Health Insurance Portability and Accountability Act Administrative Simplification: Privacy, Security, and Breach Notification Rules
HIPAAThe Privacy Rule limits how covered entities and business associates use and disclose protected health information and gives individuals rights of access, amendment, and accounting. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice of breaches of unsecured PHI. A 2024 reproductive health amendment was vacated nationwide in June 2025 except most Notice of Privacy Practices changes, which had a February 16, 2026 compliance date.
Jurisdiction
United States
Jurisdiction Type
federal
Country
United States
Effective Date
4/14/2003
Enforcing Authority
HHS Office for Civil Rights; state attorneys general (42 U.S.C. 1320d-5(d)); DOJ for criminal violations
Maximum Fine
Up to $1.5M per violation category per year; criminal penalties up to $250K and 10 years
Fines Under This Regulation
0
Total Fine Amount (USD)
--
Privacy Topics
Key Articles
| Article | Description |
|---|---|
| Privacy Rule | Use and disclosure of PHI |
| Security Rule | Administrative, physical, technical safeguards |
| Enforcement Rule | Compliance and penalties |
| Breach Notification Rule | Notification requirements for breaches |