What Is HIPAA?

HIPAA (the Health Insurance Portability and Accountability Act) is the US federal law governing how healthcare organizations protect patient health information. Its two operative rules split the work: the Privacy Rule controls how health information can be used and disclosed, and the Security Rule sets specific safeguard requirements for that information when it's electronic.

What counts as PHI

Protected Health Information (PHI) is individually identifiable health information relating to a person's past, present, or future physical or mental health, the healthcare they received, or payment for that care — in any form: electronic, paper, or spoken. It's covered the moment a covered entity or business associate creates, receives, maintains, or transmits it, not just when it's stored digitally.

Who has to comply

Covered entities — health plans, healthcare providers, and healthcare clearinghouses that transmit health information electronically — are directly bound by HIPAA. So are business associates: vendors, billing companies, cloud providers, and consultants who handle PHI on a covered entity's behalf. Since a 2013 rule change, business associates are directly liable for compliance too, not just contractually obligated through the covered entity, and must sign a Business Associate Agreement (BAA) before handling any PHI.

Penalty tiers

TierCulpabilityPer-violation range
1No knowledge, reasonable diligence$145 – $73,011
2Reasonable cause, not willful neglect$1,461 – $73,011
3Willful neglect, corrected within 30 days$14,602 – $73,011
4Willful neglect, not corrected within 30 days$73,011 – $2,190,294

The statutory annual cap across all tiers is $2,190,294, though HHS's Office for Civil Rights has applied lower discretionary annual caps to Tiers 1–3 as enforcement policy since 2019 — worth knowing the two figures can differ depending on which source you're reading. Separately, criminal penalties (DOJ-enforced) scale from a $50,000 fine and up to 1 year in prison for knowingly obtaining or disclosing PHI, up to $250,000 and 10 years for violations committed for commercial gain, personal profit, or malicious harm.

How HIPAA relates to security frameworks

HIPAA's Security Rule is deliberately technology-neutral — it doesn't mandate a specific control framework, just outcomes. In practice, most healthcare organizations map their program to something more concrete: HHS itself publishes a crosswalk (NIST SP 800-66) from the Security Rule to NIST controls, and HITRUST CSF is the most common certifiable framework in healthcare specifically because it harmonizes HIPAA with NIST, ISO 27001, and PCI DSS into one assessable control set — though HITRUST certification itself isn't a legal safe harbor.

Common Questions

What's the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs how PHI can be used and disclosed in any form; the Security Rule specifically sets administrative, physical, and technical safeguard requirements for electronic PHI (ePHI) — think encryption, access controls, and audit logging.

How much can a HIPAA violation actually cost?

Civil penalties range from roughly $145 per violation for unknowing, reasonably diligent violations up to over $2.19 million per violation category for willful neglect that isn't corrected — and criminal violations involving intent to profit or cause harm can carry fines up to $250,000 and 10 years in prison.

Does getting ISO 27001 certified automatically make an organization HIPAA compliant?

No. ISO 27001 and HIPAA's Security Rule overlap heavily as control-based frameworks, but HIPAA has PHI-specific requirements — like Business Associate Agreements and its own breach-notification rules — that ISO 27001 doesn't cover on its own.

Want hands-on practice with control testing?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is PCI DSS?

Another sector-specific standard, this one for payment card data.

What Is ISO 27001?

The general-purpose ISMS standard many healthcare vendors cross-walk against HIPAA.