Standards & Compliance

What is HIPAA?

Also known as: Health Insurance Portability and Accountability Act

Definition

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

HIPAA, the Health Insurance Portability and Accountability Act, was enacted by the U.S. Congress in 1996. It is a federal law that established, among other provisions, a set of national standards for the privacy and security of protected health information (PHI). The law applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates who handle PHI on their behalf.

The Privacy Rule (45 CFR 164.500-534) governs the use and disclosure of PHI, giving patients rights over their health information and setting limits on how that data can be used without authorization. The Security Rule (45 CFR 164.302-318) specifically addresses electronic PHI (ePHI) and requires administrative, physical, and technical safeguards to ensure its confidentiality, integrity, and availability. The Breach Notification Rule (45 CFR 164.400-414) mandates that covered entities notify affected individuals, the Secretary of HHS, and in some cases the media, following a breach of unsecured PHI.

In the wider infrastructure stack, HIPAA is not a technical protocol but a regulatory requirement that influences system architecture and data handling practices. Encryption of data at rest and in transit, access controls, audit logs, and business associate agreements are all common compliance measures. Engineers designing systems that process PHI must understand HIPAA's requirements as they affect deployment decisions, third-party vendor selection, and incident response procedures.

Key facts

  • Established national privacy and security standards for protected health information (PHI).
  • Applies to covered entities: providers, health plans, and clearinghouses plus their business associates.
  • Privacy Rule defines patient rights and permitted uses of PHI without authorization.
  • Security Rule mandates administrative, physical, and technical safeguards for electronic PHI.
  • Breach Notification Rule requires notification to individuals, HHS, and media for unsecured PHI breaches.

How it works in practice

A hospital must implement role-based access controls on its electronic health record system so that only physicians directly treating a patient can view that patient's full medical history. The same hospital must sign a business associate agreement with its cloud storage provider and encrypt all ePHI stored on that provider's servers. If a laptop containing unencrypted patient data is stolen, the hospital must notify all affected patients and the Secretary of Health and Human Services within 60 days.

Related terms

Protected Health Information (PHI) HITECH Act Business Associate Agreement Privacy Rule Security Rule Breach Notification Rule Covered Entity

References

More in Standards & Compliance

BCP 14

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

GDPR

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ISO 27001

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Regional Internet Registry

A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.

Who Is Online

In total there are 70 users online: 0 registered, 63 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369