HIPAA, Protected health information
45 CFR Part 164, Subpart C
- What this page is
- HIPAA, Protected health information
- Checked against the official source
- 2026-08-15Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
Does HIPAA apply to your operation, and which paragraph decides?
HIPAA rests on 45 CFR Part 164, Subpart C and is tested here by a deterministic rule tree of 4 rules with a coverage score of 100 percent. The tree reads your facts, names the paragraph that decides the question and returns an outcome carrying citation, content hash and read date 2026-08-15. The outcome is a machine classification, not a compliance decision.
45 CFR Part 164, Subpart CChecked against the publisher 2026-08-15Official text
A source reference, not legal advice.
- Jurisdiction
- Federal
- Risk dimensions
- privacy, security, operations
- Tier
- Tier 1
- Coverage
- 100 %
- Impact
- 5/5
- Read
- 2026-08-15
Source chain
Every block in the register row has its own address, so an outcome can be cited down to the paragraph. The node carries the reference, the scope, the link to the official text and the outcomes in the tree that rest on the block.
- Administrative safeguards
45 CFR 164.308
Risk analysis, workforce access, training and incident procedures.
- Physical safeguards
45 CFR 164.310
Facility access, workstation use and media handling.
- Technical safeguards
45 CFR 164.312
Access control, audit controls, integrity and transmission security.
- Business associate contracts
45 CFR 164.314
Written terms with every party that handles the data on your behalf.
Rule tree
Rules are tested top down. Conditions are statutory elements and each outcome points to the register blocks it rests on.
hipaa-breach
The breach notification requirement applies
risk · Requirement applies · administrative, associates
45 CFR 164.408 requires notice to Health and Human Services without unreasonable delay and no later than 60 days after discovery when at least 500 individuals are affected. Notice to the individual is governed by 45 CFR 164.404.
hipaa-ba
The business associate agreement is absent
prohibited · Requirement applies · associates, administrative
45 CFR 164.308(b)(1) requires a written contract before a business associate creates, receives, maintains or transmits electronic protected health information on behalf of a covered entity. The content is governed by 45 CFR 164.314(a).
hipaa-risk
The risk analysis is absent
risk · Requirement applies · administrative
45 CFR 164.308(a)(1)(ii)(A) requires an accurate assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. The measures follow from 45 CFR 164.308(a)(1)(ii)(B).
hipaa-covered
The security rule safeguards apply
risk · Requirement applies · administrative, physical, technical
45 CFR 164.306(a) requires administrative, physical and technical safeguards for electronic protected health information. The individual requirements are in 45 CFR 164.308, 164.310 and 164.312, and documentation in 45 CFR 164.316.
Outcome
allowed · Outside the scope
The rule yields no requirement for the facts supplied
No role under 45 CFR 160.103 is stated, or no electronic protected health information is handled.
fallback · sha256:sha256:5df1e5c0edf5f1e231761d792
Monitoring
The journal shows what moved in the register row, with the hash before and after. The impact score follows a rule stated in plain words.
How impact is scored: Grund: tillagd eller borttagen uppgift ger 3, ändrad uppgift 2, omläsning utan ändring 0. Tillägg: +1 när ändringen rör status eller tillämpningsdatum. Tillägg: +1 när agenten ligger i klass 1. Siffran begränsas till 0 till 5.
2026-08-15 · 0/5 · lasning
Raden läst mot den officiella publiceringen utan ändring
2005-04-20 · 4/5 · tillampningsdatum, status
Regeln började tillämpas enligt utgivaren
2003-02-20 · 5/5 · antagande, identifierare, status
Regeln antogs enligt 45 CFR Part 164, Subpart C
Supervision
European counterparts
- gdpr-2016-679 · Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.
Artifacts and integrity
- https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/manifest.json
- https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/run
- https://legal.exploreworldai.com/api/public/v1/us-agents/hipaa/monitor.json
- sha256:d4db7e5f4bb8b5cc958b4c4d1c050f3118c77363fb60e669d4f469a5a7977ae4
- sha256:adedad323acd212e4e613a1931e7c4dd696c9b89a5ac14f6a95c03cd5aad33d7
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision. Responsibility position · 45 CFR Part 164, Subpart C
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act