What is HIPPA?
/ˈhi-pə/ · noun · misspelling
- A common misspelling of HIPAA, the Health Insurance Portability and Accountability Act of 1996, a U.S. federal law that includes rules about the privacy and security of certain health information.
- See also: HIPPA compliance, HIPPA violation, HIPPA certification. All spelled HIPAA, for the same reason.
It's HIPAA. One P, two A's.
Almost everyone assumes the law is named for privacy protection, something like the “Health Information Privacy Protection Act.” Two P's. Perfectly logical. Also not the law.
The real HIPAA started life in 1996 as a law about keeping your health insurance when you change jobs (that's the Portability). The privacy and security rules everyone knows it for were written later by the Department of Health and Human Services (HHS) under its Accountability provisions.
Okay, so what is HIPAA, actually?
HIPAA is a U.S. federal law whose rules set national standards for how certain organizations handle health information. The rules give patients rights over their own medical records, limit how those organizations may use and share the information, and require them to protect it.
HIPAA applies to health plans, healthcare clearinghouses, and providers that bill electronically (doctors, hospitals, pharmacies, therapists), plus the vendors that handle health information for them. It is not a general medical-privacy law that applies to everyone, and it allows a good deal of sharing without asking the patient first. The official version, with the details, is at HHS.gov/hipaa.
Frequently asked questions (spelled exactly the way people ask them)
What does HIPPA stand for?
HIPAA stands for the Health Insurance Portability and Accountability Act, a U.S. federal law passed in 1996. It does not stand for the “Health Information Privacy Protection Act.” That law does not exist, and it's where the extra P usually sneaks in from.
Read more: HIPAA at HHS.gov
Why does everyone spell it HIPPA?
The brain autocompletes the name from what the law feels like it should be: a privacy protection act, two P's. The actual name is about insurance portability and accountability, and the privacy rules everyone associates with it came later, in regulations HHS wrote under the law. This site is called WhatIsHIPPA.com on purpose: it is how a great many people spell it.
What are the HIPPA laws?
What people call the “HIPAA laws” are rules HHS wrote under the one law. The Privacy Rule says when health information may be used and shared, and gives patients rights over their records. The Security Rule requires safeguards for health information kept or sent electronically. The Breach Notification Rule requires organizations to tell people, and HHS, when health information is exposed. The Enforcement Rule covers how HHS investigates and penalizes. HHS publishes a summary of each.
Read more: HIPAA for professionals
Who does HIPPA apply to?
HIPAA applies to covered entities: health plans, healthcare clearinghouses, and healthcare providers that bill electronically, which is nearly every doctor, hospital, pharmacy, and therapist that takes insurance. It also applies to their business associates: vendors that handle health information for them, such as EHR software, billing services, cloud hosts, telehealth platforms, and AI scribes. It generally does not apply to employers acting as employers, schools, most consumer apps, or individuals, so your step counter is not covered but your cardiologist is.
Read more: Covered entities and business associates
What counts as PHI under HIPPA?
Under HIPAA, protected health information (PHI) is health information that identifies a person and is held by a covered entity or business associate, in any form: spoken, on paper, or electronic. Your blood pressure in your doctor's chart is PHI, and so is a therapist's session note in an EHR. The same information typed by you into a fitness or mood-tracking app generally is not, because the app is not covered by HIPAA.
Read more: Summary of the Privacy Rule
What is a HIPPA violation?
A HIPAA violation generally means an organization HIPAA covers, or someone who works for it, failed to follow one of HIPAA's rules: sharing information it shouldn't have, failing to protect it, or denying a patient access to their own records. Common examples: a staff member opening a chart with no work reason, test results or session notes sent to the wrong person, posting about patients online, an unencrypted laptop full of records going missing. Only covered organizations and their workers can violate HIPAA. Not every privacy mistake is a violation, either; the rules allow a good deal of sharing, such as between your doctor and a specialist, without asking you first.
Read more: HIPAA compliance and enforcement
How do I report a HIPPA violation? Can I sue?
You can file a complaint with the HHS Office for Civil Rights, which enforces HIPAA. HHS explains what a complaint needs to include and how long you have to file, and organizations are not allowed to retaliate against you for complaining. HIPAA itself does not give individuals a right to sue; whether other laws do is a question for a lawyer.
Read more: Filing a HIPAA complaint
What is HIPPA compliance?
HIPAA compliance means a covered organization is following HIPAA's rules on an ongoing basis. It is a state, not a certificate. No product is “HIPAA compliant” on its own: an EHR or AI scribe can support a practice's compliance, but how the practice sets it up and uses it matters too. And compliance is not a guarantee. Following the rules is a floor for how health information must be handled, not a promise that any particular organization handles it well.
Read more: HIPAA for professionals
Is there an official HIPPA certification?
There is no official HIPAA certification. HHS does not certify organizations, products, or people, and has said it does not recognize private certifications. A training certificate shows a person completed a course. A third-party audit can be useful evidence that a vendor takes security seriously. A “HIPAA Certified” seal has no legal standing, no matter how shiny the badge.
Read more: HHS on certification
What HIPPA form do I need?
There is no single HIPAA form. People usually mean one of a few documents. An authorization lets a doctor or therapist release your records to someone else, such as a lawyer or an insurer. The Notice of Privacy Practices is the document you are handed at a first visit, and the acknowledgment you sign at check-in just confirms you received it. A request for your own records needs no authorization at all. On the business side, a business associate agreement is the contract between a practice and a vendor like its EHR or billing service. HHS publishes model notices and sample agreement language.
Read more: HIPAA for individuals
What is HIPPA training?
HIPAA expects covered organizations to train their staff on the organization's own privacy and security policies and to keep records of it. It does not name a course, a provider, or a number of hours, and HHS does not approve or endorse training vendors. HHS publishes free educational materials of its own.
Read more: HIPAA training and resources
Can my employer ask about my health under HIPPA?
HIPAA generally does not apply to employers acting as employers, your landlord, or a stranger asking nosy questions. Workplace health questions are governed mainly by other laws, such as the ADA and FMLA. HIPAA does cover your doctor or therapist, who generally needs your permission before sharing your records with your employer.
Read more: Employers and health information in the workplace
Can a patient violate HIPPA?
HIPAA regulates covered organizations, not patients. You can share your own health information with anyone you like, and repeating something you overheard in a waiting room or a group therapy session is not a HIPAA violation, though other laws or agreements may apply. A nurse or a therapist can share their own records freely too; the same person opening a coworker's chart out of curiosity is acting as staff, and that is a HIPAA problem.
Read more: Your rights under HIPAA
Is my EHR or AI scribe HIPPA compliant?
For an EHR, AI scribe, telehealth platform, or billing service to be used with patient information, the vendor is generally expected to sign a business associate agreement and protect the data it handles. “Compliant” describes how the tool is set up and used, not a badge on the product, and there is no official certification. The same tool can be used carefully by one practice and carelessly by another.
Read more: Business associates
Does HIPPA require encryption?
The HIPAA Security Rule requires safeguards for electronic health information and names encryption as one of the safeguards organizations must address; HHS explains how that works. In practice nearly every covered organization encrypts, and a stolen laptop from a clinic or a therapy practice is a very different problem if the records on it were encrypted.
Read more: Summary of the Security Rule
Where to read the real thing
Everything above is a short plain-English overview. The official rules and guidance are published by the U.S. Department of Health and Human Services:
- HIPAA at HHS.govThe home page for the law and its rules.
- HIPAA for individualsYour rights, in HHS's own words.
- HIPAA for professionalsSummaries and full text of the Privacy, Security, Breach Notification, and Enforcement Rules.
- Filing a complaintHow to report a possible violation.
Know someone who spells it HIPPA?
Statistically, you know several. Some of them write compliance documentation.