Health Insurance Portability and Accountability Act (HIPAA)
A United States federal law of 1996 whose rules set national standards for protecting the privacy and security of individually identifiable health information held by covered entities and their business associates.
HIPAA's Administrative Simplification provisions are implemented through rules issued by the US Department of Health and Human Services. The Privacy Rule governs uses and disclosures of protected health information (PHI) and gives patients rights over their records. The Security Rule requires administrative, physical and technical safeguards for electronic PHI, including risk analysis, access controls, audit controls, integrity protections and transmission security. The Breach Notification Rule requires notifying affected individuals, the department and, in some cases, the media after breaches of unsecured PHI.
Covered entities are health plans, healthcare clearinghouses and healthcare providers that conduct certain transactions electronically. Business associates, such as cloud providers, billing companies and IT service firms that handle PHI on a covered entity's behalf, are directly liable for complying with the Security Rule and must sign business associate agreements. Health software vendors and service providers serving the US healthcare market therefore encounter HIPAA requirements in their contracts.
The Security Rule is risk-based and technology-neutral, so organisations choose safeguards appropriate to their size, complexity and risks. Enforcement is carried out by the department's Office for Civil Rights, which can impose civil monetary penalties. HIPAA has no government certification programme, so organisations demonstrate compliance through documented risk analyses, policies and evidence, often supported by frameworks such as the NIST Cybersecurity Framework.
Key points
- US federal law of 1996 with Privacy, Security and Breach Notification Rules.
- Applies to covered entities and their business associates.
- The Security Rule requires administrative, physical and technical safeguards.
- Enforced by the HHS Office for Civil Rights; there is no official certification.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Encryption at Rest and in TransitCybersecurity & Compliance
- General Data Protection Regulation (GDPR)Cybersecurity & Compliance
- NIST Cybersecurity Framework (CSF)Cybersecurity & Compliance
- Incident ResponseCybersecurity & Compliance
- Compliance Gap AnalysisCybersecurity & Compliance