HIPAA law
How the HIPAA law is structured: the 1996 statute, the HHS regulations in 45 CFR, the HITECH Act and the Omnibus Rule — and who enforces them.
HIPAA law at a glance
The HIPAA law is the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191). Its Administrative Simplification provisions led HHS to issue the Privacy, Security, Breach Notification and Enforcement Rules, codified at 45 CFR Parts 160, 162 and 164. The HITECH Act of 2009 strengthened penalties and created breach notification, and the 2013 Omnibus Rule made business associates directly liable for specified requirements.
| Statute | Public Law 104-191, enacted 1996 |
|---|---|
| Regulations | 45 CFR Parts 160, 162 and 164 |
| Major amendment | HITECH Act, 2009 (part of Public Law 111-5) |
| Omnibus Rule | 2013 — business associates directly liable for specified requirements; HITECH changes implemented |
| Civil enforcement | HHS Office for Civil Rights; state attorneys general |
| Criminal enforcement | Department of Justice — up to $250,000 and 10 years for the most serious offenses |
The statute
The Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191) did two big things. Title I protected health coverage when people change jobs. Title II’s Administrative Simplification provisions required national standards for electronic health care transactions and directed HHS to protect the privacy and security of health information.
The regulations
What organizations actually have to do comes from HHS regulations, collected in 45 CFR Subchapter C:
| Part | Contents |
|---|---|
| Part 160 | Definitions, preemption of state law, and the Enforcement Rule (investigations and penalties) |
| Part 162 | Standards for electronic transactions, code sets and identifiers |
| Part 164 | Security Rule (Subpart C), Breach Notification Rule (Subpart D), Privacy Rule (Subpart E) |
Later changes
- HITECH Act (2009). Part of the American Recovery and Reinvestment Act. Created breach notification, raised civil penalties into tiers based on culpability (for violations on or after February 18, 2009), applied Security Rule duties directly to business associates and let state attorneys general sue.
- Omnibus Rule (2013). Implemented HITECH: made business associates and their subcontractors directly liable for specified HIPAA requirements, replaced the “harm” standard for breaches with a presumption of breach, and strengthened patients’ rights.
Who enforces it
- HHS Office for Civil Rights — complaints, investigations, compliance reviews and civil money penalties.
- State attorneys general — civil actions on behalf of state residents.
- Department of Justice — criminal cases. Knowingly obtaining or disclosing health information in violation of HIPAA can bring fines up to $50,000 and a year in prison, rising to $250,000 and 10 years when done for commercial advantage, personal gain or malicious harm (42 U.S.C. 1320d-6).
HIPAA sets a federal floor: state laws that are more protective of privacy generally still apply.
Next steps
Frequently asked questions
Is HIPAA a law or a regulation?
Both. HIPAA is a 1996 federal statute. Most of what organizations must do comes from regulations HHS issued under it, found in 45 CFR Parts 160, 162 and 164.
What did the HITECH Act change?
It created the breach notification requirements, increased civil penalties, extended Security Rule obligations to business associates and gave state attorneys general enforcement power.
Can individuals sue under HIPAA?
HIPAA does not give individuals a private right to sue. Patients can complain to HHS OCR; some state laws provide separate remedies.