There are numerous sites on the web that address this question, and cite the HIPAA provisions that apply.
The first link below seems like a good, quick how-to-do-it site. It's a couple of years old but still relevant. Read that one first.
The second link is to an official document from HHS that answers your question in much greater, but complicated, detail. It also has a good Q&A section at the end, but, again, is much more complex than the first link, the sum-it-up one.
The how-to-do-it site: HIPAA descript
ion from HHS: