Global & Sector Regulation
HIPAA
Health Insurance Portability and Accountability Act
The US regime for protected health information: the Privacy Rule on permitted use and disclosure, the Security Rule on administrative, physical and technical safeguards, and mandatory breach notification.
Its business associate agreements pull every downstream processor into scope, which is why de-identification and minimum-necessary access are design constraints on any health data platform touching the US.
At a glance
- Category
- Global & Sector Regulation
- Jurisdiction
- US
- Governance
- US HHS / OCR
- Status
- Enacted 1996; Privacy, Security and Breach Notification Rules
- First released
- 1996
Links
Related regulation
Other entries under Global & Sector Regulation.
- BCBS 239: Principles for Effective Risk Data Aggregation and Risk Reporting
- SOX: Sarbanes-Oxley Act
- CCPA / CPRA: California Consumer Privacy Act, as amended
See HIPAA in context
Open the interactive Data Landscape for Regulation to compare HIPAA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.