The Health Insurance Portability and Accountability Act, known as HIPAA, is the federal law that controls who can see your medical information, how it must be protected, and what happens when someone mishandles it. This is HIPAA explained in the terms most people actually need: the law applies to healthcare providers, health plans, healthcare clearinghouses, and the outside companies that work with them. It gives you enforceable rights over your records and imposes escalating penalties, with civil fines reaching over $2 million per violation category in 2026.
Who HIPAA Applies To
HIPAA reaches three types of organizations the law calls “covered entities.” The first is healthcare providers who transmit health information electronically: doctors, hospitals, clinics, nursing homes, and pharmacies. The second is health plans, including health insurance companies, employer-sponsored group health plans, HMOs, and government programs like Medicare and Medicaid. The third is healthcare clearinghouses, which convert nonstandard health data into standardized electronic formats.
The law also reaches any company that handles protected health information on a covered entity’s behalf. These “business associates” include billing companies, IT contractors, cloud storage providers, law firms, and accounting firms. Each must sign a formal agreement committing to HIPAA’s privacy and security requirements. If a billing company mishandles patient records, both the billing company and the covered entity that hired it can face enforcement action.
What Information Is Protected
HIPAA protects a category of data called protected health information, or PHI. Under federal regulation, PHI is individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits in any form: electronic, paper, or oral.1GovInfo. 45 CFR 160.103 Definitions Information qualifies as PHI when it relates to a person’s past, present, or future health condition, the healthcare services they received, or payment for those services, and when it either identifies the person or could reasonably be used to identify them.
Eighteen specific identifiers can link health data to a person: names, addresses more specific than a state, dates tied to the individual (birth, admission, discharge), phone numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric data like fingerprints, full-face photographs, and any other unique identifying code.
Several categories fall outside HIPAA. Employment records a covered entity holds in its role as an employer are not PHI, even when they contain health details.2U.S. Department of Health and Human Services. Employers and Health Information in the Workplace Education records covered by FERPA are excluded, as are records for individuals deceased more than 50 years.1GovInfo. 45 CFR 160.103 Definitions Data stripped of all eighteen identifiers becomes “de-identified” and falls outside HIPAA’s protections.
The Privacy Rule
The Privacy Rule is the core of HIPAA’s patient protections. Located at 45 CFR Part 160 and Subparts A and E of Part 164, it sets national standards for how covered entities may use and disclose PHI in every form.3U.S. Department of Health and Human Services. The HIPAA Privacy Rule Its default position is simple: a covered entity cannot use or share your health information without your written authorization, unless a specific exception applies.
When a covered entity does use or disclose PHI, it must limit the information to the minimum necessary to accomplish the purpose. A hospital billing department processing an insurance claim does not need your full psychiatric history. This standard requires covered entities to build policies restricting which employees can access what information based on job responsibilities.4eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information General Rules It does not apply to disclosures for treatment, disclosures you authorize, or disclosures required by law.
Every covered entity that directly treats patients must give you a Notice of Privacy Practices at your first visit. Written in plain language, this notice explains how the entity may use your information, your rights, and its legal duties regarding your data.5eCFR. 45 CFR 164.520 – Notice of Privacy Practices for Protected Health Information Providers with a physical location must post the notice where patients can see it. Health plans distribute it at enrollment and remind members at least every three years that it is available.
When Your Information Can Be Shared Without Consent
HIPAA is not an absolute lock on your records. The law carves out situations where covered entities may share PHI without asking you first.
The broadest exception covers treatment, payment, and routine healthcare operations.6U.S. Department of Health and Human Services. Uses and Disclosures for Treatment, Payment, and Health Care Operations Your primary care doctor can share records with a specialist for a referral. Your hospital can send billing information to your insurer. Covered entities can use PHI internally for quality improvement, training, and compliance. Without this exception, every routine interaction would require a signed form.
Covered entities may disclose PHI to law enforcement without your consent in limited circumstances: when required by law (such as mandatory reporting of gunshot wounds), in response to a court order or grand jury subpoena, or to help identify or locate a suspect or missing person. When disclosing information to locate someone, the entity may only share basic identifiers like name, address, date of birth, and physical description, not DNA data or dental records.
In judicial proceedings without a court order, a covered entity can respond to a subpoena or discovery request only after receiving satisfactory assurance that either you were notified and given a chance to object, or the requesting party obtained a qualified protective order limiting how the information can be used.
Public health disclosures are also permitted, including reports to public health authorities tracking disease outbreaks, reports of adverse drug reactions, and notifications about exposure to communicable diseases.
Reproductive Health Care
A final rule that took effect in June 2024, with a compliance deadline of December 2024 for most provisions and February 16, 2026 for updated privacy notices, added protections for reproductive health information.7Federal Register. HIPAA Privacy Rule To Support Reproductive Health Care Privacy Covered entities and business associates are prohibited from using or disclosing PHI to investigate or impose liability on anyone for seeking, obtaining, providing, or facilitating lawful reproductive health care. The rule defines reproductive health care broadly to include contraception, fertility treatments, and pregnancy-related care.
The rule presumes reproductive health care was lawful unless the covered entity has strong evidence to the contrary. When someone requests PHI for law enforcement, judicial proceedings, or health oversight that could relate to reproductive health care, the requesting party must sign a written attestation confirming the information is not being sought for a prohibited purpose.7Federal Register. HIPAA Privacy Rule To Support Reproductive Health Care Privacy
The Security Rule
While the Privacy Rule covers all forms of PHI, the Security Rule focuses specifically on electronic PHI (ePHI). Located at 45 CFR Part 160 and Subparts A and C of Part 164, it requires covered entities and business associates to implement safeguards protecting the confidentiality, integrity, and availability of electronic health data.8U.S. Department of Health and Human Services. The Security Rule
The rule groups safeguards into three categories. Administrative safeguards cover internal policies, risk assessments, workforce training, and designated security personnel. Physical safeguards control access to facilities and equipment, including locked server rooms and procedures for disposing of hardware. Technical safeguards are the technology-based protections: encryption, access controls, audit logs, and automatic session timeouts.
A proposed rule published in early 2025 would tighten these requirements, eliminating the current “addressable” category and requiring encryption for all ePHI at rest and in transit, annual compliance audits, and vulnerability scanning at least every six months.9U.S. Department of Health and Human Services. HIPAA Security Rule Notice of Proposed Rulemaking To Strengthen Cybersecurity The proposal has not been finalized.
Your Rights Under HIPAA
HIPAA gives you a set of enforceable rights over your information that apply against every covered entity holding your records.
Access Your Records
You can request a copy of your medical records from any covered entity, and the entity must respond within 30 calendar days. If records are stored electronically and you want an electronic copy, the entity must provide one. A single 30-day extension is allowed if the entity gives you a written explanation and a response date.10U.S. Department of Health and Human Services. How Timely Must a Covered Entity Be in Responding to Individuals Requests for Access to Their PHI
The entity may charge a reasonable, cost-based fee covering only labor for copying, supplies, and postage if you request mailing.11eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information The fee cannot include costs for searching or retrieving the records.
Request Amendments
If you believe your records contain an error, you can ask the covered entity to amend them. The entity has 60 days to act, with one possible 30-day extension.12eCFR. 45 CFR 164.526 – Amendment of Protected Health Information An entity can deny the request in four situations: it did not create the record, the record is not part of the designated record set, the record would not be available for your inspection, or the existing information is accurate and complete. If denied, you can submit a written statement of disagreement that becomes part of your permanent record.
An Accounting of Disclosures
You can request a list of every time a covered entity shared your PHI outside of treatment, payment, and healthcare operations during the previous six years. This helps you see whether your data was disclosed for law enforcement, research, or other purposes you may not have known about.
Confidential Communications
You can ask a healthcare provider to communicate with you through a specific channel or at a specific location. If you do not want appointment reminders sent to your home phone, you can ask the provider to use your cell phone instead. Providers must accommodate any reasonable request and cannot require you to explain why.13GovInfo. 45 CFR 164.522 – Rights To Request Privacy Protection for Protected Health Information
Restrict Disclosures
You can ask a covered entity to limit how it uses or shares your information for treatment, payment, or healthcare operations. Entities generally do not have to agree, with one important exception: if you pay for a service entirely out of pocket and ask the provider not to share information about that service with your health plan, the provider must comply.
HIPAA Does Not Apply to Your Employer
One of the most common misconceptions is that HIPAA stops your employer from asking about your health or sharing medical information. It does not. HIPAA restricts covered entities and business associates, not employers acting as employers. Your employer can ask about your health for purposes like administering sick leave, processing workers’ compensation claims, or managing wellness programs.2U.S. Department of Health and Human Services. Employers and Health Information in the Workplace
The distinction is about who holds the information and in what role. If you work for a hospital, your employment records are not PHI, even though your employer is a covered entity. Your medical records at that same hospital, maintained as part of your treatment as a patient, are fully protected. What HIPAA does prevent is your healthcare provider from handing your medical records to your employer without your authorization. Your boss can ask you about a medical absence, but your doctor cannot answer that question without your written consent.2U.S. Department of Health and Human Services. Employers and Health Information in the Workplace Other laws like the Americans with Disabilities Act may separately restrict what an employer can ask.
How Breaches Get Reported
When unsecured PHI is compromised, the Breach Notification Rule at 45 CFR §§ 164.400–414 triggers mandatory reporting.14U.S. Department of Health and Human Services. Breach Notification Rule “Unsecured” means the data was not encrypted or destroyed using methods specified by HHS guidance. If a laptop with encrypted patient records is stolen, no breach notification is required. If the laptop held unencrypted records, notification kicks in.
A covered entity must notify each affected individual within 60 calendar days of discovering the breach. The notice must describe what happened, what types of information were involved, steps you should take to protect yourself, and what the entity is doing to investigate and prevent future breaches.15eCFR. 45 CFR Part 164 Subpart D – Notification in the Case of Breach of Unsecured Protected Health Information
When a breach affects 500 or more residents of a state or jurisdiction, the entity must also notify prominent local media and report to the HHS Secretary within the same 60-day window.16eCFR. 45 CFR 164.406 – Notification to the Media The HHS Office for Civil Rights posts these large-scale breaches on a public portal where anyone can view the entity’s name, breach type, and number of individuals affected.17U.S. Department of Health & Human Services. Breach Portal Breaches affecting fewer than 500 individuals can be reported in an annual submission to HHS.
How to File a HIPAA Complaint
If you believe a covered entity or business associate violated your privacy rights, file a complaint with the Office for Civil Rights at HHS. Complaints must be filed within 180 days of when you discovered the violation, though OCR may grant an extension for good cause.18U.S. Department of Health and Human Services. How to File a Health Information Privacy or Security Complaint You can submit online through the OCR Complaint Portal, by mail, by fax, or by email.
Your complaint should describe the potential violation, identify the covered entity or business associate, and include the date and location. The portal accepts anonymous submissions, but OCR will not investigate a complaint that does not include a name and contact information.19U.S. Department of Health and Human Services. Filing a Health Information Privacy Complaint After receiving a complaint, OCR reviews it for jurisdiction and may resolve the matter through technical assistance, a formal investigation, or referral to another agency.
Penalties for Violations
HIPAA violations carry both civil and criminal consequences, and the penalties punish willful disregard far more severely than honest mistakes.
Civil Money Penalties
The Office for Civil Rights enforces civil violations through a four-tiered structure, with amounts adjusted annually for inflation.20U.S. Department of Health and Human Services. HIPAA Compliance and Enforcement As of 2026, the penalty ranges per violation are:
- No knowledge of the violation: $145 to $73,011
- Reasonable cause, not willful neglect: $1,461 to $73,011
- Willful neglect, corrected within 30 days: $14,602 to $73,011
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294
The calendar-year cap for all violations of the same provision is $2,190,294. That cap resets each year and applies per provision violated, so an entity that violates multiple HIPAA requirements in the same year faces separate caps for each one.
Criminal Penalties
The Department of Justice handles criminal HIPAA violations, which require proof that the person knowingly obtained or disclosed PHI in violation of the law. Criminal penalties escalate across three tiers:21GovInfo. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
- Knowing violation: up to $50,000 and one year in prison
- Violation committed under false pretenses: up to $100,000 and five years in prison
- Violation with intent to sell, transfer, or use information for commercial advantage, personal gain, or malicious harm: up to $250,000 and ten years in prison
A hospital employee who accesses a celebrity’s records out of curiosity faces a different level of exposure than one who sells patient data to a marketing firm. Both are crimes, but the statute calibrates punishment based on motive.