What it is
HIPAA is the US federal framework that protects identifiable health information. Congress passed the Health Insurance Portability and Accountability Act in 1996, and the Department of Health and Human Services (HHS) turned its privacy and security provisions into regulations, found at 45 CFR Parts 160 and 164. Those regulations contain the Privacy Rule, the Security Rule and the Breach Notification Rule, and were strengthened by the HITECH Act of 2009 and the 2013 Omnibus Rule.
Who it applies to
HIPAA applies to "covered entities", which are health plans, health care clearinghouses, and health care providers that conduct certain transactions electronically. It also applies directly to their "business associates", meaning vendors that create, receive, maintain or transmit protected health information on their behalf, such as billing companies, cloud providers and IT contractors. Covered entities must have a written business associate agreement with each business associate. Health data held by organizations that are not covered entities or business associates, such as many consumer health apps, generally falls outside HIPAA.
Protected health information
The rules protect "protected health information" (PHI): individually identifiable health information, in any form, that relates to a person's health condition, health care or payment for care. Information that has been de-identified under the standards in the Privacy Rule, either by expert determination or by removing specified identifiers, is no longer PHI. Electronic PHI (ePHI) is also covered by the Security Rule.
The Privacy Rule
The Privacy Rule sets limits on how PHI may be used and disclosed. Covered entities may use and disclose it for treatment, payment and health care operations, and for certain public interest purposes, and otherwise need the individual's written authorization. Uses and disclosures must generally be limited to the minimum necessary. Individuals have the right to a notice of privacy practices, to access and obtain copies of their records, to request amendments, to receive an accounting of certain disclosures, and to request restrictions and confidential communications.
The Security Rule
The Security Rule requires covered entities and business associates to protect ePHI through administrative, physical and technical safeguards. Core requirements include a documented risk analysis, risk management, workforce training, access controls, audit controls, transmission security and contingency planning. Some specifications are "addressable", meaning the organization must implement them or document an equivalent alternative.
Breach Notification Rule
After a breach of unsecured PHI, a covered entity must notify affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people must also be reported to HHS within the same period and to prominent media outlets in the affected state or jurisdiction, while smaller breaches are reported to HHS annually. Business associates must notify the covered entity, and PHI that is properly encrypted is treated as secured.
Enforcement and penalties
The HHS Office for Civil Rights (OCR) enforces the rules, and state attorneys general can also bring civil actions. Civil money penalties are organized into tiers based on the level of culpability, with amounts that are adjusted annually for inflation, and OCR may also require corrective action plans. Knowingly obtaining or disclosing PHI in violation of HIPAA can be a criminal offence prosecuted by the Department of Justice. HIPAA does not give individuals a private right to sue, though state laws may.
The official text
The authoritative version is the Code of Federal Regulations, Title 45, Parts 160 and 164, published in the Electronic Code of Federal Regulations (eCFR) and by the US Government Publishing Office. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →