45 CFR Part 160
45 CFR Part 160 is the section of the federal HIPAA regulations that sets out general rules applying across the HIPAA framework, including key definitions, how compliance is investigated, and how penalties may be imposed. It provides the foundational terms and procedures that the more specific HIPAA rules build upon. Because it contains provisions that cross-cut the Privacy, Security, and Breach Notification rules, it is often read together with the other parts of the regulations rather than on its own.
45 CFR Part 160, titled 'General Administrative Requirements,' is a component of the HIPAA Administrative Simplification regulations administered by HHS. It generally contains foundational elements applied across the regulatory scheme, including the definitions in 45 CFR § 160.103 (such as covered entity, business associate, and related terms), preemption and general administrative provisions, and subparts addressing compliance and investigations, imposition of civil money penalties, and procedures for hearings. Part 160 is typically applied in conjunction with Part 164 (which houses the Security Rule, portions of the Privacy Rule, and the Breach Notification Rule) and Part 162; for example, the Privacy Rule is generally cited as 45 CFR Part 160 together with Subparts A and E of Part 164. Part 160 itself establishes cross-cutting definitions and enforcement mechanics rather than the substantive privacy or security safeguard standards, which are set out in Part 164. Practitioners should verify specific subpart contents, penalty tiers (which are adjusted over time and enforced by HHS OCR), and current text against the current Code of Federal Regulations, and should note that the HITECH Act, state law, and other frameworks may impose additional requirements beyond Part 160.
Why it matters
45 CFR Part 160 is foundational because it supplies the definitions and enforcement machinery that the rest of the HIPAA regulatory framework depends on. When a dispute arises over whether an organization is a covered entity or a business associate, or over what a given term means, the answer generally traces back to the definitions in 45 CFR § 160.103. Because these definitions cross-cut the Privacy, Security, and Breach Notification rules, misreading Part 160 can lead to fundamental compliance errors that ripple through an entire program.
Part 160 also matters because it houses the compliance, investigation, and penalty mechanics that HHS OCR uses to enforce HIPAA. Its subparts address how compliance is investigated, how civil money penalties may be imposed, and the procedures for hearings. In practice, this means Part 160 is the part of the regulation an organization is most likely to encounter directly during an OCR investigation or enforcement action, even though the substantive safeguard standards it may have violated live in Part 164.
Because penalty tiers and amounts are adjusted over time, and because the HITECH Act, state law, and other frameworks may impose additional obligations beyond Part 160, practitioners should treat this part as a starting point rather than a complete picture. Readers should confirm current definitions, subpart contents, and penalty figures against the current Code of Federal Regulations and current HHS OCR guidance.
Who it's relevant to
Inside 45 CFR Part 160
Common questions
Answers to the questions practitioners most commonly ask about 45 CFR Part 160.