Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 532

HIPAA

Reviewed byCybersecurity entrepreneur & security researcher

What is HIPAA?

HIPAAThe U.S. Health Insurance Portability and Accountability Act, which sets national standards for protecting individually identifiable health information.


The Health Insurance Portability and Accountability Act of 1996 (HIPAA), implemented through the Privacy, Security, and Breach Notification Rules, sets U.S. national standards for protecting Protected Health Information (PHI). It applies to covered entities — health plans, healthcare providers conducting electronic transactions, and healthcare clearinghouses — and to their business associates handling PHI on their behalf. The Security Rule mandates administrative, physical, and technical safeguards (access controls, audit logs, transmission security, and risk analysis). The 2009 HITECH Act strengthened enforcement and, via the Breach Notification Rule, requires notifying affected individuals and HHS — within 60 days for large breaches (500+ individuals).

Enforcement is tangible. The HHS Office for Civil Rights (OCR) investigates and imposes tiered civil penalties, and for willful neglect, criminal referral. The record settlement followed the 2015 Anthem breach: attackers entered through a spearphishing email and exfiltrated 78.8 million records, leading to a $16 million OCR settlement in 2018 — nearly triple the previous high of $5.55 million.

flowchart TD
  PHI[Protected Health Information] --> CE[Covered entity<br/>provider / plan / clearinghouse]
  CE -->|BAA contract| BA[Business associate]
  CE --> RULES{HIPAA Rules}
  BA --> RULES
  RULES --> PR[Privacy Rule]
  RULES --> SR[Security Rule<br/>admin/physical/technical safeguards]
  RULES --> BN[Breach Notification<br/>≤60 days if 500+]
  RULES -->|violation| OCR[HHS OCR enforcement<br/>tiered civil + criminal penalties]

Practical controls: encrypt PHI at rest and in transit, enforce least-privilege access with audit logging, run periodic risk analyses, and sign Business Associate Agreements before sharing PHI with vendors.

Examples

  1. 01

    A hospital encrypting PHI at rest and in transit to satisfy the Security Rule.

  2. 02

    A SaaS vendor signing a Business Associate Agreement with a healthcare provider.

Frequently asked questions

What is HIPAA?

The U.S. Health Insurance Portability and Accountability Act, which sets national standards for protecting individually identifiable health information. It belongs to the Compliance & Frameworks category of cybersecurity.

What does HIPAA mean?

The U.S. Health Insurance Portability and Accountability Act, which sets national standards for protecting individually identifiable health information.

How do you defend against HIPAA?

Defences for HIPAA typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for HIPAA?

Common alternative names include: Health Insurance Portability and Accountability Act.

Related terms

See also