Definition

Health Insurance Portability and Accountability Act (HIPAA)

The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 federal law whose regulations set national standards for protecting health information and for electronic health care transactions, code sets and identifiers.

2 min readReviewed September 14, 2026

Also known as: HIPAA Privacy Rule, HIPAA Security Rule, Kennedy-Kassebaum Act, Public Law 104-191

Key facts

Public law
Public Law 104-191, enacted August 21, 1996
Regulations
45 CFR Parts 160, 162 and 164
Privacy and security enforcement
HHS Office for Civil Rights (OCR)
Transactions and code sets enforcement
CMS, on behalf of HHS
Applies to
Covered entities and their business associates

What is HIPAA?

HIPAA began largely as an insurance law. Title I limited how group health plans could exclude people for pre-existing conditions when they changed jobs. Title II, called Administrative Simplification, directed HHS to standardize electronic health care transactions and protect the privacy and security of health information.

Today HIPAA usually means its privacy and security regulations. They apply to covered entities (health plans, health care clearinghouses and health care providers that conduct standard electronic transactions) and to business associates that handle protected health information (PHI) for them.

How HIPAA is structured

HHS implements HIPAA through several rules:

  • Privacy Rule: limits uses and disclosures of PHI and gives individuals rights to access and amend their records.
  • Security Rule: requires administrative, physical and technical safeguards for electronic PHI.
  • Breach Notification Rule: added under the HITECH Act, requires notice to individuals, HHS and sometimes the media after a breach of unsecured PHI.
  • Transactions and Code Sets Rule: mandates standards such as X12 for claims and NCPDP for pharmacy, and code sets such as ICD-10.
  • Unique Identifiers Rules: established the National Provider Identifier (NPI) and the employer identifier.
  • Enforcement Rule: sets investigation procedures and civil money penalties.

Why HIPAA matters

HIPAA shapes how health data can be sourced, shared and joined:

  • Data sourcing: patient-level claims and EHR data from covered entities is shared for analytics mainly after de-identification or under specific permissions.
  • Vendor contracts: a company that handles PHI for a provider or plan needs a business associate agreement (BAA).
  • Claims analysis: transaction and code set standards are why claims share formats like the X12 837 and codes such as ICD-10-CM and HCPCS.
  • Provider data: HIPAA protects patient information, not clinicians' professional details, so registries such as NPPES are public.

Common misconceptions about HIPAA

HIPAA does not cover all health data. Information held by consumer apps, fitness trackers or employers acting outside a health plan is often outside HIPAA, though the FTC Health Breach Notification Rule and state privacy laws may apply. HIPAA also gives individuals no private right to sue under federal law.

The rules keep changing. HHS proposed a major Security Rule update in January 2025, and a federal district court vacated most of a 2024 reproductive health care privacy amendment in 2025. Check current HHS guidance before relying on a specific provision.

Sources

All glossary terms