What Is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law enacted in 1996 that establishes national standards for protecting sensitive patient health information. HIPAA applies to covered entities — healthcare providers, health plans, and healthcare clearinghouses — and their business associates.
If you are a founder building a health tech product, a compliance lead at a company that just signed its first hospital customer, or an engineer wondering why your sales team keeps asking about "the BAA," this lesson gives you the complete foundation: what HIPAA actually requires, who it applies to, how it is enforced, and what non-compliance really costs.
Why HIPAA Exists
HIPAA was originally designed to improve the portability of health insurance and reduce healthcare fraud — the "P" in HIPAA stands for Portability, not Privacy. The privacy and security provisions were added to protect patient information as healthcare moved from paper to electronic records. Today, HIPAA is primarily known for its data protection requirements, and that is where nearly all compliance effort goes.
The law evolved in stages, and knowing the timeline helps you understand why the requirements look the way they do:
- 1996 — HIPAA enacted, directing HHS to develop privacy and security standards.
- 2003 — The Privacy Rule takes effect, governing how protected health information may be used and disclosed.
- 2005 — The Security Rule takes effect, requiring safeguards for electronic protected health information.
- 2009 — The HITECH Act dramatically raises penalties, funds enforcement, creates the Breach Notification Rule, and extends direct liability to business associates.
- 2013 — The Omnibus Rule implements HITECH, tightens breach determination (the four-factor risk assessment), and updates business associate obligations.
- Ongoing — HHS continues rulemaking to modernize the Security Rule and address issues like reproductive health privacy and cybersecurity in healthcare, so expect requirements to keep tightening rather than relaxing.
One important clarification up front: there is no such thing as official "HIPAA certification." No government body certifies HIPAA compliance. Vendors that sell "HIPAA certified" badges are selling attestations, not legal status. Compliance is demonstrated through your documentation, risk analysis, safeguards, and — if you are ever investigated — your ability to prove all of it to regulators.
Protected Health Information (PHI)
PHI is any individually identifiable health information held or transmitted by a covered entity or business associate, in any form — electronic, paper, or oral. This includes medical records, billing information, health plan enrollment data, appointment schedules, and any information that identifies a patient and relates to their past, present, or future health condition, treatment, or payment for care. Electronic PHI (ePHI) is PHI stored or transmitted electronically, and it is the focus of the Security Rule.
The "individually identifiable" part matters. HIPAA lists 18 identifiers that make health information identifiable, including names, geographic subdivisions smaller than a state, dates related to an individual (birth, admission, discharge), phone numbers, email addresses, Social Security numbers, medical record numbers, device identifiers, IP addresses, biometric identifiers, and photographs. If health information is stripped of all 18 identifiers (or a statistician certifies re-identification risk is very small), it is de-identified and falls outside HIPAA entirely — a critical concept for analytics and AI products, covered further in the Privacy Rule lesson.
Common founder misconception: PHI is not just "medical records." A list of email addresses belonging to patients of a fertility clinic is PHI. An appointment reminder that reveals a person sees a psychiatrist is PHI. Web analytics data tied to a patient portal login can be PHI. If information connects an identifiable person to health care in any way and sits with a covered entity or business associate, treat it as PHI.
The Major HIPAA Rules
HIPAA contains several rules, but three do most of the work in a compliance program. The Privacy Rule governs how PHI can be used and disclosed. The Security Rule requires safeguards to protect ePHI. The Breach Notification Rule requires notification when PHI is compromised. We cover each in detail in subsequent lessons.
| Rule | What It Governs | Who It Applies To | Core Obligation |
|---|---|---|---|
| Privacy Rule | Use and disclosure of PHI in all forms; patient rights | Covered entities (business associates for certain provisions) | Only use or disclose PHI as permitted; honor patient rights |
| Security Rule | Confidentiality, integrity, availability of ePHI | Covered entities and business associates | Administrative, physical, and technical safeguards; risk analysis |
| Breach Notification Rule | Response when unsecured PHI is compromised | Covered entities and business associates | Notify individuals, HHS, and sometimes media within deadlines |
| Enforcement Rule | Investigations, penalties, hearings | Everyone regulated | Cooperate with OCR; penalties scale with culpability |
| Omnibus Rule (2013) | Implements HITECH updates across the rules | Everyone regulated | Direct BA liability, updated BAAs, stricter breach standard |
There is also the Transactions and Code Sets Rule governing electronic healthcare transactions (mostly relevant to billing and clearinghouse workflows) and the Unique Identifiers Rule (NPI numbers). Most technology companies never touch these directly.
Who Must Comply
Covered entities must comply with all HIPAA rules. There are three types:
- Healthcare providers who transmit health information electronically in connection with standard transactions — hospitals, physician practices, dentists, pharmacies, mental health providers, and increasingly telehealth companies that employ or contract clinicians.
- Health plans — insurers, HMOs, employer-sponsored group health plans, Medicare, and Medicaid.
- Healthcare clearinghouses — entities that translate health data between standard and non-standard formats, mostly in the claims pipeline.
Business associates are organizations that create, receive, maintain, or transmit PHI on behalf of a covered entity. This is where most SaaS companies, cloud providers, analytics vendors, billing services, and IT firms land. Business associates must comply with the Security Rule in full, the Breach Notification Rule, and the Privacy Rule provisions relevant to their services, and they carry direct liability — OCR can fine a business associate without touching the covered entity. The mechanics of business associate agreements are covered in the business associates lesson.
A few boundary cases founders frequently get wrong:
- A wellness app selling directly to consumers with no covered entity involved is generally not regulated by HIPAA — but it is regulated by the FTC, including the FTC's Health Breach Notification Rule, which has been enforced aggressively against digital health apps.
- An employer holding employee health data in its HR files is generally not covered — but its group health plan is.
- A startup with one hospital pilot becomes a business associate the moment PHI flows, regardless of company size, revenue, or whether a BAA was actually signed. The obligations attach to the activity, not the paperwork.
How HIPAA Is Enforced
The Office for Civil Rights (OCR) within HHS enforces the Privacy, Security, and Breach Notification Rules. Enforcement begins in three ways: complaints filed by patients or employees (tens of thousands per year), breach reports you are required to file yourself, and compliance reviews OCR opens on its own initiative — often after media coverage of an incident.
A typical enforcement path: OCR opens an investigation, sends a data request (your risk analysis, policies, training records, BAAs, and incident documentation are always on the list), and resolves the matter through voluntary compliance, a resolution agreement with a monetary settlement and a multi-year corrective action plan, or — rarely — formal civil money penalties. State attorneys general can also bring HIPAA actions under HITECH, and many breaches trigger parallel state breach-notification and consumer-protection exposure.
The single most cited failure in OCR enforcement actions is the absence of an accurate, thorough risk analysis — the foundational Security Rule requirement. OCR has run an explicit Risk Analysis Initiative because so many investigated entities cannot produce one. The second recurring theme is small-scale "Right of Access" enforcement: OCR has settled dozens of cases, many under $100,000, against providers who failed to give patients timely copies of their own records.
Penalties for Non-Compliance
Civil penalties are tiered by culpability and adjusted annually for inflation. The four tiers, in current inflation-adjusted terms:
| Tier | Culpability | Per-Violation Range (approx.) | Annual Cap (approx.) |
|---|---|---|---|
| 1 | Did not know and could not reasonably have known | Roughly $140 to $71,000 | About $25,000 under HHS enforcement discretion (statutory cap over $2.1 million) |
| 2 | Reasonable cause, not willful neglect | Roughly $1,400 to $71,000 | About $100,000 (statutory cap over $2.1 million) |
| 3 | Willful neglect, corrected within 30 days | Roughly $14,000 to $71,000 | About $250,000 (statutory cap over $2.1 million) |
| 4 | Willful neglect, not corrected | Roughly $71,000 minimum per violation | Over $2.1 million |
Two practical notes. First, "per violation" can mean per affected record or per day of non-compliance, so numbers escalate fast. Second, HHS's 2019 notice of enforcement discretion lowered the annual caps for the lower tiers, but willful neglect — knowing about a problem and ignoring it — still exposes you to seven-figure penalties. Documented good-faith effort is your best defense.
Criminal penalties, enforced by the Department of Justice, apply to knowing wrongful disclosure of PHI: up to $50,000 and one year in prison for basic offenses, up to $100,000 and five years when committed under false pretenses, and up to $250,000 and ten years when done for commercial advantage or malicious harm. Criminal cases are uncommon but real — snooping employees and data-selling insiders have been prosecuted.
Beyond regulatory penalties, the practical costs usually dominate: breach response and forensics, patient notification and credit monitoring, class-action litigation, lost enterprise deals, and OCR's public breach portal listing every breach affecting 500 or more individuals — informally known as the "Wall of Shame." For a startup, the biggest cost of weak HIPAA posture is often the enterprise healthcare deal that dies in security review.
HIPAA Applicability Checklist
Use this to determine where you stand:
- Do we provide healthcare services and bill electronically? If yes, we are a covered entity.
- Do we operate or sponsor a health plan? If yes, the plan is a covered entity.
- Do we create, receive, maintain, or transmit PHI on behalf of a covered entity or another business associate? If yes, we are a business associate.
- Have we signed (or been asked to sign) a business associate agreement with every relevant partner?
- Have we inventoried where PHI lives in our systems — databases, logs, backups, analytics, support tickets, email?
- Have we completed and documented a Security Rule risk analysis in the last 12 months?
- Do we have written HIPAA policies, workforce training records, and a designated privacy/security officer?
- Do we have an incident response process that includes breach risk assessment and notification timelines?
- If we are consumer health tech outside HIPAA, have we assessed FTC Health Breach Notification Rule exposure instead?
If you checked the business associate box and cannot check the risk analysis and policies boxes, that gap is your immediate priority.
Frequently Asked Questions
Is there an official HIPAA certification?
No. No federal agency certifies HIPAA compliance. Third-party attestations, SOC 2 reports with HIPAA mapping, and HITRUST certification can demonstrate your program to customers, but none of them confers legal compliance status. OCR evaluates your actual documentation and safeguards, not a badge.
Does HIPAA apply to my startup if we only have a pilot with one clinic?
Yes. Business associate status attaches when PHI flows to you on behalf of a covered entity, regardless of company size or contract value. There is no small-business exemption. Scale your program sensibly — the Security Rule is explicitly flexible about organization size — but you cannot skip it.
We only store encrypted PHI and never look at it. Are we still a business associate?
Almost always yes. Maintaining PHI on behalf of a covered entity makes you a business associate even if you never view it. There is a narrow "conduit" exception for entities that merely transmit data transiently (like an ISP or postal carrier), but OCR interprets it very narrowly — persistent storage takes you out of conduit territory.
What is the difference between HIPAA and HITRUST?
HIPAA is a law; HITRUST is a private certifiable framework that maps to HIPAA and other standards. Healthcare enterprises often ask vendors for HITRUST certification as evidence of HIPAA-aligned security. See our HITRUST introduction for the full comparison.
How much does HIPAA compliance cost for a small company?
For a small SaaS business associate, expect the core program — risk analysis, policies, training, technical hardening, and BAA management — to consume weeks of internal effort plus tooling costs. Compliance automation platforms have compressed this significantly by mapping controls, collecting evidence, and generating policies. Costs scale with the complexity of your PHI footprint, not headcount.
What triggers most OCR investigations?
Breach reports you file yourself and complaints from patients or former employees. That means two of your highest-leverage protections are a genuinely tested incident response process and a healthy internal culture where staff report problems to you before they report them to OCR.
In the next lesson, we will cover the HIPAA Security Rule in detail.
Building a HIPAA program usually means choosing a compliance automation platform and, for adjacent certifications, an auditor. AuditXYZ helps you compare compliance automation platforms and auditors side by side so you can pick the stack that fits your PHI footprint and budget.