HIPAA Privacy Rule
The HIPAA Privacy Rule is a United States federal regulation that sets national standards for protecting people's medical records and other personal health information. It defines what health information is protected and sets rules for when and how that information may be used or shared. It applies to certain healthcare-related organizations and the partners who handle protected information on their behalf.
The HIPAA Privacy Rule is a regulation issued under the U.S. Health Insurance Portability and Accountability Act that establishes national standards for the protection of individually identifiable health information (protected health information, or PHI). It governs the permitted and required uses and disclosures of PHI held or transmitted by covered entities (such as health plans and healthcare providers that conduct certain electronic transactions) and, in most cases, their business associates. As a binding U.S. federal rule rather than a voluntary standard, it addresses privacy—the control over use and disclosure of health information—and is distinct from HIPAA's Security Rule, which addresses the safeguarding of electronic PHI. The Rule includes provisions permitting certain disclosures, for example sharing PHI with public health authorities authorized by law to collect it, subject to applicable conditions. Its scope is limited to the United States and to entities defined under HIPAA; application to specific facts requires professional judgment, and readers should verify details against the current official text as administered by the U.S. Department of Health and Human Services.
Why it matters
The HIPAA Privacy Rule is the foundational U.S. federal standard governing how personal health information may be used and disclosed. Because it carries the force of law rather than functioning as a voluntary framework, covered entities and their business associates are legally obligated to comply, and failures can trigger enforcement action by the U.S. Department of Health and Human Services. For organizations handling health information, the Rule establishes the baseline expectations that patients, regulators, and business partners rely on when trusting that medical records and other individually identifiable health information will not be improperly shared.
The Rule matters because it draws the line between permitted and prohibited uses of protected health information (PHI). It defines what health information is protected and specifies when and how that information may be shared, giving individuals a degree of control over their own health data. At the same time, it accommodates legitimate operational and public interest needs—for example, it allows the existing practice of sharing PHI with public health authorities that are authorized by law to collect or receive such information, subject to applicable conditions. This balance between individual privacy and necessary information flows is central to how the U.S. healthcare system handles sensitive data.
Because application depends heavily on specific facts—the nature of the entity, the type of information, and the purpose of a disclosure—organizations should treat the Rule as fact-specific rather than mechanical. Interpretations and enforcement practice can evolve, and the Rule is periodically amended, so readers should verify obligations against the current official text administered by HHS rather than relying on general summaries.
Who it's relevant to
Inside HIPAA Privacy Rule
Common questions
Answers to the questions practitioners most commonly ask about HIPAA Privacy Rule.
