Skip to content
PrivaBaseBeta
FeaturesPricingCompareGuidesBlogGlossaryTools
Log InStart Free
← Back to Glossary

HIPAA (Health Insurance Portability and Accountability Act)

US federal law that establishes standards for protecting sensitive patient health information (PHI).

HIPAA is a US federal law enacted in 1996 that creates national standards for the protection of health information. It consists of five rules: the Privacy Rule (governing use and disclosure of PHI), the Security Rule (requiring safeguards for electronic PHI), the Breach Notification Rule (requiring notification of breaches), the Enforcement Rule (establishing penalties), and the Omnibus Rule (extending requirements to business associates). HIPAA applies to covered entities (healthcare providers, health plans, clearinghouses) and business associates (any organization handling PHI on behalf of a covered entity). Violations can result in fines from $100 to $50,000 per violation, up to $1.5 million per year, plus criminal penalties including imprisonment.

Related Terms

PHI (Protected Health Information)PII (Personally Identifiable Information)

Related Guides

Complete HIPAA Compliance Guide (2026)

The complete guide to HIPAA compliance in 2026. Learn about covered entities, PHI, the Privacy Rule, Security Rule, breach notification, and BAAs.

Ready to Simplify Your Compliance?

Start automating your privacy compliance today. No credit card required.

Start Free
PrivaBaseBeta

Automated privacy compliance for modern teams.

Product

  • Features
  • Pricing
  • Privacy Policy Generator
  • Compare

Resources

  • GDPR Guide
  • HIPAA Guide
  • CCPA Guide
  • UK GDPR Guide
  • Privacy Glossary
  • Blog

Legal

  • Terms of Service
  • Privacy Policy
  • Your Privacy Choices
  • Do Not Sell My Personal Information
  • Cookie Policy
  • DPA
  • Subprocessors

Company

  • Security
  • Data Requests
  • Accessibility
  • Contact
  • API Docs
  • Status

Your Privacy Rights

You have the right to know what personal data we collect, request its deletion, opt out of data sales or sharing, and exercise these rights without discrimination. To submit a privacy request, email privacy@privabase.com or visit our Data Request page.

Data Protection Officer

For GDPR inquiries or data protection concerns, contact our DPO at dpo@privabase.com. Spoon Seller LLC · 110 Coliseum Crossing #5392, Hampton, VA 23666

© 2026 Spoon Seller LLC. All rights reserved.
TermsPrivacyDo Not Sell My InfoData Requests