What Is HIPAA?

HIPAA is a U.S. federal law that established important standards affecting the privacy and security of certain health information. Here is a practical introduction to what HIPAA means, who it applies to, and what organizations should understand.

Start Free HIPAA Compliance Assessment

What Does HIPAA Stand For?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996.

HIPAA is a U.S. federal law. Among other provisions, it led to national standards designed to protect certain health information and established requirements affecting healthcare transactions, privacy, and security.

When people talk about “HIPAA compliance,” they are often referring to requirements established through several HIPAA rules, including the Privacy Rule and Security Rule.

Who Does HIPAA Apply To?

HIPAA does not automatically apply to every person or company that handles health-related information.

The HIPAA Rules generally apply to covered entities and, for applicable requirements, their business associates.

Covered Entities

Covered entities generally include:

For healthcare providers, HIPAA covered-entity status generally depends on whether the provider conducts certain standard healthcare transactions electronically.

Business Associates

A business associate is generally a person or organization that performs certain functions or services for a covered entity involving protected health information.

Examples may include certain billing companies, technology vendors, consultants, cloud service providers, and other service providers, depending on their role and access to PHI.

What Information Does HIPAA Protect?

One of the central concepts in HIPAA is Protected Health Information (PHI).

PHI generally includes individually identifiable health information maintained or transmitted by a covered entity or business associate, subject to the definitions and exclusions contained in the HIPAA Rules.

Depending on the circumstances, PHI can include information such as:

Not every piece of health-related information is PHI. The context, the organization holding the information, and applicable HIPAA definitions matter.

Learn more in our guide to what counts as PHI under HIPAA .

What Is the HIPAA Privacy Rule?

The HIPAA Privacy Rule establishes national standards for the protection of certain individually identifiable health information.

Among other areas, the Privacy Rule addresses how covered entities may use and disclose PHI and provides individuals with certain rights regarding their health information.

Organizations subject to the Privacy Rule should understand when PHI may be used or disclosed, when authorization may be required, and how applicable individual rights are handled.

What Is the HIPAA Security Rule?

The HIPAA Security Rule establishes standards for protecting electronic protected health information (ePHI).

It requires covered entities and business associates subject to the Rule to implement appropriate safeguards for ePHI.

The safeguards are commonly organized into three categories:

Security measures should be evaluated in the context of the organization's environment, risks, systems, workforce, and applicable HIPAA requirements.

What Is a HIPAA Risk Analysis?

Risk analysis is an important requirement of the HIPAA Security Rule. Organizations subject to the requirement must conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

A risk analysis may involve reviewing areas such as:

Read our HIPAA Risk Assessment guide for more information.

What Is a Business Associate Agreement?

A Business Associate Agreement, commonly called a BAA, is a written arrangement required in applicable relationships between covered entities and business associates.

A BAA establishes permitted and required uses and disclosures of PHI and addresses other responsibilities under HIPAA.

Whether a BAA is required depends on the relationship, services being provided, and access to PHI.

See our guide: Do Solo Providers Need a BAA?

What Is the HIPAA Breach Notification Rule?

The HIPAA Breach Notification Rule establishes notification requirements following certain breaches of unsecured PHI.

Depending on the circumstances, notification obligations may involve affected individuals, the U.S. Department of Health and Human Services, and in some cases the media.

Organizations should maintain appropriate procedures for identifying, evaluating, documenting, and responding to potential incidents involving PHI.

What Does HIPAA Compliance Involve?

HIPAA compliance is not simply a matter of completing one form or checking one checklist.

Depending on the organization's role and applicable requirements, compliance activities may include:

The specific requirements depend on the organization's role, activities, systems, risks, and applicable HIPAA provisions.

Does HIPAA Apply to Solo Providers and Small Practices?

A small practice or solo provider can still be a HIPAA covered entity if the applicable covered-entity requirements are met. Organization size alone does not determine whether HIPAA applies.

Solo providers and small practices may therefore need to evaluate areas such as patient information handling, electronic systems, vendors, workforce access, documentation, and security risks.

Explore: HIPAA for Private Practice

HIPAA for Therapists

Therapists and behavioral health practices may be subject to HIPAA when they meet the definition of a covered entity or operate as a business associate.

Relevant areas can include clinical records, electronic communications, telehealth systems, vendors, access controls, documentation, and workforce practices.

Learn more: HIPAA for Therapists

HIPAA and Telehealth

Organizations subject to HIPAA should consider how PHI is protected when delivering healthcare remotely.

This may involve reviewing telehealth platforms, communications, devices, access controls, vendor relationships, and other safeguards relevant to remote-care workflows.

Read: Telehealth HIPAA Compliance

Frequently Asked Questions About HIPAA

What is HIPAA in simple terms?

HIPAA is a U.S. federal law that led to national standards governing certain healthcare information, privacy, security, and electronic healthcare transactions.

What does HIPAA stand for?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996.

Who must comply with HIPAA?

HIPAA requirements generally apply to covered entities and, for applicable requirements, their business associates.

Does HIPAA apply to every company handling health information?

No. Handling health-related information alone does not automatically make an organization subject to HIPAA. Applicability depends on the organization's role and whether it meets the relevant HIPAA definitions.

What is PHI?

PHI means protected health information. It generally includes individually identifiable health information maintained or transmitted by covered entities or business associates, subject to HIPAA definitions and exclusions.

Is completing a HIPAA assessment enough to be compliant?

No. An assessment can help identify areas that may need attention, but completing an assessment by itself does not certify or establish HIPAA compliance.

Continue Learning About HIPAA

Review Your HIPAA Practices

Use the guided GetHIPAAcheck assessment to review key HIPAA Privacy and Security areas, identify potential gaps, and receive recommended next steps.

Start Free HIPAA Compliance Assessment

GetHIPAAcheck is an independent compliance-support tool. It does not provide legal advice, certify HIPAA compliance, or represent approval or endorsement by HHS or OCR.