Definition
HIPAA (Health Insurance Portability and Accountability Act of 1996) is the federal law that establishes national standards for the protection of individually identifiable health information (Protected Health Information, or PHI), governing how covered entities and their business associates collect, use, disclose, and safeguard patient data.
Comprehensive Definition
HIPAA is a comprehensive federal statute enacted in 1996 that established the first national standards for the protection of health information in the United States. The law is administered by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and is implemented through a series of regulations codified at 45 CFR Parts 160 and 164. HIPAA applies to "covered entities" — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically — and to their "business associates," which are entities that perform functions or services on behalf of covered entities that involve the use or disclosure of PHI.
The Privacy Rule (45 CFR Part 164, Subpart E) establishes national standards for the protection of PHI. It defines what constitutes PHI, specifies the conditions under which PHI may be used and disclosed, grants patients rights over their health information (including the right to access, amend, and receive an accounting of disclosures), and requires covered entities to implement administrative, physical, and technical safeguards to protect PHI. The Privacy Rule applies to PHI in any form — paper, electronic, or oral.
The Security Rule (45 CFR Part 164, Subpart C) establishes national standards specifically for the protection of electronic PHI (ePHI). It requires covered entities and business associates to implement administrative safeguards (e.g., security management processes, workforce training, access management), physical safeguards (e.g., facility access controls, workstation security), and technical safeguards (e.g., access controls, audit controls, encryption). The Security Rule is technology-neutral — it specifies what must be protected but does not mandate specific technologies.
The Breach Notification Rule (45 CFR Part 164, Subpart D) requires covered entities to notify affected individuals, HHS, and in some cases the media, following a breach of unsecured PHI. A breach is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. Covered entities must notify affected individuals within 60 days of discovering a breach; breaches affecting 500 or more individuals in a state must also be reported to prominent media outlets in that state.
The Enforcement Rule (45 CFR Part 160, Subpart C) establishes the procedures for investigating HIPAA complaints, conducting compliance reviews, and imposing civil money penalties. Penalties are tiered based on the level of culpability, ranging from $100 to $50,000 per violation, with an annual cap of $1.9 million per violation category. Criminal penalties under 42 U.S.C. § 1320d-6 can result in fines up to $250,000 and imprisonment up to 10 years for the most serious violations.
Why It Matters
HIPAA compliance is not optional for any entity that handles patient health information. The penalties for non-compliance are severe — HHS OCR has imposed settlements and civil money penalties totaling hundreds of millions of dollars since the Enforcement Rule took effect. High-profile HIPAA enforcement actions have targeted organizations of all sizes, from large hospital systems to small physician practices and telehealth startups.
Beyond the regulatory penalties, HIPAA violations expose organizations to significant reputational damage. Patients trust healthcare providers with their most sensitive personal information, and a data breach or privacy violation can permanently damage that trust. In an era of increasing patient awareness of data privacy rights, HIPAA compliance is also a competitive differentiator — patients choose providers who demonstrate a genuine commitment to protecting their information.
For healthcare entrepreneurs, HIPAA compliance must be built into the business from day one — not retrofitted after a breach or regulatory complaint. The cost of implementing HIPAA-compliant systems and processes upfront is a fraction of the cost of responding to a breach, defending a regulatory investigation, or paying a civil money penalty. The most successful healthcare businesses treat HIPAA compliance as a core operational competency, not a compliance checkbox.
Historical Background
HIPAA was enacted by Congress in 1996 with two primary goals: to improve the portability of health insurance coverage for workers changing jobs, and to reduce healthcare fraud and administrative costs through the standardization of electronic healthcare transactions. The privacy and security provisions of HIPAA were added to address concerns about the increasing use of electronic health records and the potential for misuse of patient health information.
The Privacy Rule was finalized in 2000 and took effect in 2003. The Security Rule was finalized in 2003 and took effect in 2005. The Breach Notification Rule was added by the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009, which also significantly strengthened HIPAA enforcement and extended HIPAA obligations directly to business associates. The HITECH Act increased the maximum annual penalty from $25,000 to $1.5 million per violation category (subsequently increased to $1.9 million by inflation adjustments).
The 21st Century Cures Act (2016) and subsequent HHS rulemaking have continued to evolve the HIPAA framework, particularly in the areas of information blocking, interoperability, and patient access to health information. HHS has also issued guidance on HIPAA compliance in the context of telehealth, mobile health applications, and cloud computing.
Federal Regulations
HIPAA is codified at 45 CFR Parts 160 and 164. The Privacy Rule is at 45 CFR Part 164, Subpart E. The Security Rule is at 45 CFR Part 164, Subpart C. The Breach Notification Rule is at 45 CFR Part 164, Subpart D. The Enforcement Rule is at 45 CFR Part 160, Subparts C, D, and E.
Criminal penalties for HIPAA violations are codified at 42 U.S.C. § 1320d-6. The HITECH Act provisions that strengthened HIPAA enforcement are codified at 42 U.S.C. § 17931 et seq.
HHS OCR has issued extensive guidance on HIPAA compliance, including guidance on telehealth, mobile health, cloud computing, and the use of online tracking technologies. This guidance, while not legally binding, reflects OCR's enforcement priorities and is an important resource for compliance planning.
State Considerations
HIPAA establishes a federal floor for health information privacy — states may enact more stringent privacy protections, but may not provide less protection than HIPAA. Many states have enacted health information privacy laws that are more stringent than HIPAA in specific areas. California's Confidentiality of Medical Information Act (CMIA) and the California Consumer Privacy Act (CCPA) impose additional privacy obligations on healthcare entities operating in California. Texas, New York, and other states have similar state-specific health privacy laws.
State breach notification laws may impose shorter notification timelines or broader notification obligations than HIPAA. For example, California requires notification of affected individuals "in the most expedient time possible and without unreasonable delay," which may be shorter than HIPAA's 60-day window. Operators must comply with both HIPAA and applicable state breach notification laws.
Mental health records, substance use disorder treatment records (governed by 42 CFR Part 2), HIV/AIDS records, and genetic information are subject to additional state and federal privacy protections beyond HIPAA. Operators in these specialty areas must layer these additional requirements on top of their HIPAA compliance program.
Common Mistakes
- Failing to execute Business Associate Agreements (BAAs) with all vendors and service providers that handle PHI — including EHR vendors, billing companies, IT providers, and cloud storage services.
- Not conducting a required Security Risk Assessment (SRA) — the Security Rule requires covered entities to conduct a thorough assessment of the potential risks and vulnerabilities to ePHI.
- Using personal email, text messaging, or consumer-grade communication tools to transmit PHI without appropriate safeguards.
- Failing to train workforce members on HIPAA requirements — the Privacy Rule requires covered entities to train all workforce members on their privacy policies and procedures.
- Not having a documented Breach Notification policy and response plan — organizations that discover a breach without a plan in place often make the situation worse by responding improperly.
- Assuming that HIPAA does not apply because the organization is small or cash-pay — HIPAA applies to any covered entity that transmits health information electronically, regardless of size or payer mix.
Operator Insight
HIPAA compliance is one of those areas where I see healthcare entrepreneurs make the same mistakes over and over. The most common is treating HIPAA as a paperwork exercise — signing a BAA here, posting a Notice of Privacy Practices there, and assuming the box is checked. It is not. HIPAA compliance is an ongoing operational commitment that requires regular risk assessments, workforce training, policy updates, and vendor management. The Security Risk Assessment is the foundation of HIPAA compliance, and it is the first thing OCR asks for in any investigation. If you have not done a formal SRA — not just a checklist, but a genuine assessment of the risks and vulnerabilities to your ePHI — you are not compliant. Period. The SRA needs to be documented, updated annually, and used to drive your security improvement roadmap. I also tell operators to think carefully about their vendor relationships. Every vendor that touches your patient data needs a BAA, and that BAA needs to be specific about what the vendor can and cannot do with PHI. Consumer-grade tools — Google Workspace, Dropbox, standard Zoom — are not HIPAA-compliant without a BAA and appropriate configuration. If your staff is using these tools to communicate about patients, you have a compliance gap that needs to be fixed immediately.
— AJ Pakpour, Healthcare Practice Startup & Strategy Expert
In Practice
A telehealth startup launches a platform for mental health services. Before accepting its first patient, the compliance team conducts a Security Risk Assessment, identifies the ePHI flows across the platform, and executes BAAs with all vendors that handle PHI — including the EHR vendor, the video conferencing provider, the billing company, and the cloud storage provider. The platform implements role-based access controls, encrypts ePHI in transit and at rest, and trains all workforce members on HIPAA requirements. A Breach Notification policy is documented and tested before launch. A small primary care practice discovers that a staff member has been sending patient appointment reminders via personal text message without patient authorization. The practice conducts a breach risk assessment, determines that the disclosure was a breach of unsecured PHI, and notifies the affected patients within 60 days. The practice also implements a corrective action plan that includes workforce retraining, a policy prohibiting the use of personal devices for patient communication, and the implementation of a HIPAA-compliant patient communication platform. The breach is reported to HHS OCR as required.
Frequently Asked Questions
References
Further Reading
Recommended Professional References
The following authoritative resources are recommended for healthcare professionals, clinic owners, compliance officers, and entrepreneurs working in this area. Links open official external websites.
HHS OCR is the primary HIPAA enforcement authority, publishing guidance, FAQs, and enforcement actions.
Best for: Compliance officers and healthcare providers
NIST provides cybersecurity frameworks and HIPAA Security Rule implementation guidance for healthcare organizations.
Best for: IT and compliance teams
ONC provides health IT standards, interoperability guidance, and HIPAA-related resources for electronic health records.
Best for: EHR administrators and health IT teams
AHIMA provides health information management resources, HIPAA compliance tools, and professional education.
Best for: HIM professionals and compliance officers
The AMA provides physician-focused HIPAA compliance resources, FAQs, and practice management guidance.
Best for: Physicians and practice administrators
Turn Knowledge Into Action
Apply what you just learned. Book a strategy session with AJ Pakpour — healthcare practice startup and strategy expert.
Book a Strategy Session