Definition
Health Insurance Portability and Accountability Act (HIPAA)
The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 federal law whose regulations set national standards for protecting health information and for electronic health care transactions, code sets and identifiers.
2 min readReviewed September 14, 2026
Also known as: HIPAA Privacy Rule, HIPAA Security Rule, Kennedy-Kassebaum Act, Public Law 104-191
Key facts
- Public law
- Public Law 104-191, enacted August 21, 1996
- Regulations
- 45 CFR Parts 160, 162 and 164
- Privacy and security enforcement
- HHS Office for Civil Rights (OCR)
- Transactions and code sets enforcement
- CMS, on behalf of HHS
- Applies to
- Covered entities and their business associates
What is HIPAA?
HIPAA began largely as an insurance law. Title I limited how group health plans could exclude people for pre-existing conditions when they changed jobs. Title II, called Administrative Simplification, directed HHS to standardize electronic health care transactions and protect the privacy and security of health information.
Today HIPAA usually means its privacy and security regulations. They apply to covered entities (health plans, health care clearinghouses and health care providers that conduct standard electronic transactions) and to business associates that handle protected health information (PHI) for them.
How HIPAA is structured
HHS implements HIPAA through several rules:
- Privacy Rule: limits uses and disclosures of PHI and gives individuals rights to access and amend their records.
- Security Rule: requires administrative, physical and technical safeguards for electronic PHI.
- Breach Notification Rule: added under the HITECH Act, requires notice to individuals, HHS and sometimes the media after a breach of unsecured PHI.
- Transactions and Code Sets Rule: mandates standards such as X12 for claims and NCPDP for pharmacy, and code sets such as ICD-10.
- Unique Identifiers Rules: established the National Provider Identifier (NPI) and the employer identifier.
- Enforcement Rule: sets investigation procedures and civil money penalties.
Why HIPAA matters
HIPAA shapes how health data can be sourced, shared and joined:
- Data sourcing: patient-level claims and EHR data from covered entities is shared for analytics mainly after de-identification or under specific permissions.
- Vendor contracts: a company that handles PHI for a provider or plan needs a business associate agreement (BAA).
- Claims analysis: transaction and code set standards are why claims share formats like the X12 837 and codes such as ICD-10-CM and HCPCS.
- Provider data: HIPAA protects patient information, not clinicians' professional details, so registries such as NPPES are public.
Common misconceptions about HIPAA
HIPAA does not cover all health data. Information held by consumer apps, fitness trackers or employers acting outside a health plan is often outside HIPAA, though the FTC Health Breach Notification Rule and state privacy laws may apply. HIPAA also gives individuals no private right to sue under federal law.
The rules keep changing. HHS proposed a major Security Rule update in January 2025, and a federal district court vacated most of a 2024 reproductive health care privacy amendment in 2025. Check current HHS guidance before relying on a specific provision.