What is the Purpose of HIPAA?

The purpose of HIPAA is to establish federal requirements for protecting the privacy and security of protected health information and to set standards for how health information is used, disclosed, safeguarded, and made available to individuals.

Privacy Protections for Protected Health Information

The HIPAA Privacy Rule limits when protected health information may be used or disclosed and requires safeguards to reduce unauthorized uses and disclosures. The HIPAA Privacy Rule also establishes individual rights related to protected health information, including rights to access and request amendments, and it requires organizations to maintain policies and procedures to support compliant handling.

Security Safeguards for Electronic Protected Health Information

The HIPAA Security Rule requires HIPAA Covered Entities and Business Associates to implement administrative, physical, and technical safeguards to protect electronic protected health information. The HIPAA Security Rule addresses access controls, workforce security, risk analysis and risk management, audit controls, integrity protections, and transmission security.

Breach Response and Notification

The HIPAA Breach Notification Rule establishes requirements for assessing and responding to breaches of unsecured protected health information. The HIPAA Breach Notification Rule includes notification requirements that apply to HIPAA Covered Entities and Business Associates and supports consistent handling of reportable events.

Accountability Through Agreements and Enforcement

HIPAA establishes obligations for Business Associates through written agreements and direct regulatory requirements that apply to Business Associates. HIPAA enforcement mechanisms support corrective actions and penalties when organizations fail to meet required privacy, security, and breach notification obligations.

Daniel Lopez

Daniel Lopez is the HIPAA expert behind HIPAA Coach. Daniel has over 10 years experience as a HIPAA trainer and has developed deep experience in teaching HIPAA to healthcare professionals. Daniel has contributed to numerous publications including expert articles on The HIPAA Guide. Daniel is currently a staff writer on HIPAA at the Healthcare IT Journal. Daniel was a subject matter expert for ComplianceJunction's online HIPAA training. Daniel's academic background in Health Information Management is the foundation of his HIPAA expertise. Daniel's primary professional interest is protecting patient privacy, which he believes is the core of the HIPAA regulations and the best route to HIPAA compliance. You can reach Daniel on the contact page of HIPAA Coach and follow him on Twitter https://twitter.com/DanielLHIPAA