Health Administration · Law and Policy
HIPAA Foundations
On this page 9 sections
In 30 seconds
HIPAA The Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), a federal statute whose Administrative Simplification provisions authorized national health-information privacy, security, and transaction rules. Full entry → — the Health Insurance Portability and Accountability Act of 1996 — is best understood as a statute plus a stack of federal regulations. Its Administrative Simplification The set of HIPAA provisions (Title II, sections 261-264) directing HHS to adopt national standards for electronic health care transactions, identifiers, privacy, and security. Full entry → provisions directed HHS to write rules, now codified in 45 CFR Parts 160, 162, and 164. Those rules — Privacy, Security, Breach Notification, and Transactions and Identifiers — bind covered entities and their business associates, and HHS's Office for Civil Rights enforces them through tiered penalties.
Why this matters
Almost every decision a health administrator makes about information — who may see a record, how a vendor is hired, what happens after a laptop is lost — runs through HIPAA. Knowing that HIPAA is a 1996 law implemented by specific regulations, rather than a single vague "privacy law," lets you find the actual requirement instead of guessing. It also clarifies who is on the hook: not just hospitals and health plans, but the contractors that handle their data. As enforcement and penalties grew after the HITECH Act The Health Information Technology for Economic and Clinical Health Act (2009), enacted within the American Recovery and Reinvestment Act, which strengthened HIPAA enforcement, added breach notification, and made business associates directly liable. Full entry →, that structural literacy became the foundation for compliance programs, audits, and breach response.
The college version
The statute and Administrative Simplification
HIPAA is the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, signed on August 21, 1996. The name points to its original purpose — helping people keep health coverage when they change jobs (portability) and combating fraud and abuse (accountability). The part that dominates a health administrator's working life, however, is Title II, Subtitle F: the Administrative Simplification provisions (sections 261 through 264). Congress wanted to move health care's paperwork onto standardized electronic transactions, and it recognized that doing so safely required national rules for privacy and security. Rather than write those detailed rules itself, Congress directed the Secretary of Health and Human Services (HHS) to issue them. That delegation is why HIPAA lives in two layers: a short statute that sets the goals and grants authority, and a much larger body of regulations that spells out the actual requirements. When someone asks "what does HIPAA require," the answer almost always lives in the regulations, not the 1996 text.
The regulatory architecture: 45 CFR Parts 160, 162, and 164
HHS codified the Administrative Simplification rules in Title 45 of the Code of Federal Regulations, across three parts. Part 160 holds the general administrative requirements: the definitions everyone relies on (including "Covered entity A health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a HIPAA-covered transaction (45 CFR 160.103). Full entry →" and "Business associate A person or organization that creates, receives, maintains, or transmits PHI to perform a function or service on behalf of a covered entity (45 CFR 160.103). Full entry →" at 45 CFR 160.103), the rules about when HIPAA preempts contrary state law, and the compliance, investigation, and penalty machinery. Part 162 contains the Transactions and Code Sets standards and the unique identifiers — for example, the National Provider Identifier (Subpart D) and the standard employer identifier (Subpart F), along with the standard formats for claims, eligibility checks, remittance, and other electronic transactions. Part 164 contains the two rules the public knows best plus a third: the Security Rule 45 CFR Part 164, Subpart C: the rule requiring administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI. Full entry → (Subpart C), the Breach Notification Rule 45 CFR Part 164, Subpart D: the rule requiring notice to individuals, HHS, and sometimes the media after a breach of unsecured PHI, generally within 60 days of discovery. Full entry → (Subpart D), and the Privacy Rule (Subpart E). Reading a HIPAA question well starts with locating it in this map — a records-access dispute is a Part 164 Subpart E question, a lost-laptop question implicates Subparts C and D, and a claims-format question is Part 162.
The Privacy, Security, and Breach Notification Rules
The Privacy Rule (45 CFR Part 164, Subpart E) governs Protected health information (PHI) Individually identifiable health information held or transmitted by a covered entity or business associate, in any form or medium, that HIPAA protects. Full entry → in any form — spoken, paper, or electronic. It sets the baseline that a covered entity may use or disclose PHI only as the rule permits or requires, gives individuals rights such as access to their own records, and requires reasonable safeguards. The Security Rule (Subpart C) is narrower in scope but deeper in detail: it protects only electronic PHI (ePHI) and requires covered entities and business associates to ensure the confidentiality, integrity, and availability of that data. It organizes its requirements into three families of safeguards — administrative (policies, workforce training, risk analysis), physical (facility and device controls), and technical (access controls, encryption, audit logs). The Breach Notification Rule (Subpart D) governs what happens when protection fails: a breach of unsecured PHI generally triggers notice to affected individuals without unreasonable delay and no later than 60 calendar days after discovery, along with notice to HHS and, for large breaches, the media. Together these three rules form a life cycle — permitted handling, required protection, and mandatory disclosure when things go wrong.
Who is regulated: covered entities and business associates
HIPAA does not regulate everyone who touches health data. It binds two categories. A covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a covered transaction (45 CFR 160.103). A large hospital and a solo dentist who bills insurance electronically are both covered entities; a fitness app that a consumer uses on their own generally is not. The second category is the business associate: a person or organization that creates, receives, maintains, or transmits PHI to perform a function on behalf of a covered entity — think billing companies, cloud storage vendors, shredding services, or outside lawyers and accountants handling PHI. A covered entity may share PHI with a business associate only under a written Business associate agreement (BAA) A required written contract obligating a business associate to safeguard PHI and comply with applicable HIPAA requirements before a covered entity may share PHI with it. Full entry → that binds the associate to protect the information. Since the HITECH Act, business associates are directly liable for many HIPAA requirements, not merely contractually bound, which is why vendor management sits at the center of modern compliance programs.
HITECH and enforcement: OCR and the penalty tiers
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as Title XIII of the American Recovery and Reinvestment Act of 2009, reshaped HIPAA. It created the federal Breach Notification Rule, extended direct liability to business associates, and strengthened enforcement, including a tiered civil money penalty structure. HHS implemented these changes chiefly through the 2013 Omnibus Rule (78 FR 5566). Enforcement is carried out by HHS's Office for Civil Rights (OCR). The civil penalty scheme in 45 CFR Part 160, Subpart D scales with culpability across four tiers: the violator did not know and could not reasonably have known; the violation was due to reasonable cause and not willful neglect; willful neglect that was corrected; and willful neglect that was not corrected. The regulation sets per-violation ranges and an annual cap for identical violations, but it states that these dollar figures are adjusted for inflation each year and published at 45 CFR Part 102 — so the operative numbers are the current adjusted amounts, not a fixed 1996 or 2009 figure. Separately, the criminal provisions at 42 U.S.C. 1320d-6 punish knowing wrongful disclosure, escalating from a base offense to false-pretenses conduct to disclosure intended for sale or personal gain, with correspondingly higher fines and prison terms. None of this is a substitute for legal advice; it is the map a health administrator uses to know which rule, which regulator, and which stakes apply.

Eli explains
The same idea, in plain words
Explain it like I’m 10
HIPAA is really two things stacked together. The bottom is a law Congress passed in 1996 that said, in effect, "health information moving around by computer needs national rules — HHS, go write them." The top is the set of detailed rules HHS actually wrote, which is where all the specific do's and don'ts live. Those rules split the job up: one rule (Privacy) covers who may see health information, one rule (Security) covers protecting the computer version of it, one rule (Breach Notification) covers telling people when protection fails, and another set covers standard formats and ID numbers for electronic paperwork. The rules only apply to certain organizations — health plans, clearinghouses, and providers who bill electronically — plus the outside companies ("business associates") they hire to handle the data. A federal office called OCR checks that everyone follows the rules and can fine those who don't.
Picture it like this
Think of HIPAA like the rules for a swimming pool. The city passes a short ordinance saying "public pools must be safe," then the health department writes the thick rulebook: how deep the water can be, where lifeguards stand, what the chlorine level must be, and what to do if someone gets hurt. The ordinance is HIPAA the statute; the rulebook is the regulations in 45 CFR.
Where the picture stops working
The analogy understates two things. HIPAA reaches beyond the "pool owner" (the covered entity) to the contractors it hires (business associates), as if the towel service and the repair crew were also bound by the pool rules. And HIPAA's penalties scale with fault — an honest mistake and deliberate neglect are treated very differently — which a simple safety code usually does not capture.
Worked example
A 30-physician clinic that bills insurers electronically is a covered entity. It signs up with a cloud vendor to host its records and hires an outside company to mail patient statements. Both vendors will handle PHI on the clinic's behalf, so each is a business associate, and the clinic must execute a business associate agreement with each before sharing any PHI. Months later, an employee at the statement vendor emails an unencrypted spreadsheet of 4,000 patients to the wrong address. Because this is unsecured PHI disclosed in a way the Privacy Rule does not permit, it is a breach under Subpart D. The vendor must notify the clinic; the clinic must notify the affected individuals without unreasonable delay and no later than 60 days after discovery, notify HHS, and — because more than 500 people are affected — notify prominent media in the area. If OCR later finds the vendor ignored a known encryption gap, the willful-neglect tiers of the civil penalty scheme in 45 CFR Part 160 come into play, at the inflation-adjusted amounts then in effect.
Key takeaway
HIPAA is a 1996 statute implemented through regulations in 45 CFR Parts 160, 162, and 164 — the Privacy, Security, Breach Notification, and Transactions/Identifiers rules — that bind covered entities and their business associates and are enforced by HHS's Office for Civil Rights through inflation-adjusted, culpability-tiered penalties.
Quick check
3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.
Which HIPAA rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI)?
A medical group hires an outside company to process its insurance claims, and the company will receive patients' PHI to do that work. Under HIPAA, what is that company, and what must the group put in place?
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related
You’ll learn to
- Define HIPAA and its Administrative Simplification provisions, and locate their implementing rules in 45 CFR Parts 160, 162, and 164.
- Distinguish the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Transactions and Identifiers standards by what each governs.
- Explain who is regulated — covered entities and business associates — and the role of the business associate agreement.
- Describe how the HITECH Act strengthened HIPAA and how HHS's Office for Civil Rights enforces it through tiered civil and criminal penalties.
Common mistakes
Treating HIPAA as one single "privacy law."
HIPAA is a statute plus several distinct regulations — Privacy, Security, Breach Notification, and Transactions/Identifiers — that govern different things. Naming the specific rule is how you find the actual requirement.
Believing HIPAA protects all health information held by anyone.
HIPAA binds only covered entities and their business associates. Health data a consumer enters into a personal app, or that an employer holds as an employer, is often outside HIPAA entirely.
Assuming the Privacy Rule and the Security Rule cover the same thing.
The Privacy Rule covers PHI in any form and governs uses and disclosures; the Security Rule covers only electronic PHI and specifies administrative, physical, and technical safeguards.
Quoting a fixed maximum penalty figure as if it never changes.
The civil penalty amounts in 45 CFR Part 160 are adjusted for inflation each year and published at 45 CFR Part 102. Cite the tiered structure and "as adjusted," not a stale dollar amount.
Thinking a signed contract with a vendor is optional or merely good practice.
A covered entity generally may not share PHI with a business associate without a business associate agreement, and since HITECH the associate is also directly liable under HIPAA.
Easily confused
Privacy Rule (Part 164, Subpart E) vs. Security Rule (Part 164, Subpart C)
The Privacy Rule governs all PHI in any medium and controls uses and disclosures; the Security Rule governs only electronic PHI and mandates administrative, physical, and technical safeguards.
Covered entity vs. Business associate
A covered entity is a health plan, clearinghouse, or electronically billing provider; a business associate is an outside party handling PHI on a covered entity's behalf, bound through a business associate agreement.
Civil penalties (45 CFR Part 160, Subpart D) vs. Criminal penalties (42 U.S.C. 1320d-6)
Civil money penalties are imposed by OCR and scale across four culpability tiers; criminal penalties are prosecuted for knowing wrongful disclosure and escalate with intent to deceive or profit.
Key vocabulary
- HIPAA
- The Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), a federal statute whose Administrative Simplification provisions authorized national health-information privacy, security, and transaction rules.
- Administrative Simplification
- The set of HIPAA provisions (Title II, sections 261-264) directing HHS to adopt national standards for electronic health care transactions, identifiers, privacy, and security.
- Protected health information (PHI)
- Individually identifiable health information held or transmitted by a covered entity or business associate, in any form or medium, that HIPAA protects.
- Electronic protected health information (ePHI)
- PHI that is created, received, maintained, or transmitted in electronic form; it is the specific data the Security Rule protects.
- Covered entity
- A health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a HIPAA-covered transaction (45 CFR 160.103).
- Business associate
- A person or organization that creates, receives, maintains, or transmits PHI to perform a function or service on behalf of a covered entity (45 CFR 160.103).
- Business associate agreement (BAA)
- A required written contract obligating a business associate to safeguard PHI and comply with applicable HIPAA requirements before a covered entity may share PHI with it.
- Security Rule
- 45 CFR Part 164, Subpart C: the rule requiring administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI.
- Breach Notification Rule
- 45 CFR Part 164, Subpart D: the rule requiring notice to individuals, HHS, and sometimes the media after a breach of unsecured PHI, generally within 60 days of discovery.
- HITECH Act
- The Health Information Technology for Economic and Clinical Health Act (2009), enacted within the American Recovery and Reinvestment Act, which strengthened HIPAA enforcement, added breach notification, and made business associates directly liable.
Sources & references
- Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 (110 Stat. 1936) — U.S. Congress / Government Publishing Office (Statutes at Large)
- 45 CFR Part 160 - General Administrative Requirements (HIPAA applicability, definitions, and preemption) — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
- 45 CFR Part 162 - Administrative Requirements (Transactions, Code Sets, and Unique Identifiers) — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
- 45 CFR Part 164 Subpart C - Security Standards for the Protection of Electronic Protected Health Information — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
- 45 CFR Part 164 Subpart D - Notification in the Case of Breach of Unsecured Protected Health Information — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
- 45 CFR Part 164 Subpart E - Privacy of Individually Identifiable Health Information — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
- Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act and GINA (78 FR 5566) — U.S. Department of Health and Human Services / Federal Register
- 42 U.S.C. 1320d-6 - Wrongful disclosure of individually identifiable health information — Office of the Law Revision Counsel, U.S. House of Representatives (U.S. Code)
- HIPAA Administrative Simplification - Standard electronic transactions overview — Centers for Medicare & Medicaid Services (CMS)
EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.
Researched 2026-08-19
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

