HIPAA
Also known as: Health Insurance Portability and Accountability Act
US law establishing privacy and security standards for protected health information.
The Health Insurance Portability and Accountability Act of 1996 established the foundational US framework for privacy and security of protected health information (PHI) held by covered entities — health plans, health care clearinghouses, and most health care providers — and their business associates. Specific requirements were promulgated through HHS regulations: the Privacy Rule (effective 2003) governs use and disclosure of PHI; the Security Rule (effective 2005) sets administrative, physical, and technical safeguards for electronic PHI; the Breach Notification Rule was added by the HITECH Act of 2009; and the 2013 Omnibus Rule strengthened business associate direct liability and extended enforcement reach. Enforcement is by the HHS Office for Civil Rights with civil monetary penalties tiered by culpability and corrective action plans for systemic issues.
Core components
- Privacy Rule (uses and disclosures of PHI, minimum necessary standard, individual rights including access and accounting)
- Security Rule (administrative, physical, technical safeguards for ePHI
- addressable vs required specifications)
- Breach Notification Rule
- Business Associate Agreements
- Enforcement Rule
- Patient access rights
- Marketing and authorization restrictions
Primary use case
Privacy and security compliance for US health plans, providers, clearinghouses, and their business associates; framework for clinical and research information governance.
Common criticisms
- Covered-entity scope excludes much modern health-adjacent data (consumer health apps, wearables, brokers)
- 'minimum necessary' is subjective and inconsistently applied
- technology guidance lags cloud, AI/ML, and interoperability mandates (21st Century Cures)
- breach notification thresholds and methodology contested
- OCR enforcement uneven and resource-constrained
- tension between privacy and the 21st Century Cures Act information-blocking rule.
Lineage
- Child of
- FIPPs
- Siblings
- GDPR, CCPA, FIPPs
- Derived from
- FIPPs