What HIPAA Is and Why It Exists

HIPAA stands for the Health Insurance Portability and Accountability Act, a federal law passed in 1996. The law creates rules about how health information can be collected, used, and shared. Understanding HIPAA matters because it affects your medical privacy and your rights as a patient.

Learn How to Make Beef Gravy from Pan Drippings →

The law was created for several reasons. Before HIPAA, there were few national standards protecting health information. Someone's medical records could be shared widely without their knowledge. Insurance companies had few restrictions on what they could do with personal health data. The law aimed to fix these problems by setting minimum privacy and security standards across the entire country.

HIPAA applies to three main groups of organizations: covered entities, business associates, and subcontractors. Covered entities are the organizations that must follow HIPAA rules. These include health plans (like insurance companies and HMOs), healthcare providers (doctors, hospitals, clinics), and healthcare clearinghouses (organizations that process health information). Business associates are companies that work with covered entities and handle protected health information. If a covered entity hires a company to handle records or billing, that company must also follow HIPAA rules. Subcontractors are companies hired by business associates and must follow the same standards.

HIPAA actually contains multiple parts, though most people think of it as one rule. The Privacy Rule controls how health information is used and shared. The Security Rule sets standards for protecting electronic health information. The Breach Notification Rule requires organizations to tell you if your information is compromised. The Enforcement Rule explains what happens when organizations break the rules. Each part addresses different aspects of health information protection.

The law protects "protected health information" or PHI. This includes any information in your medical record or health plan information that can identify you. Examples include your name, address, phone number, Social Security number, medical record numbers, and specific health conditions. Even indirect identifiers can be protected—information like birth dates combined with other facts that could lead someone to figure out who you are. The key principle is that if information could reasonably identify you, HIPAA likely covers it.

Practical takeaway: HIPAA is a federal law that sets minimum standards for protecting your health information. It applies to your doctor's office, hospital, insurance company, and other health-related organizations. The law covers information that could identify you, including your name, health conditions, and medical record numbers.

Understanding Protected Health Information (PHI)

Protected Health Information, or PHI, is the specific category of information that HIPAA rules protect. Not all information about you is PHI—the law focuses on health information that can identify you. Learning what counts as PHI helps you understand what privacy protections apply to you.

Learn About Getting Rid of Body Lice →

PHI includes identifiers directly tied to health information. These identifiers are things like your full name, your address, your phone number, your email address, your Social Security number, your medical record number, your health plan member ID number, your account numbers, and your license plate number. If any of these identifiers appears with health information, that information typically becomes PHI. For example, a list of all your medications without your name attached might not be PHI, but the same list with your name is PHI.

PHI also includes specific health data. This covers any information about your past, present, or future physical or mental health condition. Examples include diagnoses (like "diabetes" or "depression"), treatment information (like "knee surgery scheduled for June 15"), medication lists, lab results, imaging results, mental health notes, and substance abuse treatment information. Payment information related to healthcare also counts as PHI—things like insurance claim information, billing records, and payment history.

There are some specific types of information that receive extra protection under HIPAA. Mental health records have additional safeguards beyond standard medical records. Substance abuse treatment information is heavily restricted and requires special consent before sharing. HIV/AIDS status information is protected with stricter rules in many states. Genetic information and information about genetic testing may have additional protections. These categories receive stronger privacy protection because of the sensitive nature of the information and the potential for discrimination.

HIPAA distinguishes between identified and de-identified information. De-identified information is health information with all identifiers removed. According to HIPAA, if someone has removed 18 specific identifiers (including name, address, phone number, Social Security number, and medical record number), the remaining information is considered de-identified and is no longer protected by HIPAA. This allows researchers and organizations to use health data for studies and other purposes without HIPAA restrictions. However, the removal process must be done correctly—simply taking out a name isn't enough.

One important aspect of PHI is that it can exist in different forms. Electronic PHI (e-PHI) is health information stored or sent electronically—in your online patient portal, in emails between you and your doctor, in your insurance company's computer system, or in text messages with healthcare providers. Paper PHI is information on printed documents—your medical record files, printed lab results, or paper billing statements. Oral PHI exists in spoken communication—conversations between you and your doctor, phone calls with your insurance company, or discussions in medical offices. HIPAA protects all these forms equally.

Practical takeaway: PHI is health information that can identify you. It includes your personal identifiers (name, address, medical record number) combined with health information (diagnoses, medications, test results). Information without identifiers removed usually counts as PHI. Understanding what's protected helps you know your privacy rights.

HIPAA Coverage: Who Must Follow the Rules

HIPAA doesn't apply to every organization that handles information about your health. The law only covers specific types of organizations called "covered entities." Knowing which organizations must follow HIPAA helps you understand what privacy protections apply to your information in different settings.

Learn About Finding LabCorp Locations and Scheduling →

Health plans are the first major category of covered entities. This includes health insurance companies (both for-profit and non-profit), Health Maintenance Organizations (HMOs), preferred provider organizations (PPOs), point-of-service plans, dental plans, vision plans, and long-term care insurance plans. Federal programs like Medicare and Medicaid are covered entities. Employee health plans offered by employers are typically covered entities if they involve a health insurance company or administrator. Government health plans like the Veterans Health Administration and military health system must follow HIPAA. However, certain small group health plans with fewer than 50 members may have different rules depending on circumstances.

Healthcare providers are the second major category. This includes doctors (both individual practitioners and group practices), hospitals, urgent care centers, ambulatory surgery centers, dental offices, mental health clinics, physical therapy offices, nursing homes, hospices, and home health agencies. Pharmacies are covered entities for the prescriptions they handle. Medical labs that test samples are covered entities. Behavioral health facilities and substance abuse treatment programs are covered entities. Any organization that bills for healthcare services and stores patient health information is likely a covered entity. This applies regardless of whether the provider works for the government or is a private business.

Healthcare clearinghouses are the third category of covered entities. These are organizations that process health information into standard formats. Medical billing companies that translate information from one format to another are clearinghouses. Insurance claim processors are covered entities. Any organization that converts health information into standardized electronic formats must follow HIPAA. These organizations often work behind the scenes—patients may not even know they exist—but they handle sensitive health information.

Business associates are organizations that aren't covered entities themselves but must still follow HIPAA because they work with covered entities. If a covered entity hires another company to help with operations and that company handles PHI, the hired company becomes a business associate. Examples include medical transcription companies, cloud storage providers that store health records, billing software companies, IT support services, legal firms hired by hospitals, accountants for healthcare organizations, medical record copying services, and patient portal vendors. Business associates must sign Business Associate Agreements (BAAs) with covered entities, and they must follow the same HIPAA Privacy, Security, and Breach Notification Rules. If a business associate hires another company to help, that third company becomes a subcontractor and must also follow HIPAA rules.

Several types of organizations are NOT covered entities and therefore don't have to follow HIPAA. Life insurance companies aren't covered entities (though they may be regulated by different laws). Employers who offer health insurance through a health plan are only covered for the health plan portion, not for general employment records. Schools and school districts aren't covered by HIPAA (though they may have protections under FERPA, the Family Educational Rights and Privacy Act). Non-medical providers like gyms, fitness centers, and wellness apps without medical