HIPAA
Health Insurance Portability and Accountability Act: Privacy, Security and Breach Notification Rules
Governs protected health information held by the health care system and its vendors: permitted uses and disclosures, patient rights, security safeguards for electronic records, and breach notice.
The law in brief
HIPAA sets the federal rules for protecting health information in the United States. Its Privacy Rule governs how protected health information may be used and shared, its Security Rule sets safeguards for electronic health information, and its Breach Notification Rule sets who must be told, and how fast, when unsecured health information is compromised.
It applies to covered entities and to the business associates that handle health information for them, and each carries its own direct duties.
Who it applies to
- Covered entities: health plans, health care clearinghouses, and health care providers that conduct standard transactions electronically, such as billing insurance.
- Business associates: vendors and contractors that create, receive, keep or transmit protected health information for a covered entity, and their subcontractors.
- It covers protected health information: individually identifiable health information in any form, held by a covered entity or business associate.
- Health data outside these relationships, such as many consumer health apps, is usually outside HIPAA and falls under state privacy laws and the FTC.
What it requires
Use and share only as permitted
Use or disclose protected health information only as the Privacy Rule permits or the individual authorizes, and limit most uses to the minimum necessary for the purpose.
A documented security risk analysis
Assess the risks to the confidentiality, integrity and availability of electronic protected health information, and put administrative, physical and technical safeguards in place to reduce them.
Business associate agreements
Before a vendor handles protected health information for you, sign an agreement that limits its uses and requires safeguards, breach reporting and flow-down to subcontractors.
A notice of privacy practices
Give individuals a plain-language notice of how their information may be used and of their rights, and post it where required.
Tell individuals about breaches within 60 days
Notify each affected individual of a breach of unsecured protected health information without unreasonable delay. The clock starts when the breach is known, or would have been known with reasonable diligence.
Tell HHS, and the media for large breaches
Report breaches affecting 500 or more people to HHS at the same time as individuals, and notify prominent media where more than 500 residents of a state are affected. Log smaller breaches and report them to HHS within 60 days of the end of the year.
People's rights
Individuals can:
- get a copy of their records, generally within 30 days, with one 30-day extension (45 CFR 164.524);
- ask for corrections (164.526);
- get an accounting of certain disclosures (164.528);
- ask for restrictions and for communications by other means or at other locations (164.522);
- receive a notice of privacy practices (164.520);
- complain to the HHS Office for Civil Rights.
Enforcement and penalties
Civil money penalties in four tiers based on the level of culpability, from violations the entity did not know about to willful neglect left uncorrected, with annual caps; the amounts are adjusted for inflation each year. The HHS Office for Civil Rights enforces, often through settlements with corrective action plans, and state attorneys general can also bring actions. Knowingly obtaining or disclosing protected health information in violation of HIPAA is a federal crime.
What's changing
Proposed, not final. HHS proposed a major update to the Security Rule in January 2025, including removing the distinction between required and addressable safeguards and requiring measures such as encryption and multi-factor authentication. Until a final rule takes effect, the current rule applies. Regulatory Watch reports its status.
What to do first
- Confirm your role for each relationship: covered entity, business associate, or neither.
- Run and document a security risk analysis, then manage the risks it finds.
- Inventory business associates and put a compliant agreement in place with each.
- Check your notice of privacy practices and your process for access requests within 30 days.
- Apply the minimum necessary standard to routine uses and disclosures.
- Rehearse a breach: the four-factor risk assessment, and the 60-day clock from discovery.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
The piece provides practitioners with case‑law guidance on how pixel‑tracking claims are being evaluated under federal and state privacy statutes ahead of the Salazar v. Paramount Supreme Court review. EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple district‑court rulings that recognize standing when companies collect IP addresses, health data, or other sensitive information without user consent, and highlights circuit splits on what constitutes an intrusion upon seclusion.
Source: EPIC. HIPAA in the regulations library.
Sources
- 45 CFR Part 164 (Security and Privacy) eCFR · Official text or regulator