CyberGlossary

Compliance & Frameworks

HIPAA

Also known as: Health Insurance Portability and Accountability Act

Definition

The U.S. Health Insurance Portability and Accountability Act, which sets national standards for protecting individually identifiable health information.

The Health Insurance Portability and Accountability Act of 1996 (HIPAA), implemented through the Privacy, Security, and Breach Notification Rules, sets U.S. national standards for protecting Protected Health Information (PHI). It applies to covered entities — health plans, healthcare providers conducting electronic transactions, and healthcare clearinghouses — and to their business associates handling PHI on their behalf. The Security Rule mandates administrative, physical, and technical safeguards (such as access controls, audit logs, transmission security, and risk analysis). The HHS Office for Civil Rights (OCR) enforces HIPAA and can impose civil and, for willful violations, criminal penalties.

Examples

  • A hospital encrypting PHI at rest and in transit to satisfy the Security Rule.
  • A SaaS vendor signing a Business Associate Agreement with a healthcare provider.

Related terms