Short answer: The HIPAA Privacy Rule governs how patient health information can be used and disclosed, and what rights patients have over their own records — regardless of whether that information is on paper or electronic. The HIPAA Security Rule specifically governs the technical, physical, and administrative safeguards protecting electronic protected health information (ePHI). Most compliance discussion, including much of what's written about small practices, focuses heavily on the Security Rule because it maps cleanly to specific technical requirements — but the Privacy Rule is a separate, equally real set of obligations most practices also need to address.
Why the distinction matters
It's common for a small practice to focus compliance effort entirely on Security Rule requirements — risk assessments, encryption, access controls — because those map to specific, checkable items. The Privacy Rule is less often discussed in the same detail, partly because its requirements are more about policies, patient rights, and permitted disclosures than about specific technical controls. But OCR enforces both, and a gap in Privacy Rule compliance is just as real a liability as a Security Rule gap, even if it's less frequently the headline topic.
What the Privacy Rule actually covers
Patient access rights. Patients generally have the right to access, inspect, and obtain a copy of their own medical records, typically within 30 days of a request. A practice without a clear, documented process for handling these requests is out of compliance with a specific, enforceable requirement.
The "minimum necessary" standard. When using or disclosing PHI for purposes other than treatment, practices generally need to limit what's shared to the minimum necessary to accomplish the purpose — not share a patient's full record when only a specific piece of information was actually needed.
Notice of Privacy Practices. Practices need to provide patients with a written notice describing how their health information may be used and disclosed, and patients' rights regarding that information. This is a specific, required document, not an optional courtesy.
Permitted uses and disclosures. The Privacy Rule defines when PHI can be used or shared without specific patient authorization (treatment, payment, and healthcare operations, generally) and when it requires explicit authorization (most marketing uses, for example).
Requirements around PHI regardless of format. Unlike the Security Rule, which is specifically about electronic PHI, Privacy Rule protections generally apply to PHI in any form — paper records, verbal communication, and electronic data alike.
What the Security Rule specifically covers
The Security Rule is narrower in scope by design: it applies specifically to electronic PHI, and requires administrative, physical, and technical safeguards — the risk assessment, access controls, encryption, and other technical measures covered extensively elsewhere in this context. It doesn't address a patient's right to access their paper chart, for instance, because that falls under the Privacy Rule instead.
Why both matter for a small practice's compliance program
A practice that's built a strong Security Rule program — solid risk assessment, encryption, access controls — but has never formalized a Notice of Privacy Practices, or has no documented process for patient record requests, has a real gap that a purely security-focused compliance effort wouldn't catch. Both rules need their own attention, even though they're often discussed together under the single umbrella of "HIPAA compliance."
Building a complete picture
A genuinely complete compliance program addresses both: the technical safeguards protecting your systems, and the policies governing how patient information is used, disclosed, and made accessible to patients themselves. Truvidence's compliance program is built around both sets of obligations, not just the Security Rule's technical requirements.