The purpose of HIPAA is to establish federal requirements for protecting the privacy and security of protected health information and to set standards for how health information is used, disclosed, safeguarded, and made available to individuals.
Privacy Protections for Protected Health Information
The HIPAA Privacy Rule limits when protected health information may be used or disclosed and requires safeguards to reduce unauthorized uses and disclosures. The HIPAA Privacy Rule also establishes individual rights related to protected health information, including rights to access and request amendments, and it requires organizations to maintain policies and procedures to support compliant handling.
Security Safeguards for Electronic Protected Health Information
The HIPAA Security Rule requires HIPAA Covered Entities and Business Associates to implement administrative, physical, and technical safeguards to protect electronic protected health information. The HIPAA Security Rule addresses access controls, workforce security, risk analysis and risk management, audit controls, integrity protections, and transmission security.
Breach Response and Notification
The HIPAA Breach Notification Rule establishes requirements for assessing and responding to breaches of unsecured protected health information. The HIPAA Breach Notification Rule includes notification requirements that apply to HIPAA Covered Entities and Business Associates and supports consistent handling of reportable events.
Accountability Through Agreements and Enforcement
HIPAA establishes obligations for Business Associates through written agreements and direct regulatory requirements that apply to Business Associates. HIPAA enforcement mechanisms support corrective actions and penalties when organizations fail to meet required privacy, security, and breach notification obligations.
