HIPAA

Also known as: Health Insurance Portability and Accountability Act

framework · governance and compliance · regulatory-standard

US law establishing privacy and security standards for protected health information.

The Health Insurance Portability and Accountability Act of 1996 established the foundational US framework for privacy and security of protected health information (PHI) held by covered entities — health plans, health care clearinghouses, and most health care providers — and their business associates. Specific requirements were promulgated through HHS regulations: the Privacy Rule (effective 2003) governs use and disclosure of PHI; the Security Rule (effective 2005) sets administrative, physical, and technical safeguards for electronic PHI; the Breach Notification Rule was added by the HITECH Act of 2009; and the 2013 Omnibus Rule strengthened business associate direct liability and extended enforcement reach. Enforcement is by the HHS Office for Civil Rights with civil monetary penalties tiered by culpability and corrective action plans for systemic issues.

Originators

United States Congress; US Department of Health and Human Services (HHS) administers; HHS Office for Civil Rights enforces high

Year / Decade

1996 (HIPAA); 2003 (Privacy Rule effective); 2005 (Security Rule effective); 2009 (HITECH Act); 2013 (Omnibus Rule) high

Primary sources

Public Law 104-191 (1996). Health Insurance Portability and Accountability Act, HITECH Act (Pub. L. 111-5, Title XIII, 2009), 45 CFR Parts 160 and 164 high

Core components

Primary use case

Privacy and security compliance for US health plans, providers, clearinghouses, and their business associates; framework for clinical and research information governance.

Common criticisms

Lineage

Child of
FIPPs
Siblings
GDPR, CCPA, FIPPs
Derived from
FIPPs