position
Jurisdiction
Federal
Risk dimensions
privacy, security, operations
Tier
Tier 1
Coverage
100 %
Impact
5/5
Read
2026-08-15

Source chain

Every block in the register row has its own address, so an outcome can be cited down to the paragraph. The node carries the reference, the scope, the link to the official text and the outcomes in the tree that rest on the block.

45 CFR Part 164, Subpart C

Rule tree

Rules are tested top down. Conditions are statutory elements and each outcome points to the register blocks it rests on.

  1. hipaa-breach

    The breach notification requirement applies

    risk · Requirement applies · administrative, associates

    45 CFR 164.408 requires notice to Health and Human Services without unreasonable delay and no later than 60 days after discovery when at least 500 individuals are affected. Notice to the individual is governed by 45 CFR 164.404.

  2. hipaa-ba

    The business associate agreement is absent

    prohibited · Requirement applies · associates, administrative

    45 CFR 164.308(b)(1) requires a written contract before a business associate creates, receives, maintains or transmits electronic protected health information on behalf of a covered entity. The content is governed by 45 CFR 164.314(a).

  3. hipaa-risk

    The risk analysis is absent

    risk · Requirement applies · administrative

    45 CFR 164.308(a)(1)(ii)(A) requires an accurate assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. The measures follow from 45 CFR 164.308(a)(1)(ii)(B).

  4. hipaa-covered

    The security rule safeguards apply

    risk · Requirement applies · administrative, physical, technical

    45 CFR 164.306(a) requires administrative, physical and technical safeguards for electronic protected health information. The individual requirements are in 45 CFR 164.308, 164.310 and 164.312, and documentation in 45 CFR 164.316.

Outcome

allowed · Outside the scope

The rule yields no requirement for the facts supplied

No role under 45 CFR 160.103 is stated, or no electronic protected health information is handled.

fallback · sha256:sha256:5df1e5c0edf5f1e231761d792

Monitoring

The journal shows what moved in the register row, with the hash before and after. The impact score follows a rule stated in plain words.

How impact is scored: Grund: tillagd eller borttagen uppgift ger 3, ändrad uppgift 2, omläsning utan ändring 0. Tillägg: +1 när ändringen rör status eller tillämpningsdatum. Tillägg: +1 när agenten ligger i klass 1. Siffran begränsas till 0 till 5.

  • 2026-08-15 · 0/5 · lasning

    Raden läst mot den officiella publiceringen utan ändring

  • 2005-04-20 · 4/5 · tillampningsdatum, status

    Regeln började tillämpas enligt utgivaren

  • 2003-02-20 · 5/5 · antagande, identifierare, status

    Regeln antogs enligt 45 CFR Part 164, Subpart C

Supervision

European counterparts

  • gdpr-2016-679 · Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.

Artifacts and integrity

  • https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/manifest.json
  • https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/run
  • https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/monitor.json
  • sha256:d4db7e5f4bb8b5cc958b4c4d1c050f3118c77363fb60e669d4f469a5a7977ae4
  • sha256:adedad323acd212e4e613a1931e7c4dd696c9b89a5ac14f6a95c03cd5aad33d7

The verdict is a machine classification of the outcome, not legal advice and not a compliance decision. Responsibility position · 45 CFR Part 164, Subpart C

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit