Health Insurance Portability and Accountability Act
HIPAA is a United States federal law, passed by Congress in 1996, that sets national standards to protect patients' medical records and other sensitive health information from unauthorized disclosure. It also originally aimed to improve the portability and continuity of health insurance coverage when people change or lose jobs. Because it is a statute rather than a voluntary framework, organizations within its scope are legally bound to comply.
HIPAA is a binding US federal statute enacted in 1996 that, among its original insurance-portability aims, establishes federal standards for protecting sensitive health information from disclosure. Its scope is jurisdictionally limited to the United States and, in practice, applies to defined categories of entities that handle protected health information rather than to all organizations universally; readers should verify the precise scope, covered entities, and applicable safeguards against the current authoritative text. HIPAA should be understood as enforceable law distinct from voluntary standards or certification schemes, and it is periodically amended, so its provisions and implementing regulations should be confirmed against the latest official sources. This entry addresses HIPAA's definition and character; it does not enumerate specific requirements, penalty amounts, effective dates, or compliance procedures, and application to particular circumstances requires professional judgment.
Why it matters
HIPAA is one of the foundational US federal laws governing the handling of health information, and for organizations within its scope, compliance is a legal obligation rather than a discretionary best practice. Unlike voluntary frameworks such as ISO/IEC 27001 or SOC 2, HIPAA carries the force of federal statute, meaning that entities that fall within its defined categories are bound to protect patients' medical records and other sensitive health information from unauthorized disclosure. For compliance officers, legal counsel, and information security professionals working in or with the US healthcare sector, understanding whether an organization or a particular data flow falls under HIPAA is a threshold question that shapes downstream obligations.
Who it's relevant to
Inside HIPAA
Common questions
Answers to the questions practitioners most commonly ask about HIPAA.

