Skip to main content
Category: Regulatory Framework

45 CFR Part 160

Also known as: General Administrative Requirements, Part 160, HIPAA Administrative Requirements
Simply put

45 CFR Part 160 is the section of the federal HIPAA regulations that sets out general rules applying across the HIPAA framework, including key definitions, how compliance is investigated, and how penalties may be imposed. It provides the foundational terms and procedures that the more specific HIPAA rules build upon. Because it contains provisions that cross-cut the Privacy, Security, and Breach Notification rules, it is often read together with the other parts of the regulations rather than on its own.

Formal definition

45 CFR Part 160, titled 'General Administrative Requirements,' is a component of the HIPAA Administrative Simplification regulations administered by HHS. It generally contains foundational elements applied across the regulatory scheme, including the definitions in 45 CFR § 160.103 (such as covered entity, business associate, and related terms), preemption and general administrative provisions, and subparts addressing compliance and investigations, imposition of civil money penalties, and procedures for hearings. Part 160 is typically applied in conjunction with Part 164 (which houses the Security Rule, portions of the Privacy Rule, and the Breach Notification Rule) and Part 162; for example, the Privacy Rule is generally cited as 45 CFR Part 160 together with Subparts A and E of Part 164. Part 160 itself establishes cross-cutting definitions and enforcement mechanics rather than the substantive privacy or security safeguard standards, which are set out in Part 164. Practitioners should verify specific subpart contents, penalty tiers (which are adjusted over time and enforced by HHS OCR), and current text against the current Code of Federal Regulations, and should note that the HITECH Act, state law, and other frameworks may impose additional requirements beyond Part 160.

Why it matters

45 CFR Part 160 is foundational because it supplies the definitions and enforcement machinery that the rest of the HIPAA regulatory framework depends on. When a dispute arises over whether an organization is a covered entity or a business associate, or over what a given term means, the answer generally traces back to the definitions in 45 CFR § 160.103. Because these definitions cross-cut the Privacy, Security, and Breach Notification rules, misreading Part 160 can lead to fundamental compliance errors that ripple through an entire program.

Part 160 also matters because it houses the compliance, investigation, and penalty mechanics that HHS OCR uses to enforce HIPAA. Its subparts address how compliance is investigated, how civil money penalties may be imposed, and the procedures for hearings. In practice, this means Part 160 is the part of the regulation an organization is most likely to encounter directly during an OCR investigation or enforcement action, even though the substantive safeguard standards it may have violated live in Part 164.

Because penalty tiers and amounts are adjusted over time, and because the HITECH Act, state law, and other frameworks may impose additional obligations beyond Part 160, practitioners should treat this part as a starting point rather than a complete picture. Readers should confirm current definitions, subpart contents, and penalty figures against the current Code of Federal Regulations and current HHS OCR guidance.

Who it's relevant to

Privacy and Security Officers
Privacy and security officers rely on the definitions in 45 CFR § 160.103 to determine whether their organization is a covered entity or a business associate and which obligations flow through their relationships. Because Part 160 supplies cross-cutting terms used throughout the Privacy, Security, and Breach Notification rules, understanding it is generally a prerequisite to correctly applying the substantive standards found in Part 164.
Compliance Officers and Legal Counsel
Compliance officers and legal counsel engage directly with Part 160 during OCR investigations and enforcement actions, since its subparts govern compliance and investigations, imposition of civil money penalties, and procedures for hearings. They should note that penalty tiers are adjusted over time and confirm current figures against HHS OCR guidance, and should account for the HITECH Act and state law, which may impose additional requirements.
Auditors and Regulatory Analysts
Auditors and analysts mapping controls to regulatory requirements use Part 160 as the foundational reference point, reading it alongside Parts 162 and 164 rather than on its own. They should verify specific subpart contents and current text against the current Code of Federal Regulations, since Part 160 establishes definitions and enforcement mechanics rather than the specific safeguard standards housed in Part 164.

Inside 45 CFR Part 160

General Administrative Requirements
45 CFR Part 160 sets out the general administrative provisions that apply across the HIPAA Administrative Simplification rules, providing the overarching framework within which the Privacy Rule, Security Rule, and Breach Notification Rule (located in Part 164) operate.
Definitions (Subpart A)
Part 160 contains foundational definitions used throughout the HIPAA regulations, including key terms such as covered entity, business associate, and other concepts that establish who and what the rules apply to. These definitions carry specific regulatory meanings that may differ from common usage.
Preemption of State Law (Subpart B)
Part 160 addresses the relationship between HIPAA and state law, generally establishing that HIPAA provides a federal floor while more stringent state laws may still apply. Practitioners should verify specific preemption outcomes against the current regulatory text and applicable state law.
Compliance and Enforcement (Subparts C, D, and E)
Part 160 houses the Enforcement Rule provisions, including procedures for investigations, compliance reviews, imposition of civil money penalties, and hearing procedures. Enforcement is carried out by HHS OCR, and penalty tiers and amounts are adjusted over time and should be confirmed against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about 45 CFR Part 160.

Does 45 CFR Part 160 contain the actual Privacy and Security Rule requirements?
Not directly. Part 160 sets out the general administrative requirements that apply across the HIPAA regulations, including definitions, provisions on preemption of state law, and the compliance and enforcement procedures administered by HHS OCR. The substantive Privacy Rule standards are generally found in Part 164 (with Part 160 supplying overarching definitions and enforcement framework), and the Security Rule standards for ePHI also appear in Part 164. In most cases you should read Part 160 together with Parts 162 and 164 rather than expecting it to house the operative privacy or security safeguard requirements. Readers should verify the specific structure against the current regulatory text.
Does compliance with Part 160 mean my organization is fully HIPAA compliant?
No. Part 160 covers general provisions, preemption, and enforcement, but full HIPAA compliance depends on meeting the substantive obligations in the other parts, typically the Privacy Rule, the Security Rule's administrative, physical, and technical safeguards for ePHI, and the Breach Notification requirements. Satisfying the administrative and enforcement framework alone does not establish compliance with those substantive standards. Note that separate frameworks such as HITRUST CSF certification are private and do not by themselves establish HIPAA compliance, and that the HITECH Act and state law may impose additional requirements.
How does the preemption provision in Part 160 affect our compliance with state privacy laws?
Part 160 generally addresses when HIPAA preempts contrary state law and identifies exceptions, such as circumstances where a state law is more stringent. In practice this means HIPAA typically sets a baseline while more protective state requirements may still apply, so many organizations must comply with both. Because preemption analysis can be fact-specific and varies by state, organizations should assess overlapping state law obligations, often with legal counsel, rather than assuming HIPAA displaces all state requirements. Verify specifics against the current regulation and applicable state statutes.
Which entities are subject to the enforcement provisions in Part 160?
The compliance and enforcement provisions generally apply to covered entities and, as extended by later rulemaking, to business associates. Obligations for subcontractors and other vendors typically flow through business associate agreements rather than attaching automatically to any party that touches data. When mapping who is subject to enforcement in a given arrangement, identify each party's defined role and confirm the contractual relationships. Enforcement under HIPAA is administered by HHS OCR.
What should we understand about penalties referenced under the enforcement framework in Part 160?
Part 160 provides the procedural and enforcement framework under which HHS OCR may pursue civil money penalties, but the specific penalty tiers and dollar figures are adjusted over time. Because of this, you should not rely on a fixed amount; instead confirm current penalty tiers and figures against the latest OCR guidance and regulatory text. General planning should account for the fact that penalties may vary based on culpability and other factors defined in the enforcement provisions.
How should we use Part 160 when interpreting definitions that appear throughout the HIPAA regulations?
Part 160 generally supplies overarching definitions that apply across the HIPAA rules, so it is a useful starting point when a term's meaning is unclear. Because a defined regulatory term may differ from its common usage, teams should check the applicable definition before applying it operationally, and be aware that certain terms are further defined or refined within other parts such as Part 164. When definitions matter for a compliance decision, confirm the exact wording in the current regulatory text.

Common misconceptions

45 CFR Part 160 contains the actual Privacy and Security Rule requirements.
The substantive Privacy, Security, and Breach Notification Rule requirements are generally located in 45 CFR Part 164. Part 160 provides the general administrative framework, definitions, preemption provisions, and enforcement procedures that support those rules rather than the operational safeguard requirements themselves.
Because HIPAA is federal law, it fully overrides any conflicting state privacy laws.
Part 160's preemption provisions generally treat HIPAA as a federal floor. More stringent state laws may continue to apply, and other frameworks such as the HITECH Act may impose additional requirements. Specific preemption determinations should be verified against the current regulation and applicable state law.
The definitions in Part 160 mean the same thing as their everyday usage.
Terms defined in Part 160, such as covered entity and business associate, have specific regulatory meanings. Obligations attach through defined relationships rather than to every vendor that touches data, so these definitions should be read precisely against the regulatory text.

Best practices

Read Part 160 alongside Part 164, treating Part 160 as the definitional and administrative framework and Part 164 as the source of the substantive Privacy, Security, and Breach Notification requirements.
Rely on the specific regulatory definitions in Part 160 when determining whether an organization is a covered entity, business associate, or subcontractor, since obligations attach through these defined relationships.
Conduct a preemption analysis with qualified counsel to identify where more stringent state law, or frameworks such as HITECH, may impose obligations beyond the federal HIPAA floor.
When addressing enforcement risk, attribute investigation and penalty authority to HHS OCR and confirm current penalty tiers and amounts against present guidance, as figures are adjusted over time.
Verify any specific CFR subpart citations, definitions, or procedural details against the current published regulatory text before relying on them in compliance documentation.
Remember that voluntary frameworks such as the HITRUST CSF do not by themselves establish compliance with Part 160's requirements and should be treated as complementary rather than a legal substitute.