HIPAA

42 U.S.C. § 1320d et seq.; 45 C.F.R. Parts 160, 162, 164

Health Insurance Portability and Accountability Act — Privacy, Security and Breach Notification Rules

In force since April 14, 2003

Who it applies to

  • Covered entities: health plans, health-care clearinghouses, and health-care providers that transmit health information electronically
  • Business associates that create, receive, maintain or transmit protected health information on their behalf

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — grantedRequire inaccurate personal data to be fixed.
  • Deletion / erasure — not granted
  • Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Mixed
Universal opt-out signal
Not required
Risk assessments
Required for higher-risk processing
Data protection officer
Required
Records of processing
Not required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Without unreasonable delay and no later than 60 days after discovery
To the regulator
To HHS within 60 days for breaches affecting 500 or more individuals; annually for smaller breaches
What triggers it
Acquisition, access, use or disclosure of unsecured protected health information not permitted by the Privacy Rule, presumed to be a breach unless a risk assessment shows a low probability of compromise

Penalties

Headline
Tiered civil penalties by culpability, with annual caps per violation type
Private right of action
No — enforcement is by the regulator only
Notes
HIPAA has NO private right of action — a fact that surprises people, and the reason state statutes like California's CMIA matter so much in litigation. Criminal penalties are available through the Department of Justice.

Exemptions

Entities

  • Employers acting as employers
  • Most health and fitness apps sold directly to consumers
  • Life insurers, workers' compensation carriers and many schools

Data

  • De-identified data meeting the safe-harbor or expert-determination standard
  • Employment records held by a covered entity in its role as employer

Amendment history

  1. February 17, 2009

    HITECH Act

    Extended direct liability to business associates and created the federal breach-notification rule.

  2. September 23, 2013

    HIPAA Omnibus Rule

    Implemented HITECH, tightened the breach-risk assessment and strengthened marketing restrictions.

Sources

Timeline

todayHIPAA in forceApril 14, 2003HITECH ActFebruary 17, 2009HIPAA Omnibus RuleSeptember 23, 2013