Most health care practices put their compliance attention on the Security Rule’s technical safeguards and treat the Privacy Rule as an afterthought. That’s a mistake — it’s a distinct, equally enforceable set of obligations, and 2025’s enforcement record proves OCR is actively checking both.
Privacy Rule vs. Security Rule: Not the Same Thing
The Privacy Rule sets the conditions for use and disclosure of protected health information in any form — paper, verbal, or electronic. The Security Rule addresses the technical and administrative safeguards needed specifically to protect electronic PHI. A practice can be fully compliant with one and still have real gaps in the other, since they govern genuinely different aspects of how patient information gets handled.
What the Privacy Rule Actually Requires
Core requirements include defining permissible uses and disclosures of PHI with and without patient authorization, applying the “minimum necessary” standard, establishing patient rights around access, amendment, and accounting of disclosures, and maintaining transparency through a Notice of Privacy Practices along with consistent internal policies. The minimum necessary standard is where most violations happen in practice: granting broad PHI access to all workforce members by default, rather than restricting access by role with regular permission reviews, is a common and costly pattern.
Enforcement Has Never Been More Active
2025 already set a record for the highest number of HIPAA resolution agreements in a single year — 19 settlements and over $8 million in fines issued by HHS’s Office for Civil Rights through the year. Fines range from $137 to nearly $64,000 per violation, with annual caps reaching $2 million for severe or repeated non-compliance.
The Business Associate Blind Spot
Business associates are involved in roughly 36% of reported healthcare breaches, and OCR continues to fine covered entities specifically for sharing PHI without a signed Business Associate Agreement, or for failing to monitor a vendor’s compliance after signing one. A recent multi-million-dollar settlement stemmed partly from a missing BAA discovered during a breach investigation — not the breach itself, the missing paperwork.
The Website Risk Most Practices Don’t See
This has become a well-documented enforcement pattern: misconfigured third-party tracking tools have allowed practices to inadvertently collect and transmit sensitive patient data — names, IP addresses, appointment details — to outside platforms without patient consent or a covering BAA. Any practice running Google Analytics or marketing pixels on its website should specifically audit what patient data those tools might be capturing.
Who Needs to Own This
HIPAA requires designating both a Privacy Officer and a Security Officer. In a small practice, the same person, including the practice owner, can hold both roles — but someone must be formally designated and accountable. A practice without a clearly named individual in these roles has a documentation gap that surfaces quickly during any OCR investigation.
Staying Current
Privacy and security risk assessments should happen at least annually, or whenever a major change occurs — new systems, new vendors, expanded services — with more frequent ad hoc reviews for technical controls specifically. Treating the annual assessment as the only compliance touchpoint, rather than an ongoing practice, is a common and avoidable gap. Retention requirements run alongside this: administrative compliance documents need to be kept six years from creation or last effective date. See our data retention guide for how that fits into a broader policy.
How CelereTech Helps
CelereTech helps practices implement the access controls and monitoring that support the minimum necessary standard, audits vendor relationships and third-party tools — including website analytics — for BAA and data-flow gaps, and maintains the documentation retention needed to demonstrate compliance during an OCR review, addressing Privacy and Security Rule obligations as a connected whole.
Get your Privacy Rule compliance assessed alongside your Security Rule safeguards.