Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HIPAA is the Health Insurance Portability and Accountability Act of 1996. Its privacy, security, and breach-notification rules protect specified individually identifiable health information held or transmitted by covered entities and their business associates—not every organization that handles health data.

What is HIPAA?

HIPAA is a U.S. federal law. In everyday conversation, “HIPAA” often means the rules that implement it, especially the Privacy Rule, Security Rule, and Breach Notification Rule. Together, they set limits on certain uses and disclosures of protected health information (PHI), require safeguards, give people rights over certain records, and establish notification duties when unsecured PHI is breached.

PHI is individually identifiable health information held or transmitted by a covered entity or business associate, subject to the definitions and exclusions in the regulations. Electronic PHI, or ePHI, is the portion maintained or transmitted electronically; the Security Rule applies to ePHI. HIPAA is therefore not a universal health-data privacy law: whether it applies depends on the organization’s role, relationships, and information-handling activities.

Who has to comply with HIPAA?

Covered entities

HHS identifies three types of covered entities: health plans, health care clearinghouses, and health care providers that conduct specified standard electronic transactions. An organization’s label alone does not settle whether it is covered; its actual functions and transactions matter.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Business associates

A business associate is generally a person or organization performing services or activities for a covered entity that involve PHI. Certain subcontractors can also be business associates. Business associates are directly liable for certain HIPAA requirements, and covered entities generally must have written business associate arrangements that define the services and require appropriate safeguards.

Does HIPAA apply to employers?

Not merely because an organization is an employer. HHS says the Privacy Rule does not regulate employers in that role, life insurance companies, or public agencies delivering Social Security or welfare benefits merely by virtue of those roles. A particular organization may have a separate covered-entity or business-associate role depending on what it actually does.

Are health apps covered by HIPAA?

Not automatically. A health app that is not acting as a covered entity or business associate may fall outside HIPAA, even if it collects sensitive health information. Other laws may still apply: HHS and the Federal Trade Commission describe consumer health information protections that can involve the FTC Act or FTC Health Breach Notification Rule. The app’s relationships and activities, rather than the word “health” in its branding, determine the relevant analysis.

What is the difference between the HIPAA Privacy Rule and Security Rule?

Rule What it addresses What it means in practice
Privacy Rule Uses and disclosures of PHI, safeguards, and individual rights. Organizations must apply limits and conditions to PHI handling and support rights that include inspecting and obtaining records, requesting corrections, and directing a covered entity in specified circumstances to send an electronic copy in an electronic health record to a third party.
Security Rule Protection of ePHI. Covered entities and business associates must use appropriate administrative, physical, and technical safeguards to protect ePHI’s confidentiality, integrity, and availability. HHS describes the standard as flexible and technology-neutral, with measures suited to the organization’s circumstances and risks.
Breach Notification Rule Breaches of unsecured PHI. It establishes when and how affected people, HHS, and sometimes the media must be notified. A business associate notifies the covered entity.

What does HIPAA compliance involve?

HIPAA compliance is an ongoing set of duties, not a certification or a single software purchase. The work depends on the organization’s role and the PHI it handles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Determine the role and map the information. Establish whether the organization is a covered entity or business associate, then identify where PHI is created, received, maintained, or transmitted.
  2. Build privacy processes. Apply Privacy Rule limits, safeguards, and processes for individual rights requests.
  3. Manage security risks to ePHI. Conduct a security risk analysis and implement reasonable and appropriate administrative, physical, and technical measures. Address reasonably anticipated threats and workforce compliance.
  4. Manage business associate relationships. Put suitable written arrangements in place and address subcontractor duties where applicable.
  5. Prepare for incidents. Maintain a process to assess impermissible uses or disclosures, document breach determinations, and make any required notifications.

A tool can support tasks such as risk assessment, documentation, or business associate management, but purchasing software does not by itself make an organization HIPAA-compliant. HHS notes that its Security Rule summary is not comprehensive legal guidance; the regulation controls if a summary conflicts with it.

What counts as a HIPAA violation?

A violation can involve failing to meet an applicable HIPAA requirement—for example, an impermissible use or disclosure of PHI, inadequate safeguards, or failure to meet an applicable individual-rights or notification duty. Whether a rule applies, what happened, and which entity had the relevant obligation all matter; not every mishandling of health information is automatically a HIPAA violation.

An impermissible use or disclosure is generally presumed to be a breach unless an exception applies or the covered entity or business associate demonstrates a low probability that PHI was compromised through a risk assessment. HHS says that assessment considers:

  • The nature and extent of the PHI, including identifiers and the likelihood of re-identification.
  • Who received or used the information.
  • Whether the information was actually acquired or viewed.
  • What steps were taken to mitigate the risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happens if HIPAA is violated?

Assess the incident and any notice duties

The organization must assess the facts and determine whether the event is a breach of unsecured PHI, whether an exception applies, or whether the risk assessment supports a low probability that the PHI was compromised. Notice requirements vary with the facts; a privacy incident does not always trigger identical notices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Notify affected people and authorities when required

For a breach affecting 500 or more individuals, HHS says the covered entity must report it to the Secretary without unreasonable delay and no later than 60 days after discovery. For a breach affecting fewer than 500 individuals, a covered entity may report annually, with the report due no later than 60 days after the end of the calendar year in which it discovered the breach. Individual notice and, in some cases, media notice also apply. A business associate must notify the covered entity after discovery.

OCR may investigate and enforce

The HHS Office for Civil Rights (OCR) administers and enforces HIPAA standards through complaint investigations and compliance reviews. Civil money penalties can depend on the circumstances and are adjusted over time, so an undated dollar figure can be misleading. The applicable requirements and exceptions should be checked against current HHS guidance and regulations.

What is a business associate agreement?

A business associate agreement is the written arrangement generally required when a business associate performs services or activities for a covered entity involving PHI. It defines the services and requires appropriate safeguards; applicable duties must also be managed through relevant subcontractor relationships. A vendor’s claim that a product is “HIPAA-compliant” is not a substitute for determining the parties’ roles, documenting the arrangement, and meeting the organization’s own obligations.

How to report a possible HIPAA violation

People who believe a covered entity or business associate has violated their HIPAA privacy rights can submit a complaint to HHS OCR. The concern should identify the organization and describe what happened; retain relevant records such as correspondence or notices. OCR investigates complaints and conducts compliance reviews, but not every report will establish a violation. For an active breach or suspected exposure, contacting the organization’s privacy or security office may also help it assess and contain the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.