What Does HIPAA Require: Rules, Rights & Safeguards

HIPAA, the Health Insurance Portability and Accountability Act of 1996, requires health care providers, health insurers, and their business partners to protect the privacy and security of your health information while giving you specific rights over your own records. The law does this through three main sets of rules: the Privacy Rule, the Security Rule, and the Breach Notification Rule. Each imposes different obligations, and the gaps between them are just as important as what they cover.

The Privacy Rule and What It Protects

The Privacy Rule is the part of HIPAA most people encounter, even if they don’t know it by name. It went into effect on April 14, 2003, for covered health care providers, institutions, and businesses, and it governs how your protected health information can be used and shared.1Oxford Academic. Access Anxiety: HIPAA and Historical Research Protected health information, usually called PHI, includes anything that connects your identity to your health status, treatments, or payment records. That spans everything from your diagnosis codes and lab results to your insurance claim history and appointment notes.

The rule applies to “covered entities,” which include doctors, hospitals, pharmacies, health insurers, and health care clearinghouses, plus their “business associates,” meaning any outside company that handles PHI on their behalf, such as a billing service, a cloud storage provider, or an IT contractor. If a company falls into one of these categories, the Privacy Rule controls what it can do with your data.

In broad terms, a covered entity can use and share your PHI for treatment, payment, and health care operations without asking your explicit permission each time. Your doctor can send your records to a specialist you’re being referred to, and your hospital can send a bill to your insurer. But for most other purposes, such as marketing, sharing with employers, or releasing information to researchers, the entity needs your written authorization first. The “minimum necessary” standard applies as well: when sharing your data, a covered entity is supposed to disclose only the information needed for the purpose at hand, not your entire medical file.

De-identification and the Safe Harbor Method

Sometimes organizations need to use health data for research, analytics, or public health purposes without putting individual patients at risk. HIPAA provides a pathway called de-identification, and the most commonly used version is the Safe Harbor method. Under Safe Harbor, an organization must strip out 18 categories of identifiers, including names, Social Security numbers, email addresses, phone numbers, account numbers, and all other record numbers. Dates have to be generalized to years only, and geographic information can be reported only at the level of the first three digits of a ZIP code, unless that three-digit area has fewer than 20,000 residents, in which case even that much geography gets replaced with “000.”2PubMed Central. Re-identification Risks in HIPAA Safe Harbor Data: A study of data from one environmental health study

Once data has been de-identified under Safe Harbor, it is no longer considered PHI, and HIPAA’s protections no longer apply to it. That makes the thoroughness of the de-identification process crucial. Researchers have shown that even after Safe Harbor stripping, certain datasets can sometimes be re-linked to individuals if enough contextual clues remain, which is why some organizations go beyond the minimum requirements or use the alternative “expert determination” method, where a qualified statistician certifies that the risk of re-identification is very small.

Your Right to See and Correct Your Records

HIPAA gives you the right to review your own medical records and to request amendments if you believe something is wrong.3Journal of the American Medical Informatics Association. The Effects of Promoting Patient Access to Medical Records: A Review This is known as the “right of access,” and in practice it means you can ask any covered entity for a copy of the health records it maintains about you. The entity must respond within 30 days, though a one-time 30-day extension is allowed if the entity provides a written explanation of the delay. You can also specify the format you want the records in, such as an electronic copy, and the provider is generally supposed to comply with that preference.

In principle, your right of access sounds straightforward. In reality, getting your records can be harder than it should be. A study that scored responses from over 200 health care providers and surveyed nearly 3,000 health care institutions found that more than half of providers were out of compliance with the HIPAA right of access. The most common failure, accounting for 86 percent of noncompliance, was refusing to send records to the patient or the patient’s designee in the form and format the patient requested.4medRxiv. Health Care Provider Compliance with the HIPAA Right of Individual Access: a Scorecard and Survey (Revised) In other words, the most frequent violation isn’t outright denial of records but providers insisting on their own preferred delivery method rather than yours.

The U.S. Department of Health and Human Services has taken this problem seriously enough to launch a specific “Right of Access Initiative,” using enforcement actions against providers who repeatedly fail to hand over records. If you run into this situation, filing a complaint with HHS’s Office for Civil Rights is the formal avenue for resolution.

The Security Rule and Technical Safeguards

The Privacy Rule tells organizations what they may and may not do with your information. The Security Rule tells them how to protect the electronic version of it. It applies specifically to electronic protected health information, or ePHI, and it requires covered entities and business associates to implement three categories of safeguards: administrative, physical, and technical.

Administrative safeguards include things like appointing a security officer, conducting risk assessments, and training employees on data handling. Physical safeguards address the protection of actual hardware and facilities, from server rooms to workstations in shared offices. Technical safeguards cover the digital protections: access controls, audit logs, data encryption, and secure data transmission.

A study that built an analysis framework to evaluate twelve HIPAA technical safeguards in mobile health apps found that authorization to access sensitive resources, data encryption and decryption, and data transmission security were the most vulnerable areas across the apps examined.5PubMed Central. A comparative study on HIPAA technical safeguards assessment of android mHealth applications That finding is worth paying attention to. Health apps are a growing part of how people interact with the medical system, and the technical protections baked into those apps don’t always meet the standard the Security Rule sets.

One subtle but important detail: the Security Rule is written to be “scalable.” It does not mandate specific technologies, like a particular encryption algorithm. Instead, it requires covered entities to assess their own risks and implement safeguards that are reasonable and appropriate given their size, complexity, and capabilities. A large hospital system and a solo practitioner’s office are held to the same principles but not necessarily the same technical setup. This flexibility is intentional, but it also means that the security you get as a patient varies widely depending on where you receive care.

Breach Notification Requirements

When things go wrong and your data is exposed, the Breach Notification Rule governs what happens next. Covered entities must notify affected individuals, HHS, and in some cases the media, when a breach of unsecured PHI occurs. For breaches affecting 500 or more people, the notification must happen within 60 days and is reported publicly to HHS, which maintains a searchable online portal sometimes called the “Wall of Shame.” For smaller breaches, the entity logs them and reports them annually.

The scale of breaches reported under this system is substantial. In 2023 alone, HIPAA’s mandatory reporting led to the public disclosure of 746 major breaches affecting roughly 168 million people. Since 2010, the U.S. has logged over 3,300 major hacking incidents in health care. That volume doesn’t necessarily mean the U.S. health care system is less secure than systems in other countries. It reflects the fact that HIPAA’s regulatory framework forces these failures into public view, whereas many other legal systems lack comparable mandatory disclosure requirements.6Genetics and Molecular Research. Transparency in Healthcare Data Breach Reporting: A Comparative Analysis of GDPR and HIPAA

For you as a patient, this means that if a covered entity discovers your data has been compromised, you should receive a written notice explaining what happened, what types of information were involved, what steps the entity is taking, and what you can do to protect yourself. If you never receive a notice, that doesn’t necessarily mean your data has never been exposed, but it does mean no reportable breach has been identified and attributed to that entity under HIPAA’s definition.

When Sharing Your Data Is Allowed Without Your Permission

HIPAA is not an absolute lockdown on health information. The law includes a number of exceptions where covered entities can share PHI without your authorization. Some are routine: providers can disclose information to public health authorities for disease surveillance, to law enforcement under specific circumstances like a court order, and to coroners or funeral directors in connection with a death. Others are situational.

Emergencies represent one of the more significant exception categories. During public health crises such as pandemics or natural disasters, the normal balance between privacy and the need for timely information shifts. HIPAA permits sharing of PHI when necessary to prevent or lessen a serious and imminent threat to health or safety. Legal and ethical frameworks around emergency data sharing emphasize principles like proportionality, necessity, transparency, and accountability, recognizing that the urgency of a crisis does not erase the obligation to handle data responsibly.7IGI Global. Health Data Sharing in Emergencies: Ethical and Legal Considerations During declared public health emergencies, HHS can also issue limited waivers of certain HIPAA provisions, as it did during the COVID-19 pandemic to allow expanded telehealth and information sharing between providers.

Workers’ compensation cases are another area where patients are sometimes surprised. If you file a workers’ comp claim, your provider can share relevant health information with the insurer or employer’s comp carrier without your separate authorization, to the extent the information is needed for the claim. Similarly, HIPAA permits disclosures for health oversight activities, judicial and administrative proceedings, and certain research activities that have been approved by an institutional review board or privacy board.

What HIPAA Does Not Cover

Perhaps the biggest misconception about HIPAA is that it protects all of your health-related data, everywhere. It does not. HIPAA only applies to covered entities and their business associates. A fitness tracker on your wrist, a period-tracking app on your phone, or a wellness platform offered by your gym are almost certainly not covered entities. The health data they collect, including heart rate, sleep patterns, menstrual cycles, and location information, falls outside HIPAA’s reach.

This gap is wider than many people realize. Data from wearable devices and health-monitoring apps may be transmitted, stored, and even sold without the user’s specific knowledge, and the cybersecurity protections around these consumer devices remain relatively weak, making them comparatively easy targets for data theft.8PubMed Central. What Clinicians Should Tell Patients About Wearable Devices and Data Privacy: A Narrative Review When your doctor prescribes a connected glucose monitor and the data flows through the hospital’s electronic health record, that data is protected by HIPAA. When you voluntarily log the same glucose readings into a consumer app made by a tech company, those readings likely are not.

This also means that health information you share on social media, in workplace wellness surveys administered by non-covered entities, or through direct-to-consumer genetic testing services is generally not protected by HIPAA. Other laws may offer some protection, such as the Federal Trade Commission Act’s prohibition on deceptive practices, or state-level privacy laws like Washington’s My Health My Data Act, but the patchwork is inconsistent. If you care about who sees your health data, the terms of service for any app or device you use matter more than HIPAA does in those contexts.

HIPAA Penalties and Enforcement

HIPAA enforcement is handled by HHS’s Office for Civil Rights. Penalties are tiered based on the level of negligence involved. At the lowest tier, violations that the entity was unaware of and could not have reasonably avoided carry penalties starting at a few hundred dollars per violation. At the highest tier, violations resulting from willful neglect that are not corrected can reach up to about $2 million per violation category per year. Criminal penalties, including fines and imprisonment, are also possible for individuals who knowingly obtain or disclose PHI in violation of the law.

In practice, OCR resolves most complaints through voluntary compliance or corrective action plans rather than financial penalties. The agency investigates tens of thousands of complaints each year, but only a fraction result in monetary settlements. The largest settlements have reached into the tens of millions of dollars, typically involving large health systems or insurers that experienced massive breaches or demonstrated systemic noncompliance. For smaller providers, the more common enforcement pattern involves technical assistance and agreements to fix identified problems within a set timeframe.

One enforcement trend worth watching is HHS’s increasing attention to the right of access, as described earlier. Since launching its Right of Access Initiative, the agency has settled multiple cases against providers of varying sizes, including small single-physician practices, for failing to provide records in a timely manner. The settlements have generally been modest in dollar terms but send a clear message that patient access obligations are being actively monitored.

The Reproductive Privacy Rule

One of the most significant recent changes to HIPAA’s framework is the Reproductive Privacy Rule, finalized in 2024. This regulatory update was designed to prevent law enforcement in states with restrictive abortion laws from using HIPAA-covered records to prosecute patients or physicians.9PubMed. New Reproductive Privacy Rule to Protect Both Patients and Physicians Before this rule, HIPAA’s existing exceptions for law enforcement disclosures created ambiguity about whether a state could compel a provider to hand over records showing that a patient had received reproductive care in another state.

The new rule specifically prohibits covered entities from disclosing PHI for the purpose of investigating or prosecuting someone for seeking, obtaining, providing, or facilitating lawful reproductive health care. “Lawful” in this context means care that was legal in the state where it was provided. This protection applies whether the request comes from law enforcement, a court, or an administrative body in a state with different laws.

The rule matters because it illustrates how HIPAA can be adapted to address new threats to patient privacy that its original drafters didn’t anticipate. When the law was written in 1996, the idea that medical records about a legal procedure could be used as evidence in a criminal prosecution in a different jurisdiction was not on the radar. The Reproductive Privacy Rule doesn’t change HIPAA’s overall structure, but it adds a specific carve-out that reflects a changed legal landscape.

Common Misunderstandings About HIPAA

HIPAA is one of the most frequently misquoted laws in everyday conversation. A few persistent misunderstandings are worth clearing up.

First, HIPAA does not prevent your doctor from talking to your family members about your care in all circumstances. If you are present and don’t object, or if the provider reasonably infers from the circumstances that you wouldn’t object, they can share information with a family member or close friend who is involved in your care. If you’re incapacitated and a provider believes sharing information is in your best interest, the Privacy Rule allows that as well. If you want to restrict who gets information about you, you need to tell your provider explicitly.

Second, HIPAA does not apply to individuals. If a coworker overhears your phone call with your doctor and tells other people, that’s rude, but it isn’t a HIPAA violation. Only covered entities and business associates can violate HIPAA. Your neighbor, your employer (unless the employer is also your health plan), and random people on the internet are not bound by it.

Third, HIPAA does not prohibit a provider from asking about your vaccination status, your sexual history, your mental health, or any other health topic. Providers are allowed and often clinically obligated to collect health information from you. HIPAA governs what they do with that information after they have it, not whether they can ask for it in the first place.

Fourth, the law’s name is commonly misspelled. It is HIPAA, not HIPPA. The “AA” stands for “Accountability Act.” Getting the name right is a minor point, but it signals whether someone has actually read the law or is working from secondhand summaries.

How HIPAA Intersects With Research

Researchers who want to use health data face a specific set of HIPAA requirements that can shape what studies get done and how quickly. For research that uses identifiable health information, the Privacy Rule generally requires either the patient’s individual authorization or a waiver of authorization granted by an institutional review board or privacy board. Waivers are allowed when the research involves no more than minimal risk to privacy, couldn’t practicably be conducted without the waiver, and couldn’t practicably be done without the identifiable information.

In practice, this framework has created friction. Historians, epidemiologists, and public health researchers have all documented situations where HIPAA’s requirements slowed or complicated legitimate research, particularly for retrospective studies involving old records where it would be impractical to track down every patient for individual consent.1Oxford Academic. Access Anxiety: HIPAA and Historical Research The de-identification pathway offers an alternative, but as noted earlier, fully de-identified data sometimes loses the granularity that makes it useful for certain research questions. Researchers working with dates of medical events, for example, lose all day-and-month precision under Safe Harbor, which can make it impossible to study time-sensitive questions about disease progression or treatment timing.

None of this means HIPAA is wrong to impose these requirements. The tension between research utility and patient privacy is genuine, and the law attempts to balance them. But the balance has real consequences for the speed and scope of health research, and researchers navigate it constantly.