How HIPAA got to be the way it is
The Security Rule was written in 2003, before the smartphone. That single fact explains most of what feels strange about applying it to a clinic whose workstation is a tablet in a family's living room.
Last verified: 2026-07-12
Read the Security Rule for ten minutes and you will notice something strange. It talks about facilities. It talks about maintenance records for doors and locks. It labels encryption as optional-sounding. It never mentions a phone.
That is not because the drafters were careless. It is because of when they were writing, and the timeline is worth knowing, because it explains almost everything that feels wrong about applying this rule to an ABA clinic in 2026.
1996: a law that was mostly about something else
HIPAA was signed in August 1996 (Public Law 104-191), and the part everyone now means by “HIPAA” was a small piece of it. The act’s main business was insurance portability: letting people keep coverage when they changed jobs. The privacy and security provisions were a subsection, and they were mostly an instruction to Congress to come back and legislate on health privacy within three years.
Congress did not. And the statute contained a fallback: if Congress failed to act, HHS would write the rules itself.
So the entire privacy and security regime that governs your clinic exists because Congress missed a deadline. That is not a cynical reading; it is the drafting history.
2000 and 2003: the two rules arrive, four years apart
The Privacy Rule was finalized in December 2000 (65 FR 82462) and revised in 2002, taking effect for most providers in 2003. It governs PHI in all forms, and its logic is the logic of a records office: who may see the chart, who may have a copy, what is written in the notice on the waiting room wall.
The Security Rule followed in February 2003 (68 FR 8334), with compliance required by 2005. And this is the date that explains your confusion.
Think about what a health care computing environment looked like in 2003. There was no iPhone; it arrived in 2007. There was no meaningful cloud storage; S3 launched in 2006. Records lived on desktop computers in buildings, or on servers in rooms in those buildings. The threat model was a stranger walking into a records room, or a laptop stolen from an office.
So the drafters wrote about facilities, because the data lived in buildings. They wrote about workstations, meaning desktop computers, and defined the term broadly enough (any device performing similar functions, plus the media in its immediate environment) that it would later, accidentally and correctly, capture the tablet in an RBT’s backpack. They made encryption addressable rather than required, because in 2003 encrypting everything was genuinely burdensome and the drafters chose flexibility.
Every one of those choices was reasonable in 2003. Several of them are the reason a clinic owner in 2026 reads the rule and thinks it was written for somebody else. It was. The three safeguard families still work, but their vocabulary is from a world where the data stayed still.
2009: HITECH, the year HIPAA grew teeth
For its first decade, HIPAA enforcement was thin. That changed with the HITECH Act in 2009, which did three things that matter enormously to a small clinic:
It created the Breach Notification Rule. Before 2009, there was no federal obligation to tell anyone when health data was exposed. The 60-day clock, the individual notices, the HHS reporting, the public breach portal: all of it is HITECH.
It made business associates directly liable. Before HITECH, your vendors’ obligations were purely contractual. After it, they answer to OCR themselves, and the modern BAA regime follows from it.
It raised the penalties, creating the tiered structure that still governs today, and gave state attorneys general enforcement authority.
If HIPAA is a rule with consequences today, that is 2009’s doing.
2013: the Omnibus Rule, and then silence
In January 2013, HHS published the Omnibus Rule (78 FR 5566), implementing HITECH: direct business associate liability, the current breach standard with its presumption and four-factor test, the modern penalty tiers, and the subcontractor chain.
And then, essentially, nothing.
That is the fact worth sitting with. The rules that govern your clinic’s technology have been substantially unchanged since 2013, and the technical core dates from 2003. In that time, ABA delivery moved into homes and schools, data collection moved onto tablets, sessions moved onto video, notes started being written by AI, and every clinic in the country put its records in somebody else’s cloud.
The rule did not follow. The rule was not written for you, and it governs you anyway. That is not a flaw in your understanding of it. It is the actual situation, and it is why this site spends so much of its time translating.
2024 and 2025: the attempted correction, and the reversal
Two recent events, in opposite directions.
“The rule was not written for you, and it governs you anyway. That is not a flaw in your understanding of it. It is the actual situation”
In April 2024, HHS finalized new reproductive health privacy protections. In June 2025, a federal court vacated nearly all of them nationwide, and HHS did not appeal. The text is still printed in the CFR and has no legal force.
In January 2025, HHS proposed the first real rewrite of the Security Rule in over two decades (90 FR 800): the end of the addressable category, mandatory encryption and multi-factor authentication, a required asset inventory. It is a proposal. It has not been finalized, and the federal agenda now shows final action pushed to 2027. Where all of that actually stands.
So the state of things is genuinely unusual: a 2003 technical rule, a 2013 enforcement framework, one attempted modernization stalled and another erased by a court, and an enforcement office pursuing everyone under the rule that already exists.
Why any of this matters to you
Three practical conclusions come out of the history.
The rule is more flexible than it looks, on purpose. The 2003 drafters knew they could not write technology requirements that would survive, so they wrote 45 CFR 164.306(b): use any measures reasonable and appropriate for your size, systems, budget, and risks. That clause is why a twelve-person clinic is not held to a hospital’s answer, and it exists precisely because the drafters knew the world would move.
The gaps are yours to fill honestly. Where the rule says facility and you have a living room, the rule does not stop applying. It asks what a reasonable clinic like yours would do about a workstation in a room you do not control. There is no lookup table for that. There is only an honest answer, written down.
And nothing coming will rescue you from the basics. The proposed rule, if it ever lands, mostly mandates what an honest risk analysis already concludes. The clinic doing the work today is prepared. The clinic waiting for clearer instructions has been waiting since 2003.
The short version
- HIPAA in 1996 was mostly about insurance portability; the privacy and security rules came later, and only because Congress failed to legislate them itself.
- The Security Rule was finalized in 2003, before smartphones, cloud storage, and the tablet in a family's living room. Its vocabulary of facilities and workstations dates from that world.
- HITECH in 2009 did the heavy lifting that made HIPAA bite: business associate liability, breach notification, and real penalties.
- The 2013 Omnibus Rule is the last major revision; the rule has been substantially unchanged for over a decade while practice transformed.
- Understanding the timeline explains why the rule feels written for a hospital: it was.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Health Insurance Portability and Accountability Act of 1996Public Law 104-191https://www.govinfo.gov/app/details/PLAW-104publ191
- Standards for Privacy of Individually Identifiable Health Information, final rule65 FR 82462, December 28, 2000https://www.federalregister.gov/documents/2000/12/28/00-32678/standards-for-privacy-of-individually-identifiable-health-information
- Health Insurance Reform: Security Standards, final rule68 FR 8334, February 20, 2003https://www.federalregister.gov/documents/2003/02/20/03-3877/health-insurance-reform-security-standards
- Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (the Omnibus Rule)78 FR 5566, January 25, 2013https://www.federalregister.gov/documents/2013/01/25/2013-01073/modifications-to-the-hipaa-privacy-security-enforcement-and-breach-notification-rules-under-the
- HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule, not in force)90 FR 800, January 6, 2025https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
- Security standards: General rules45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
An old rule, applied to the clinic you actually run.
The rule speaks about facilities and workstations. Your facility is a family's living room and your workstation is in a backpack. WiseUpHIPAA does that translation for you, honestly, and shows you where you really stand.