Security, Resilience & Assurance · United States
Health Insurance Portability and Accountability Act
The US federal law governing protected health information (PHI). Its Privacy and Security Rules set standards for how covered entities and their business associates use, disclose and safeguard health data.
REGULATORHHS Office for Civil Rights (OCR)
REGIONUnited States
EFFECTIVEPrivacy Rule 2003; Security Rule 2005, with ongoing updates
Who it applies to
- Healthcare providers, health plans and healthcare clearinghouses (“covered entities”)
- Business associates handling PHI on behalf of covered entities
- Technology vendors processing health data under a Business Associate Agreement
Key requirements
- Administrative, physical and technical safeguards for electronic PHI
- Signed Business Associate Agreements with all relevant vendors
- Breach notification to affected individuals, HHS, and in some cases the media
- Minimum necessary access to PHI for any given purpose
- Regular risk analysis of systems handling PHI
Maximum penaltyTiered civil penalties up to roughly $2.1 million per violation category per year, plus potential criminal charges for wilful violations
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates HIPAA compliance
Continuous monitoring, evidence and reporting for HIPAA — alongside every other framework you need to satisfy.