Back to Frameworks
Privacy

HIPAA

The Health Insurance Portability and Accountability Act (1996) protects the privacy and security of health information in the United States.

Its Privacy Rule governs how Protected Health Information (PHI) can be used and disclosed, while its Security Rule sets administrative, physical, and technical safeguards for electronic PHI. It applies directly to "covered entities" (providers, insurers, clearinghouses) and to their "business associates" — vendors who handle PHI on their behalf — via signed Business Associate Agreements.

See how LumiGRC handles HIPAA

Get a Demo
2

Core rules: Privacy & Security

0%
Typical certification profile
Audit Rigor53%
Time to Certify46%
Surveillance Burden63%
Issued & Enforced By

HHS Office for Civil Rights

45 CFR Parts 160 & 164

Key Points

  • Privacy Rule (use/disclosure) and Security Rule (safeguards)
  • Applies to covered entities and their business associates
  • No formal certification — compliance is demonstrated, not certified
  • Enforced by the HHS Office for Civil Rights