Global & Sector Regulation

HIPAA

Health Insurance Portability and Accountability Act

Law / regulation US US HHS / OCR Since 1996

The US regime for protected health information: the Privacy Rule on permitted use and disclosure, the Security Rule on administrative, physical and technical safeguards, and mandatory breach notification.

Its business associate agreements pull every downstream processor into scope, which is why de-identification and minimum-necessary access are design constraints on any health data platform touching the US.

At a glance

Category
Global & Sector Regulation
Jurisdiction
US
Governance
US HHS / OCR
Status
Enacted 1996; Privacy, Security and Breach Notification Rules
First released
1996

Links

Related regulation

Other entries under Global & Sector Regulation.

See HIPAA in context

Open the interactive Data Landscape for Regulation to compare HIPAA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.