Back to TechSplainer
    HIPAA: Why the Paperwork Is the Requirement, Not the Afterthought

    HIPAA: Why the Paperwork Is the Requirement, Not the Afterthought

    TL;DR:

    HIPAA is the law that governs how health information gets protected, and the part most businesses underestimate is that it grades your process, not only your luck.

    Think of it like a restaurant health inspection. The inspector is not only asking whether anyone got sick. They are asking to see the temperature logs, the cleaning schedule, and the training records. A spotless kitchen with no paperwork still fails, because the paperwork is how you prove the kitchen is spotless on the days nobody is looking.

    On a good day nothing happens and the binder sits there. On a bad day that binder is the entire difference between an incident and a finding.


    Beyond the Basics:

    Here's the shift: HIPAA moved from a hospital concern to an everybody-who-touches-it concern, and a lot of businesses are inside its scope without having noticed.

    The Security Rule covers electronic protected health information and applies to covered entities, which is providers, health plans, and clearinghouses. Since the HITECH Act of 2009 it applies directly to business associates too: the IT provider, the backup vendor, the billing company, anyone handling that data on someone else's behalf. That direct liability is the part that catches service businesses out.

    1. Administrative safeguards. Risk analysis, workforce training, access management, and an incident response process. This is the largest category and the one most often thin.
    2. Physical safeguards. Facility access, workstation placement, and what happens to a device at the end of its life.
    3. Technical safeguards. Access control, audit logging, integrity checks, and transmission security.
    4. Documentation of all of it. Policies written down, decisions recorded, and evidence the process ran.

    The word to understand is addressable. Some specifications are Required and some are Addressable, and addressable does not mean optional. It means assess whether it is reasonable and appropriate in your environment, then either implement it or document why not and put an equivalent safeguard in place. Encryption sits here, which is why "we decided against encryption" with nothing written is a worse position than not having considered it.

    Here's the catch, and it is the most commonly misread number in the whole rule: the six-year retention requirement in 164.316 applies to your HIPAA documentation, from creation or last effective date, whichever is later. It is not a medical records retention period. HHS says plainly that the Privacy Rule sets no medical record retention period at all, and state law governs that instead. Confusing the two is how businesses end up keeping the wrong things for the wrong reasons. Get your actual schedule from counsel, not from a techsplainer.


    Learn More: