Glossary
Health Insurance Portability and Accountability Act (HIPAA)
The U.S. law that sets privacy and security rules for protected health information handled by healthcare providers and insurers.
Also called: HIPAA
HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law that sets privacy and security requirements for "protected health information" (PHI), health records, diagnoses, treatment and payment details, tied to an identifiable individual, when handled by covered entities such as healthcare providers and insurers, and by their business associates, including many analytics and software vendors that process health data on their behalf.
HIPAA's Privacy Rule governs who may access and share PHI and for what purposes, while its Security Rule sets specific technical and administrative safeguards, such as role-based access control and audit logging, for electronic health information. HIPAA also defines a specific method, "de-identification," under which PHI can be stripped of eighteen defined identifier types, or certified by a statistician, and then used more freely; this is a narrower, more rule-based process than general anonymization, and stricter than typical data masking used outside healthcare.
For analytics work, HIPAA determines whether a dataset can be used at all outside direct patient care, and under what safeguards; de-identified datasets are common in health analytics and research specifically to fall outside HIPAA's direct scope. It differs from broader regimes like General Data Protection Regulation by being sector-specific to health data in the U.S. rather than general-purpose, though both treat health-related personally identifiable information as especially sensitive. This is general background only, not legal or compliance advice; specific HIPAA obligations depend on an organization's role and the data involved.
Last reviewed September 22, 2026