What is HIPAA?
A plain-English overview of HIPAA: what it protects, who it applies to, the three main rules, patients' rights and how it is enforced.
What is HIPAA? at a glance
HIPAA is a 1996 U.S. federal law whose privacy and security rules control how health care providers, health plans, clearinghouses and their business associates use, share and protect patients' health information. It gives patients rights over their records, requires safeguards for electronic health data, and requires notification when unsecured health information is breached. The HHS Office for Civil Rights enforces it, with civil penalties of up to $2.19 million per year for a type of violation.
| Full name | Health Insurance Portability and Accountability Act of 1996 |
|---|---|
| Main rules | Privacy Rule, Security Rule, Breach Notification Rule |
| Who must comply | Covered entities and their business associates |
| What it protects | Protected health information (PHI), including electronic PHI |
| Enforced by | HHS Office for Civil Rights (OCR) |
| Civil penalties | $145 to $2,190,294 per violation, depending on culpability (2025 adjustment) |
What HIPAA protects
HIPAA protects protected health information (PHI): information that identifies a person and relates to their health, their care or payment for it, held by a covered entity or business associate. When it is stored or sent electronically it is also ePHI. See PHI and ePHI.
Who has to follow it
- Covered entities — health plans, health care clearinghouses, and health care providers that conduct standard transactions (such as insurance claims) electronically.
- Business associates — vendors and contractors that create, receive, maintain or transmit PHI on a covered entity’s behalf, and their subcontractors.
Not sure where you fit? Read Who must comply with HIPAA or use the Does HIPAA apply to me? tool.
The three rules most people mean
| Rule | What it does |
|---|---|
| Privacy Rule | When PHI may be used or shared, and patients’ rights over their health information |
| Security Rule | Administrative, physical and technical safeguards for ePHI |
| Breach Notification Rule | Notices to patients, HHS and sometimes the media after a breach |
Patients’ rights
Patients can see and get copies of their records, ask for corrections, ask how their information was shared, request confidential communications, and receive a Notice of Privacy Practices.
Enforcement
The HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties. Under the 2025 inflation adjustment these range from $145 to $2,190,294 per violation, with an annual cap of $2,190,294 for identical violations, depending on how culpable the organization was. Knowingly obtaining or disclosing health information in violation of HIPAA is also a federal crime. See HIPAA penalties.
Next steps
- HIPAA for therapists in private practice →Scenario
- PHI and ePHI →Requirement
- Covered entity →Requirement
- Business associate →Requirement
- Notifying patients of a breach →Requirement
Frequently asked questions
What is HIPAA in simple terms?
A federal law that sets rules for how doctors, health plans and the companies working for them handle your health information, and gives you rights to see and control it.
Who enforces HIPAA?
The HHS Office for Civil Rights enforces the Privacy, Security and Breach Notification Rules. Criminal cases are handled by the Department of Justice, and state attorneys general can also bring civil actions.
Does HIPAA apply to every company with health data?
No. It applies to covered entities and their business associates. Many consumer apps and employers acting as employers are outside HIPAA.