HIPAA
42 U.S.C. § 1320d et seq.; 45 C.F.R. Parts 160, 162, 164Health Insurance Portability and Accountability Act — Privacy, Security and Breach Notification Rules
In force since April 14, 2003
Who it applies to
- Covered entities: health plans, health-care clearinghouses, and health-care providers that transmit health information electronically
- Business associates that create, receive, maintain or transmit protected health information on their behalf
Consumer rights
- Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
- Correction — grantedRequire inaccurate personal data to be fixed.
- Deletion / erasure — not granted
- Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — not granted
Obligations
- Consent model
- Mixed
- Universal opt-out signal
- Not required
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Required
- Records of processing
- Not required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Without unreasonable delay and no later than 60 days after discovery
- To the regulator
- To HHS within 60 days for breaches affecting 500 or more individuals; annually for smaller breaches
- What triggers it
- Acquisition, access, use or disclosure of unsecured protected health information not permitted by the Privacy Rule, presumed to be a breach unless a risk assessment shows a low probability of compromise
Penalties
- Headline
- Tiered civil penalties by culpability, with annual caps per violation type
- Private right of action
- No — enforcement is by the regulator only
- Notes
- HIPAA has NO private right of action — a fact that surprises people, and the reason state statutes like California's CMIA matter so much in litigation. Criminal penalties are available through the Department of Justice.
Exemptions
Entities
- Employers acting as employers
- Most health and fitness apps sold directly to consumers
- Life insurers, workers' compensation carriers and many schools
Data
- De-identified data meeting the safe-harbor or expert-determination standard
- Employment records held by a covered entity in its role as employer
Amendment history
February 17, 2009
HITECH Act
Extended direct liability to business associates and created the federal breach-notification rule.
September 23, 2013
HIPAA Omnibus Rule
Implemented HITECH, tightened the breach-risk assessment and strengthened marketing restrictions.
Sources
- PrimaryRegulation45 C.F.R. Part 164 — Security and Privacy
- PrimaryBreach registryHHS OCR — breach portal (500+ individuals)
- OfficialRegulatorHHS — HIPAA for professionals