HIPAA Privacy Rule
The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates.
45 CFR Part 160 and Part 164 Subparts A and E · HHS Office for Civil Rights
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
HIPAA Privacy Rule is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Metadata only; the codified Privacy Rule has not been modelled as a requirement catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Uses and disclosures · Minimum necessary · Individual rights · Notices and authorizations · Administrative requirements
- Applies to
- healthcare · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 45 CFR Part 160 and Part 164 Subparts A and E | Current edition | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- HIPAA Security Rule45 CFR Part 164 Subparts A and C
Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
- HIPAA Breach Notification Rule45 CFR §§ 164.400–414
Also applies to healthcare · What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.
- Colorado AI ActSB 26-189
Also applies to healthcare · Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions.