Free Guide to Understanding HIPAA Certification Requirements
What HIPAA Is and Why It Matters HIPAA stands for the Health Insurance Portability and Accountability Act. Congress passed this federal law in 1996. The law...
What HIPAA Is and Why It Matters
HIPAA stands for the Health Insurance Portability and Accountability Act. Congress passed this federal law in 1996. The law creates national standards for protecting people's health information. Understanding HIPAA is important because it affects how doctors, hospitals, insurance companies, and other healthcare organizations handle your personal medical records.
The law has several main parts. The Privacy Rule controls how health information can be used and shared. The Security Rule sets standards for protecting electronic health information. The Breach Notification Rule requires organizations to tell you if your information gets exposed. The Enforcement Rule explains how the government checks if organizations follow the rules.
HIPAA applies to "covered entities." These include health plans like insurance companies and HMOs, healthcare providers like doctors and hospitals, and healthcare clearinghouses that process health information. Business associates also must follow HIPAA rules. These are companies that work with covered entities and handle health information, such as billing services or IT companies.
The U.S. Department of Health and Human Services Office for Civil Rights enforces HIPAA. Since 1996, this office has resolved thousands of complaints about privacy violations. In 2022 alone, the office handled over 25,000 complaints. Penalties for breaking HIPAA rules can range from $100 to $50,000 per violation, and organizations can face millions in total fines.
HIPAA protections matter to you personally. They mean your doctor cannot share your medical history with your employer without permission. Your insurance company cannot sell your health information to advertisers. If a hospital loses a file with your records, they must notify you about what happened. These protections give you control over one of your most sensitive personal details.
Practical Takeaway: HIPAA is a federal privacy law that controls how healthcare organizations use and share your health information. It applies to doctors, hospitals, insurance companies, and their business partners. Understanding these basics helps you know what protections you have when you receive healthcare or deal with insurance.
Understanding the Privacy Rule
The Privacy Rule is the most well-known part of HIPAA. It took effect on April 14, 2003. The rule sets standards for how healthcare organizations can use and share your "protected health information," often called PHI. Protected health information includes anything in your medical record or health plan records that could identify you, such as your name, Social Security number, medical record number, date of birth, or diagnosis information.
The Privacy Rule says healthcare organizations must get your permission before using or sharing your information for most purposes. This permission is usually a written authorization form you sign. However, the rule allows sharing without permission in certain situations. Providers can share information for treatment purposes—for example, your doctor can send your test results to a specialist you're seeing. They can share for payment purposes, like sending information to your insurance company to process a claim. They can also share for healthcare operations, such as staff training or quality improvement activities.
Organizations must also follow the "minimum necessary" standard. This means they should only share the smallest amount of information needed for the specific purpose. For example, if your insurance company needs to verify that you had surgery, the provider shouldn't send your entire medical history. They should send only the information about that surgery.
You have rights under the Privacy Rule. You can request a copy of your medical records within 30 days. You can ask your provider to correct information they have about you if you believe it's wrong. You can request that sensitive information not be shared with certain people, like an ex-spouse. You can get a list of people or organizations that have received your health information. You can also ask your provider to communicate with you in a specific way, such as sending bills to a work address instead of home.
Some health information gets special protection. Certain states have extra privacy rules for sensitive conditions like HIV/AIDS, mental health, and substance abuse treatment. HIPAA requires these extra protections to be followed. Additionally, psychotherapy notes—the personal notes a therapist keeps during sessions—have stronger protections than regular medical records. A provider needs a specific authorization just to share psychotherapy notes, and they cannot share them for payment purposes.
Practical Takeaway: The Privacy Rule controls how your medical information can be used and shared. Providers need your permission before sharing information with most people, but they can share without permission for treatment, payment, and operations. You have rights to see your records, correct errors, and limit who receives your information.
The Security Rule and Protecting Electronic Health Records
The Security Rule became effective on April 21, 2005. It specifically addresses electronic protected health information, often called ePHI. As healthcare organizations increasingly store records on computers and send information through email and secure networks, the Security Rule sets requirements for protecting this digital information. The rule applies to any covered entity or business associate that creates, receives, maintains, or sends electronic health information.
The Security Rule requires organizations to implement three types of safeguards. Administrative safeguards include policies, procedures, and training. An organization must have a security officer responsible for developing and maintaining security policies. Staff must receive training on how to handle information securely. Technical safeguards involve computer systems and technology. Organizations must use encryption, which scrambles information so unauthorized people cannot read it. They must maintain firewalls that block unauthorized access. They must also have systems to track who accesses patient records. Physical safeguards protect the buildings and equipment where information is stored. This includes restricting access to server rooms, protecting computers from theft, and securely destroying old records.
Organizations must perform a security risk assessment. This means they analyze their systems to find vulnerabilities that could lead to a breach. A breach occurs when someone who shouldn't have access obtains protected health information. The assessment must identify what information they have, who has access to it, and what could go wrong. Based on findings, the organization must create a plan to reduce risks. This might involve upgrading software, changing passwords more frequently, or adding security cameras.
The rule requires organizations to have a incident response plan. If a breach happens, they must respond quickly. This includes investigating what information was accessed, notifying affected people, and working with law enforcement if necessary. Between 2009 and 2023, there were approximately 4,000 reported breaches in the healthcare industry affecting over 280 million people. Many of these breaches resulted from inadequate security measures that could have been prevented through proper Security Rule compliance.
Business associates—companies that handle health information on behalf of providers or insurers—must also follow Security Rule standards. This includes cloud storage companies that store patient records, IT companies that manage hospital networks, and billing companies. Contracts between organizations and their business associates must clearly state what security measures the business associate will implement. If a business associate experiences a breach, the covered entity that hired them can also face penalties.
Practical Takeaway: The Security Rule requires healthcare organizations to protect electronic health records through administrative measures like staff training, technical tools like encryption and firewalls, and physical protections. Organizations must assess security risks and have plans to respond to breaches. Understanding these requirements helps you know what protections should be in place when your records are stored digitally.
Breach Notification Requirements
The Breach Notification Rule, which took effect on September 23, 2009, explains what must happen if someone unauthorized gets access to your protected health information. A breach is different from normal, permitted sharing. A normal use might be your doctor sharing your information with another doctor. A breach occurs when information is obtained or viewed by someone without permission, or when information is disclosed to someone it wasn't supposed to go to, without a good business reason.
Not every unauthorized access counts as a breach. HIPAA has a "low probability of compromise" standard. This means if information was accessed but the organization has strong evidence that the unauthorized person never actually viewed or misused it, it may not qualify as a breach. For example, if an unopened encrypted file is accidentally sent to the wrong person, and the organization confirms the file was never opened, it might not meet the definition of a breach. However, if there is any reasonable chance someone accessed or misused your information, the organization should treat it as a breach to be safe.
When a breach occurs, covered entities must notify you without unreasonable delay, and no later than 60 days after discovering the breach. The notification must be provided in writing, and it must include specific information. The notice must explain what information was involved, what happened, what steps you should take to protect yourself, what the organization is doing to investigate, and how you can contact the organization for more information. If you don't have a home address on file,
Related Guides
More guides on the way
Browse our full collection of free guides on topics that matter.
Browse All Guides →