Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules

HIPAA
active

The Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.

Jurisdiction

United States

Jurisdiction Type

federal

Country

United States

Effective Date

4/14/2003

Enforcing Authority

HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations

Maximum Fine

Up to $1.5M per violation category per year; criminal penalties up to $250K and 10 years

Fines Under This Regulation

0

Total Fine Amount (USD)

--

Privacy Topics

health_dataphibreach_notificationbusiness_associatesminimum_necessary

Key Articles

ArticleDescription
Privacy RuleUse and disclosure of PHI
Security RuleAdministrative, physical, technical safeguards
Enforcement RuleCompliance and penalties
Breach Notification RuleNotification requirements for breaches