HIPAA, the Health Insurance Portability and Accountability Act, is a federal law enacted in 1996 that sets national standards for protecting people’s medical information and ensuring they can maintain health insurance coverage when changing jobs. It applies to specific types of organizations in the healthcare system, not to everyone who handles health-related data, and this distinction trips up a surprising number of people. The law has evolved considerably since its passage, with major updates in 2009 and 2013 that expanded its reach and sharpened its enforcement teeth.
What HIPAA Was Originally Designed to Do
The name itself hints at HIPAA’s first purpose, which most people forget about: portability. Before HIPAA, workers who left a job or got laid off could be denied health insurance by a new employer’s plan because of pre-existing conditions. HIPAA limited those exclusions and created rules so that people moving between group health plans would not lose coverage simply because they had been sick before. This insurance-continuity function was the law’s headline purpose in 1996.
The privacy and security provisions that HIPAA is famous for today came later, through a series of rules the Department of Health and Human Services (HHS) developed after Congress passed the law. The Privacy Rule took effect in 2003, the Security Rule followed in 2005, and a sweeping set of updates arrived in 2013 through the HIPAA Omnibus Rule, which implemented changes from the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009. The Omnibus Rule strengthened enforcement, extended obligations to business associates of healthcare providers, and raised penalties for violations.1PubMed Central. The HIPAA Omnibus Rule: implications for public health policy and practice So when people say “HIPAA,” they are usually referring to this accumulated body of regulation rather than the original 1996 statute alone.
Who Has to Follow HIPAA
HIPAA does not apply to every person or business that touches health information. It targets two categories: covered entities and business associates.
Covered entities are the organizations directly involved in healthcare delivery and payment:
- Health plans: health insurance companies, HMOs, employer-sponsored health plans, Medicare, Medicaid, and military and veterans’ health programs.
- Healthcare providers: doctors, hospitals, clinics, pharmacies, nursing homes, dentists, psychologists, chiropractors, and any other provider who transmits health information electronically in connection with certain standard transactions like billing or benefit inquiries.
- Healthcare clearinghouses: entities that process or convert nonstandard health information into standard formats, often serving as intermediaries between providers and insurers.
Business associates are companies or individuals that perform services for a covered entity and, in doing so, access protected health information. Think of the IT firm that maintains a hospital’s electronic records system, the billing company that processes insurance claims, the cloud storage provider that hosts patient data, or the law firm that reviews medical records during a malpractice case. Before the HITECH Act, business associates operated under contracts with covered entities but were not directly regulated by HIPAA. Since the Omnibus Rule of 2013, they are directly liable for compliance and can face penalties on their own.1PubMed Central. The HIPAA Omnibus Rule: implications for public health policy and practice
Who Does Not Have to Follow HIPAA
This is where the misconceptions pile up. Your employer is not a covered entity under HIPAA simply because it has your health information in a personnel file. A fitness app that tracks your heart rate and sleep patterns is not covered by HIPAA. Your friend who works at a hospital and blabs about a patient is violating HIPAA, but if your neighbor who is not in healthcare tells someone about your medical condition, that is not a HIPAA violation, however rude it might be.
Life insurance companies, workers’ compensation carriers, schools (in most situations), and law enforcement agencies are generally not covered entities. Social media companies that collect health-related data through your posts or searches are outside HIPAA’s scope unless they are acting as business associates to a covered entity. This leaves large swaths of health data essentially unprotected by HIPAA, which is a gap the law was never designed to fill but which has become increasingly conspicuous as health-related data proliferates outside traditional healthcare settings.
What Counts as Protected Health Information
HIPAA protects a specific category of data called protected health information, or PHI. This is any individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or its business associate. The key phrase is “individually identifiable,” meaning the information either directly identifies a person or could reasonably be used to identify them.
The regulations spell out 18 specific identifiers that, when linked to health data, make it PHI. These include obvious ones like names, addresses, dates of birth, Social Security numbers, and phone numbers. But the list also covers less intuitive identifiers such as device serial numbers, vehicle identifiers, web URLs, IP addresses, biometric identifiers like fingerprints or voiceprints, and full-face photographs. Even account numbers and health plan beneficiary numbers qualify. If a covered entity strips all 18 identifiers from a dataset, the remaining information is considered de-identified and falls outside HIPAA’s protections.
PHI is not limited to electronic records. Paper charts, verbal conversations between providers, faxes, and even images on a phone all count as PHI if they include identifiable health information held by a covered entity. The electronic subset, known as ePHI, gets additional attention under the Security Rule because digital data faces different risks than paper files.
The Privacy Rule and the Security Rule
HIPAA’s regulatory framework rests on two main pillars. The Privacy Rule governs who can see and use PHI and under what circumstances. The Security Rule focuses specifically on ePHI and requires covered entities and business associates to implement safeguards to keep that electronic data safe.
Under the Privacy Rule, covered entities can use and share PHI without a patient’s written authorization for three core purposes: treatment, payment, and healthcare operations. A doctor can share your test results with a specialist you have been referred to, an insurer can process your claim, and a hospital can conduct internal quality reviews, all without needing you to sign a separate form. For uses outside those three categories, such as marketing, research, or sharing information with an employer, the covered entity generally must obtain your written authorization.2PubMed. HIPAA privacy regulations There are also exceptions carved out for public health activities, law enforcement, and certain other government functions, but these are narrowly defined.
The Privacy Rule also gives patients specific rights: the right to access their own medical records, the right to request corrections, and the right to receive an accounting of certain disclosures. Covered entities must provide a Notice of Privacy Practices explaining how they handle PHI, which is that document your doctor’s office hands you on a clipboard and you probably do not read carefully.
The Security Rule is more technical but boils down to three types of safeguards that covered entities must put in place for ePHI. Administrative safeguards include things like risk assessments, workforce training, and policies for managing access. Physical safeguards cover facility access controls and workstation security. Technical safeguards involve encryption, audit controls, and authentication mechanisms. The rule is intentionally flexible about how these safeguards are implemented, recognizing that a solo physician’s office and a large hospital system have very different resources and risk profiles.
What Happens When HIPAA Is Violated
Enforcement falls to the Office for Civil Rights (OCR) within HHS, and since the HITECH Act, it has real consequences. Penalties are tiered based on the level of negligence involved. At the low end, a violation the entity did not know about and could not reasonably have avoided might result in a fine starting at a few hundred dollars per violation. At the high end, willful neglect of HIPAA requirements that goes uncorrected can result in fines of up to about $1.9 million per violation category per year, adjusted periodically for inflation.
Criminal penalties also exist. Knowingly obtaining or disclosing PHI in violation of HIPAA can result in fines and up to ten years in prison, depending on the intent. These criminal provisions are enforced by the Department of Justice, not OCR.
Beyond government penalties, HIPAA violations carry reputational costs that can be devastating. OCR publishes a “Wall of Shame,” formally called the Breach Portal, listing every breach affecting 500 or more individuals. Being on that list signals to patients, partners, and insurers that an organization failed to protect sensitive data. The practical fallout often exceeds the fine itself.
Misconceptions That Lead People Astray
One of the most persistent misunderstandings is the belief that HIPAA prevents anyone from asking about your health status. During the COVID-19 pandemic, this came up constantly: businesses asking about vaccination status were accused of “HIPAA violations” by customers who did not realize that HIPAA only restricts covered entities, not private businesses, employers (in most contexts), or individuals. A restaurant asking whether you have been vaccinated is not violating HIPAA any more than your aunt asking about your cholesterol.
Another common error is assuming that all health data is protected by HIPAA. Data from wearable fitness trackers, health apps you download on your phone, and genetic testing services you order online may contain extremely sensitive health information, but unless those companies are covered entities or business associates, HIPAA does not apply. Some states have separate laws that cover some of this data, and the Federal Trade Commission can step in when companies violate their own privacy policies, but the patchwork is inconsistent.
People also frequently confuse HIPAA with a blanket ban on sharing health information. Covered entities share PHI routinely and legally for treatment, payment, operations, public health reporting, and other permitted purposes. The law does not lock health information in a vault. It creates rules about when, how, and with whom that information can be shared, and it gives patients certain rights over their own data. The goal is controlled flow, not total secrecy.
Where HIPAA Meets FERPA in Schools
Schools create an especially confusing situation because two federal privacy laws can potentially apply, and they do not always play nicely together. FERPA, the Family Educational Rights and Privacy Act, protects the privacy of student education records, and health records maintained by a school that receives federal education funding generally fall under FERPA rather than HIPAA. This means that a school nurse’s records about a student’s health condition are typically governed by FERPA, not HIPAA, even though they contain medical information.
Since HIPAA’s Privacy Rule took effect in 2003, school health officials have struggled to navigate the overlap. The two laws have different consent requirements, different enforcement mechanisms, and different definitions of what is protected.3Sage Journals. HIPAA-FERPA revisited The practical question school administrators face is which law controls in a given situation, and the answer depends on who created the record, how the school is funded, and whether a healthcare provider is operating independently within the school. A school-based health clinic run by an outside healthcare provider, for instance, might be a HIPAA-covered entity even though the school itself is not.
For parents, the takeaway is that your child’s health information at school is likely protected by privacy law, but which law applies depends on the specific arrangement. If you have concerns about how a school is handling your child’s medical records, asking whether they follow FERPA or HIPAA for that particular type of record is the right first step.
HIPAA and Cloud Computing
The shift to electronic health records and cloud-based systems has created new compliance questions that the original 1996 law did not anticipate. When a hospital stores patient data on servers it owns and controls in its own building, the security obligations are relatively straightforward. When that same data lives on servers owned by Amazon, Google, or Microsoft in data centers spread across multiple states, the chain of responsibility gets longer and more complex.
Cloud providers that store or process ePHI are business associates and must sign business associate agreements spelling out their compliance obligations. Research into the cloud computing model and federal health record regulations has found that cloud-based electronic health records can meet HIPAA’s privacy and security requirements, provided the business associate contracts specify compliance expectations, performance metrics, and how liability is shared.4Journal of the American Medical Informatics Association. Reconciliation of the cloud computing model with US federal electronic health record regulations In practice, the major cloud providers now offer HIPAA-eligible infrastructure and will sign the required agreements, but the covered entity remains responsible for configuring and using those services correctly. A hospital that stores patient data in a properly contracted cloud environment but leaves an access port misconfigured is still on the hook for the resulting breach.
The cloud question is not just technical. It also raises jurisdictional issues when servers are located outside the United States, and it complicates incident response because a breach might originate at the cloud provider rather than the covered entity. These layers of shared responsibility are manageable but require the kind of ongoing attention that smaller practices sometimes struggle to maintain.
The Growing Challenge of Artificial Intelligence and Re-Identification
HIPAA’s de-identification standard, removing the 18 identifiers from a dataset, was designed for a world where data was harder to cross-reference. Today, advances in artificial intelligence are testing the limits of that standard. AI tools can combine de-identified health data with publicly available information from social media, voter rolls, commercial databases, and other sources to re-identify individuals with uncomfortable accuracy.
Researchers have increasingly flagged this concern: even after de-identification, the evolving capabilities of AI create a growing threat of re-identification that blurs the boundary between identifiable and non-identifiable data.5eClinicalMedicine. Open Data Sharing in Clinical Research and Participants Privacy: Challenges and Opportunities in the Era of Artificial Intelligence This is a particular problem for medical research, where sharing data openly accelerates scientific progress but also increases the risk that study participants can be traced back to their records. The fear of re-identification deters some researchers from sharing clinical data at all, which in turn slows down the kind of collaborative research that benefits patients.
HIPAA’s framework has not yet adapted to this reality. The 18-identifier approach treats de-identification as a binary: either the identifiers are removed or they are not. But re-identification risk exists on a spectrum, and a dataset that was genuinely anonymous in 2005 might be linkable today given the right AI tools and auxiliary data. Whether regulators will update the de-identification standard, impose new requirements around AI-assisted data analysis, or take some other approach remains an open question. For now, covered entities and researchers are left to layer additional protections, such as data use agreements, restricted-access repositories, and differential privacy techniques, on top of what HIPAA requires.
State Laws and the Patchwork Beyond HIPAA
HIPAA sets a federal floor for health information privacy, but it does not preempt state laws that provide stronger protections. If your state has a health privacy law that gives patients more rights or imposes stricter requirements on covered entities than HIPAA does, the state law wins. This creates a patchwork where the practical rules depend on where you live and where your healthcare provider operates.
California, for example, has the Confidentiality of Medical Information Act, which in some respects goes further than HIPAA. Several states have enacted specific protections for reproductive health data, mental health records, or genetic information that exceed HIPAA’s baseline. On the other end, some states add very little beyond what HIPAA already requires.
For consumers, the practical effect is that your rights over your health data are not identical everywhere in the country, even though HIPAA provides a baseline. For covered entities and business associates operating across state lines, compliance means meeting both HIPAA and the most protective state law in each jurisdiction where they do business. This layered regulatory environment is one reason compliance feels so burdensome, particularly for smaller organizations that may lack dedicated legal and compliance staff. The cost of keeping up with evolving federal and state requirements, training staff, conducting risk assessments, and maintaining documentation is significant, and it falls disproportionately on smaller practices and rural providers with thin margins.
None of this complexity changes the core purpose of the law: to give patients some control over how their most personal information is used and shared, while allowing the healthcare system to function. The tension between those goals is built into HIPAA’s DNA, and every update to the regulations is an attempt to recalibrate the balance as technology, business models, and public expectations shift around it.