HIPAA (the Health Insurance Portability and Accountability Act) is the US federal law governing how healthcare organizations protect patient health information. Its two operative rules split the work: the Privacy Rule controls how health information can be used and disclosed, and the Security Rule sets specific safeguard requirements for that information when it's electronic.
What counts as PHI
Protected Health Information (PHI) is individually identifiable health information relating to a person's past, present, or future physical or mental health, the healthcare they received, or payment for that care — in any form: electronic, paper, or spoken. It's covered the moment a covered entity or business associate creates, receives, maintains, or transmits it, not just when it's stored digitally.
Who has to comply
Covered entities — health plans, healthcare providers, and healthcare clearinghouses that transmit health information electronically — are directly bound by HIPAA. So are business associates: vendors, billing companies, cloud providers, and consultants who handle PHI on a covered entity's behalf. Since a 2013 rule change, business associates are directly liable for compliance too, not just contractually obligated through the covered entity, and must sign a Business Associate Agreement (BAA) before handling any PHI.
Penalty tiers
| Tier | Culpability | Per-violation range |
|---|---|---|
| 1 | No knowledge, reasonable diligence | $145 – $73,011 |
| 2 | Reasonable cause, not willful neglect | $1,461 – $73,011 |
| 3 | Willful neglect, corrected within 30 days | $14,602 – $73,011 |
| 4 | Willful neglect, not corrected within 30 days | $73,011 – $2,190,294 |
The statutory annual cap across all tiers is $2,190,294, though HHS's Office for Civil Rights has applied lower discretionary annual caps to Tiers 1–3 as enforcement policy since 2019 — worth knowing the two figures can differ depending on which source you're reading. Separately, criminal penalties (DOJ-enforced) scale from a $50,000 fine and up to 1 year in prison for knowingly obtaining or disclosing PHI, up to $250,000 and 10 years for violations committed for commercial gain, personal profit, or malicious harm.
How HIPAA relates to security frameworks
HIPAA's Security Rule is deliberately technology-neutral — it doesn't mandate a specific control framework, just outcomes. In practice, most healthcare organizations map their program to something more concrete: HHS itself publishes a crosswalk (NIST SP 800-66) from the Security Rule to NIST controls, and HITRUST CSF is the most common certifiable framework in healthcare specifically because it harmonizes HIPAA with NIST, ISO 27001, and PCI DSS into one assessable control set — though HITRUST certification itself isn't a legal safe harbor.