What is HIPAA?
Also known as: Health Insurance Portability and Accountability Act
HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.
HIPAA, the Health Insurance Portability and Accountability Act, was enacted by the U.S. Congress in 1996. It is a federal law that established, among other provisions, a set of national standards for the privacy and security of protected health information (PHI). The law applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates who handle PHI on their behalf.
The Privacy Rule (45 CFR 164.500-534) governs the use and disclosure of PHI, giving patients rights over their health information and setting limits on how that data can be used without authorization. The Security Rule (45 CFR 164.302-318) specifically addresses electronic PHI (ePHI) and requires administrative, physical, and technical safeguards to ensure its confidentiality, integrity, and availability. The Breach Notification Rule (45 CFR 164.400-414) mandates that covered entities notify affected individuals, the Secretary of HHS, and in some cases the media, following a breach of unsecured PHI.
In the wider infrastructure stack, HIPAA is not a technical protocol but a regulatory requirement that influences system architecture and data handling practices. Encryption of data at rest and in transit, access controls, audit logs, and business associate agreements are all common compliance measures. Engineers designing systems that process PHI must understand HIPAA's requirements as they affect deployment decisions, third-party vendor selection, and incident response procedures.
Key facts
- Established national privacy and security standards for protected health information (PHI).
- Applies to covered entities: providers, health plans, and clearinghouses plus their business associates.
- Privacy Rule defines patient rights and permitted uses of PHI without authorization.
- Security Rule mandates administrative, physical, and technical safeguards for electronic PHI.
- Breach Notification Rule requires notification to individuals, HHS, and media for unsecured PHI breaches.
How it works in practice
Related terms
References
More in Standards & Compliance
BCP 14
BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.
BCP 38
BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.
GDPR
The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.
IANA
IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.
ICANN
ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.
IETF
The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.
ISO 27001
ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
ITU-T
ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.
PCI DSS
PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.
Regional Internet Registry
A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.