Health Insurance Portability and Accountability Act (Wikipedia)
Wikipedia’s article on HIPAA, the 1996 U.S. federal law governing protected health information (PHI).
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Key points
- Applies to covered entities (health plans, clearinghouses, providers transmitting health data electronically) and, since a 2013 rule, their business associates.
- The Privacy Rule requires a Notice of Privacy Practices, a 30-day deadline to fulfill a patient’s own PHI access request, and a minimum-necessary standard for other disclosures; other disclosures need the patient’s written authorization.
- The Security Rule covers access controls tied to job function, workstation/screen placement away from public view, audit documentation, and encryption of PHI in transit.
- A 2013 Omnibus Rule extended some record-retention obligations (e.g., 50 years post-death) and formalized the business-associate extension.
- The article notes providers have historically been overcautious in applying the law, given ongoing uncertainty about its exact scope.