What is HIPPA?
/ˈhi-pə/ · noun · misspelling
- A common misspelling of HIPAA, the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law that includes rules about the privacy and security of certain health information.
- See also: HIPPA compliance, HIPPA violation, HIPPA certification.
It's HIPAA. One P, two A's.
Almost everyone assumes the law is named for privacy protection, something like the “Health Information Privacy Protection Act.” Two P's. Perfectly logical. Also totally not correct.
The real HIPAA started life in 1996 with a major focus on keeping your health insurance when you change jobs (that's the Portability). HIPAA also directed the Department of Health and Human Services (HHS) to establish national standards governing health information, and the Privacy and Security Rules everyone associates with HIPAA were issued later.
Okay, so what is HIPAA, actually?
HIPAA is a U.S. federal law whose rules set national standards for how certain organizations handle health information. The rules give patients rights over their own medical records, limit how those organizations may use and share the information, and require them to protect it.
HIPAA applies to health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard healthcare transactions electronically, such as electronic billing (think doctors, hospitals, pharmacies, therapists), plus business associates that handle protected health information on their behalf. It is not a general medical-privacy law that applies to everyone, and it allows a good deal of sharing without asking the patient first. The official version, with the details, is at HHS.gov/hipaa.
Frequently asked questions (spelled exactly the way people ask them)
What does HIPPA stand for?
HIPAA stands for the Health Insurance Portability and Accountability Act, a U.S. federal law passed in 1996. It does not stand for the “Health Information Privacy Protection Act.” That law does not exist, and it's where the extra P usually sneaks in from.
Read more: HIPAA at HHS.gov
Why does everyone spell it HIPPA?
The brain autocompletes the name from what the law feels like it should be: a privacy protection act, two P's. The actual name is about insurance portability and accountability, and the privacy rules everyone associates with it came later, in regulations HHS wrote under the law. This site is called WhatIsHIPPA.com on purpose: it is how a great many people spell it. (An alternate explanation: People picture a hippopotamus when they think HIPPA, and let's face it, a hippopotamus is more fun than healthcare data legislation.)
What are the HIPPA laws?
What people call the “HIPAA laws” are rules HHS wrote under the one law. The Privacy Rule says when health information may be used and shared, and gives patients rights over their records. The Security Rule requires safeguards for health information kept or sent electronically. The Breach Notification Rule requires notifications following certain breaches of unsecured protected health information. The Enforcement Rule covers how HHS investigates and penalizes. HHS publishes a summary of each.
Read more: HIPAA for professionals
Who does HIPPA apply to?
HIPAA applies to covered entities: health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard transactions electronically, which includes most doctors, hospitals, pharmacies, and therapists that bill health plans electronically. It also applies to their business associates: vendors that handle health information for them, such as EHR software, billing services, cloud hosts, telehealth platforms, and AI scribes. It generally does not apply to employers acting as employers, schools, most consumer apps, or individuals, so your step counter is not covered but your cardiologist is.
Read more: Covered entities and business associates
What counts as PHI under HIPPA?
Under HIPAA, protected health information (PHI) is health information that identifies a person and is held by a covered entity or business associate, in any form: spoken, on paper, or electronic. Your blood pressure in your doctor's chart is PHI, and so is a session note maintained by a HIPAA-covered therapist or practice. The same information typed by you into a fitness or mood-tracking app generally is not, because the app is not covered by HIPAA.
Read more: Summary of the Privacy Rule
What is a HIPPA violation?
A HIPAA violation generally means an organization HIPAA covers, or someone who works for it, failed to follow one of HIPAA's rules: sharing information it shouldn't have, failing to protect it, or denying a patient access to their own records. Common examples: a staff member opening a chart with no work reason, test results or session notes sent to the wrong person, posting about patients online, failing to use required safeguards, or mishandling a breach of protected health information. HIPAA violations involve HIPAA-regulated entities, meaning covered entities and business associates, or people acting through those organizations. An ordinary person who is not acting for a HIPAA-regulated organization generally cannot violate HIPAA. Not every privacy mistake is a violation, either; the rules allow a good deal of sharing, such as between your doctor and a specialist, without asking you first.
Read more: HIPAA compliance and enforcement
How do I report a HIPPA violation? Can I sue?
You can file a complaint with the HHS Office for Civil Rights, which enforces HIPAA. HHS explains what a complaint needs to include and how long you have to file, and organizations are not allowed to retaliate against you for complaining. HIPAA itself does not give individuals a right to sue; whether other laws do is a question for a lawyer.
Read more: Filing a HIPAA complaint
What is HIPPA compliance?
HIPAA compliance means a covered organization is following HIPAA's rules on an ongoing basis. It is a state, not a certificate. No product is “HIPAA compliant” on its own: an EHR or AI scribe can support a practice's compliance, but how the practice sets it up and uses it matters too. And compliance is not a guarantee. Following the rules is a floor for how health information must be handled, not a promise that any particular organization handles it well. Nor is it a guarantee that protected health information will never be leaked, improperly accessed, or mishandled.
Read more: HIPAA for professionals
Is there an official HIPPA certification?
There is no official HHS HIPAA certification for organizations or products. HHS does not endorse or recognize private certifications as proof of compliance. A training certificate shows a person completed a course. A third-party audit can be useful evidence that a vendor takes security seriously. A “HIPAA Certified” seal has no legal standing, no matter how shiny the badge. (Seriously, even if it looks super professional looking.)
Read more: HHS on certification
What HIPPA form do I need?
There is no single HIPAA form. People usually mean one of a few documents. An authorization lets a doctor or therapist release your records to someone else, such as a lawyer or an insurer. The Notice of Privacy Practices is the document you are handed at a first visit, and the acknowledgment you sign at check-in just confirms you received it. A request to access your own records does not require a HIPAA authorization, although the provider may require you to submit an access request or verify your identity. On the business side, a business associate agreement (or BAA) is the contract between a practice and a vendor like its EHR or billing service. HHS publishes model notices and sample agreement language.
Read more: HIPAA for individuals
What is HIPPA training?
HIPAA requires covered organizations to train their workforce on applicable privacy policies and procedures and to provide security awareness and training. It does not name a course, a provider, or a number of hours, and HHS does not approve or endorse training vendors. HHS publishes free educational materials of its own.
Read more: HIPAA training and resources
Can my employer ask about my health under HIPPA?
HIPAA generally does not apply to employers acting as employers, your landlord, or a stranger asking nosy questions. Workplace health questions are governed mainly by other laws, such as the ADA and FMLA. HIPAA does cover your doctor or therapist, who generally needs your permission before sharing your records with your employer.
Read more: Employers and health information in the workplace
Can a patient violate HIPPA?
HIPAA regulates covered organizations, not patients. You can share your own health information with anyone you like, and repeating something you overheard in a waiting room or a group therapy session is not a HIPAA violation, though other laws or agreements may apply. A nurse or a therapist can share their own records freely too; the same person opening a coworker's chart out of curiosity is acting as staff, and that is a HIPAA problem.
Read more: Your rights under HIPAA
Is my EHR or AI scribe HIPPA compliant?
If an EHR, AI scribe, telehealth platform, or billing service creates, receives, maintains, or transmits PHI on behalf of a covered entity, it is generally a business associate, and HIPAA requires an appropriate business associate agreement. “Compliant” describes how the tool is set up and used, not a badge on the product, and there is no official certification. The same tool can be used carefully by one practice and carelessly by another.
Read more: Business associates
Does HIPPA require encryption?
The HIPAA Security Rule requires safeguards for electronic protected health information. Encryption is currently an “addressable” implementation specification: an organization must determine whether it is reasonable and appropriate based on its risk analysis and, if it does not use encryption, document that decision and use an appropriate alternative when necessary. It's also important to understand the difference between encryption in transit, encryption at rest, and end-to-end encryption. Encryption does not guarantee that health information can never be improperly accessed or involved in a breach.
Read more: Summary of the Security Rule
Where to read the real thing
Everything above is a short plain-English overview. The official rules and guidance are published by the U.S. Department of Health and Human Services:
- HIPAA at HHS.govThe home page for the law and its rules.
- HIPAA for individualsYour rights, in HHS's own words.
- HIPAA for professionalsSummaries and full text of the Privacy, Security, Breach Notification, and Enforcement Rules.
- Filing a complaintHow to report a possible violation.
Know someone who spells it HIPPA?
Statistically, you know several. Some of them write compliance documentation.