Home / Blog / Exploring HIPAA Compliance?
Compliance

Exploring HIPAA Compliance?

Last reviewed July 2026 — spelling, contact details, and cost figures corrected with sources.

At Jarato, we understand that navigating the complexities of HIPAA can feel overwhelming. Below, we’ve broken down the key aspects of HIPAA compliance to help you better understand your obligations and how to proceed.

What is HIPAA?

HIPAA (Health Insurance Portability and Accountability Act) is a U.S. federal law enacted in 1996 to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. It also aims to make healthcare more efficient by setting standards for electronic health transactions.

Why do I need to know about PHI?

Protected Health Information (PHI) includes any data that can identify a patient, such as medical records, billing information, or even spoken conversations. Understanding PHI is critical because mishandling it can lead to severe legal consequences. PHI must be safeguarded to ensure patient privacy and prevent identity theft.

Who needs to comply with HIPAA?

HIPAA applies to "covered entities" which include:

  • Healthcare providers (e.g., doctors, clinics, hospitals)

  • Health plans (e.g., insurance companies)

  • Healthcare clearinghouses
    Additionally, "business associates" who handle PHI on behalf of covered entities must also comply.

What does it cover?

HIPAA covers all forms of PHI—whether it's written, electronic, or even spoken. This includes medical records, billing information, and any other data that could identify an individual. It also sets rules for how this information can be shared and stored.

What’s the law for this compliance?

The primary laws governing HIPAA compliance are the Privacy Rule, Security Rule, and Breach Notification Rule. These rules outline how PHI should be protected, what safeguards must be in place (administrative, technical, and physical), and what steps must be taken in the event of a breach.

What are the steps to be compliant?

In our experience, we recommend the following steps for achieving HIPAA compliance:

  1. Appoint a HIPAA Compliance Officer: This person will oversee all compliance activities.

  2. Conduct a Risk Assessment: Identify potential risks to PHI.

  3. Implement Safeguards: Administrative, physical, and technical safeguards must be put in place.

  4. Develop Policies and Procedures: Create clear guidelines for handling PHI.

  5. Training: Train your workforce on HIPAA requirements.

  6. Regular Audits: Conduct internal audits to ensure ongoing compliance.

How much does it cost to be HIPAA compliant?

The cost of achieving compliance varies widely with organization size, scope, and whether work is handled internally or with outside support. Rather than budgeting to a single figure, plan for the components: risk assessments, training programs, software solutions, and legal consultation.

What is the cost of non-compliance?

Non-compliance is far more expensive than compliance. Under the HHS Office for Civil Rights penalty schedule in effect since January 28, 2026, civil monetary penalties range from $145 to $2,190,294 per violation depending on the culpability tier, with an annual cap of $2,190,294 per identical provision (HIPAA Journal, 2026 penalty schedule). And the breach behind a violation carries its own price: the average cost of a healthcare data breach was $7.42 million in 2025 — the highest of any industry for the 14th consecutive year (IBM Cost of a Data Breach Report 2025).

Do I need my vendors to be compliant?

Yes! If your vendors handle PHI on your behalf (e.g., cloud storage providers or billing services), they must also be HIPAA-compliant. You should have a Business Associate Agreement (BAA) in place with each vendor to ensure they meet HIPAA standards.

Does HIPAA overlap with any other regulation?

Yes, HIPAA often overlaps with other regulations like the HITECH Act (Health Information Technology for Economic and Clinical Health), which strengthens certain aspects of HIPAA related to electronic health records. Additionally, state laws may impose stricter requirements than HIPAA.

I find HIPAA confusing and complex; what resources are available?

We recommend several resources:

  • The U.S. Department of Health and Human Services (HHS) offers extensive guidance on its website.

  • Tools like the Security Risk Assessment Tool provided by HHS can help small businesses conduct risk assessments.

  • Industry organizations like AHIMA or HIMSS provide additional toolkits and webinars.

Is there a checklist I can refer to before proceeding for compliance?

Yes! Here is our recommended checklist that includes:

  • Appointing a Privacy Officer

  • Conducting risk assessments

  • Implementing administrative/technical/physical safeguards

  • Training employees

  • Reviewing Business Associate Agreements


    This checklist will help you cover all the essential areas of HIPAA compliance.

By taking these steps now, you’ll not only avoid costly penalties but also build trust with your patients by ensuring their sensitive information is protected. Let us know how we can assist you further!

I need help; where can I get it?

Jarato offers tailored consulting services including risk assessments, policy development, employee training, and ongoing audit support. We also provide dynamic tools that streamline compliance processes such as risk management software and automated reminders for annual updates. Reach out to the Jarato team by sending an email to info@jarato.io or filling out this form https://www.jarato.io/contact.

Talk with Jarato

Questions about how this applies to your organization? Reach out for a conversation — no prepared pitch, no obligation.

Schedule a Consultation