Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Regulations & Laws

Health Insurance Portability and Accountability Act

Also known as: HIPAA, Health Insurance Portability and Accountability Act of 1996, HIPAA of 1996
Simply put

HIPAA is a United States federal law, passed by Congress in 1996, that sets national standards to protect patients' medical records and other sensitive health information from unauthorized disclosure. It also originally aimed to improve the portability and continuity of health insurance coverage when people change or lose jobs. Because it is a statute rather than a voluntary framework, organizations within its scope are legally bound to comply.

Formal definition

HIPAA is a binding US federal statute enacted in 1996 that, among its original insurance-portability aims, establishes federal standards for protecting sensitive health information from disclosure. Its scope is jurisdictionally limited to the United States and, in practice, applies to defined categories of entities that handle protected health information rather than to all organizations universally; readers should verify the precise scope, covered entities, and applicable safeguards against the current authoritative text. HIPAA should be understood as enforceable law distinct from voluntary standards or certification schemes, and it is periodically amended, so its provisions and implementing regulations should be confirmed against the latest official sources. This entry addresses HIPAA's definition and character; it does not enumerate specific requirements, penalty amounts, effective dates, or compliance procedures, and application to particular circumstances requires professional judgment.

Why it matters

HIPAA is one of the foundational US federal laws governing the handling of health information, and for organizations within its scope, compliance is a legal obligation rather than a discretionary best practice. Unlike voluntary frameworks such as ISO/IEC 27001 or SOC 2, HIPAA carries the force of federal statute, meaning that entities that fall within its defined categories are bound to protect patients' medical records and other sensitive health information from unauthorized disclosure. For compliance officers, legal counsel, and information security professionals working in or with the US healthcare sector, understanding whether an organization or a particular data flow falls under HIPAA is a threshold question that shapes downstream obligations.

Who it's relevant to

Healthcare compliance officers
Those responsible for compliance within US healthcare organizations need to assess whether their organization falls within HIPAA's defined scope and, where it does, to align internal controls with the statute's requirements. Because HIPAA is enforceable law rather than a voluntary framework, this analysis carries direct legal consequences and should be grounded in the current authoritative text.
Legal counsel and privacy specialists
Attorneys and data protection professionals advising on US health information matters must distinguish HIPAA's binding statutory obligations from voluntary standards, and must account for its jurisdictional limitation to the United States. They also need to identify which of HIPAA's dual aims — insurance portability or information protection — is engaged in a given matter.
Information security professionals
Security teams supporting organizations that handle protected health information should understand that HIPAA establishes federal standards for protecting sensitive health information from disclosure. While security controls support compliance, HIPAA is a legal obligation rather than a certification scheme, and applicable safeguards should be confirmed against the latest official sources.
Auditors and assessors
Professionals conducting reviews of US healthcare entities should treat HIPAA as a legal baseline distinct from voluntary standards against which certification is granted. Any assessment should reflect that covered-entity definitions and requirements are set by statute and implementing regulations that are periodically amended and should be verified for currency.

Inside HIPAA

Privacy Rule
Establishes national standards in the United States for the protection of individually identifiable health information, generally referred to as protected health information (PHI). It governs how covered entities may use and disclose PHI and grants individuals certain rights over their health information. It applies to PHI in any form, including oral, paper, and electronic.
Security Rule
Sets standards specifically for protecting electronic protected health information (ePHI). It generally requires covered entities and business associates to implement administrative, physical, and technical safeguards. Unlike the Privacy Rule, its scope is limited to health information in electronic form.
Breach Notification Rule
Generally requires covered entities and, where applicable, business associates to provide notification following a breach of unsecured PHI. Notification obligations may extend to affected individuals, the relevant federal authority, and in some cases the media, depending on the nature and scale of the breach. Specific thresholds and timeframes should be verified against the current official text.
Covered Entities
The categories of organizations directly subject to HIPAA, which generally include certain health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with covered transactions. Not every organization handling health data qualifies as a covered entity.
Business Associates
Persons or entities that perform functions or services involving PHI on behalf of a covered entity. They are generally subject to defined HIPAA obligations, typically formalized through a business associate agreement (BAA). This role is distinct from that of a covered entity, though certain obligations apply to both.
Protected Health Information (PHI)
Individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate. ePHI is the subset of PHI in electronic form to which the Security Rule applies.

Common questions

Answers to the questions practitioners most commonly ask about HIPAA.

Does HIPAA apply to every organization that handles health information?
No. HIPAA's obligations generally attach only to covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with certain transactions) and to their business associates. A great deal of health-related information held by other organizations—such as data collected by many consumer wellness apps, fitness trackers, or life insurers—may fall outside HIPAA entirely, though it could be subject to other laws such as state privacy statutes or the FTC Act. Whether HIPAA applies is fact-specific and turns on the organization's role rather than merely on the presence of health data. Readers should verify status against the current statutory and regulatory text.
Is HIPAA compliance something an organization can be certified in?
There is no official government HIPAA certification. HIPAA is a U.S. federal law enforced primarily by the Department of Health and Human Services Office for Civil Rights, not a voluntary certification scheme. Vendors may market 'HIPAA certified' or 'HIPAA compliant' attestations, but these are private assessments and do not confer legal safe harbor or a regulator's endorsement. Compliance is an ongoing obligation demonstrated through implemented safeguards, documentation, and practices—not a one-time credential. Any third-party assessment should be understood as informational rather than as proof of legal compliance.
What is the difference between a covered entity and a business associate under HIPAA?
A covered entity is generally a health plan, health care clearinghouse, or a health care provider that conducts certain transactions electronically. A business associate is, broadly, a person or organization that performs functions or services involving protected health information on behalf of a covered entity—such as claims processing, data storage, or analytics. Business associates are directly subject to certain HIPAA obligations and are typically bound by a business associate agreement that allocates responsibilities. The distinction affects which requirements apply and how liability is shared, so organizations should assess their specific role and relationships rather than assume a single status.
What is a business associate agreement and when is one generally needed?
A business associate agreement (BAA) is a contract that sets out the permitted uses and disclosures of protected health information and the safeguards a business associate must maintain. One is generally required before a covered entity discloses protected health information to a business associate, and comparable agreements are typically expected between business associates and their subcontractors that handle such information. The specific required terms are set by the applicable HIPAA rules and may be updated over time, so the current regulatory text and any organizational templates should be checked before relying on a particular form.
How do the HIPAA Privacy Rule and Security Rule relate to each other in practice?
The Privacy Rule generally governs the permitted uses and disclosures of protected health information across formats and establishes individual rights, while the Security Rule addresses the confidentiality, integrity, and availability of electronic protected health information through administrative, physical, and technical safeguards. In practice they are complementary but distinct: satisfying one does not automatically satisfy the other. Implementation typically involves mapping both sets of requirements to organizational processes and systems. Because the Security Rule's safeguards allow for flexibility based on factors such as organization size and risk, application is fact-specific and should be documented.
What is generally expected of an organization following a breach involving protected health information?
The HIPAA Breach Notification requirements generally call for notifying affected individuals and the Department of Health and Human Services following a breach of unsecured protected health information, with additional notification to the media in certain larger incidents; business associates are generally expected to notify the covered entity. Timing thresholds, content, and other specifics are set by the applicable rules and can vary, so organizations should confirm the current requirements and any overlapping state breach-notification laws. This describes the general structure only; whether a particular incident constitutes a reportable breach requires a fact-specific assessment and professional judgment.

Common misconceptions

HIPAA applies to any organization that handles health-related data.
HIPAA's obligations generally attach only to covered entities and their business associates as defined under the law. Many organizations that process health-related information, such as certain wellness apps or employers acting in that capacity, may fall outside HIPAA's scope, though other laws may still apply. Application to a specific organization requires case-specific analysis.
HIPAA is a global privacy standard comparable to the GDPR.
HIPAA is a United States federal law limited to specified health-sector actors and PHI. It is not a general data protection regime and does not govern personal data broadly across sectors or jurisdictions. It is distinct in scope, structure, and enforcement from frameworks such as the EU's GDPR.
Achieving 'HIPAA certification' proves an organization is compliant.
HIPAA is a regulation imposing legal obligations rather than a voluntary certification scheme, and there is no official government-issued HIPAA certification that confers compliance. Third-party attestations or assessments may support an organization's compliance efforts, but compliance is an ongoing legal obligation, not a certified status.

Best practices

Determine your organization's role under HIPAA—covered entity, business associate, or neither—since obligations differ by role, and document the basis for that determination.
Maintain current business associate agreements with all applicable vendors and downstream partners that handle PHI on your behalf.
Implement and periodically review administrative, physical, and technical safeguards for ePHI in line with the Security Rule, adjusting to the organization's size and risk profile.
Establish and test a breach response process so that any required notifications to individuals, authorities, or others can be made within applicable timeframes.
Treat compliance as an ongoing program rather than a one-time exercise, and periodically reassess as the regulation, guidance, and enforcement practice evolve.
Verify specific requirements, thresholds, and timeframes against the current official text and authoritative sources, and involve qualified professionals for application to your particular circumstances.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.