Auditen
Home / Frameworks / HIPAA

HIPAA (Health Insurance Portability and Accountability Act)

The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law that establishes national standards for the protection of sensitive patient health information. It exists to safeguard individual privacy and secure electronic healthcare data while ensuring that critical information flows efficiently between providers, insurers, and patients.

Who it applies to

  • Healthcare providers who transmit health information electronically, such as doctors, clinics, and pharmacies.
  • Health plans, including health insurance companies and government programs like Medicare and Medicaid.
  • Healthcare clearinghouses that process nonstandard health information into standard formats.
  • Business associates, such as IT vendors or billing services, that handle protected health information (PHI) on behalf of a covered entity.

How it works

HIPAA is organized into several primary rules. The Privacy Rule sets standards for when PHI can be used or disclosed. The Security Rule outlines the administrative, physical, and technical safeguards required to protect electronic PHI (ePHI). Additionally, the Breach Notification Rule requires entities to notify affected individuals and the government following a data breach.

Compliance is managed through self-assessment rather than an official government certification. There is no "HIPAA Certificate" issued by the US Department of Health and Human Services (HHS). Instead, organizations implement safeguards based on their specific risk profile and document these efforts in written policies and procedures.

Verification typically occurs via internal or third-party audits to ensure that controls are functioning as intended. If a breach occurs or a complaint is filed, the Office for Civil Rights (OCR) may conduct an investigation and issue fines if non-compliance is discovered.

Getting started

  1. Identify all locations where protected health information is stored, transmitted, or accessed within your organization.
  2. Conduct a comprehensive risk analysis to identify vulnerabilities in the confidentiality, integrity, and availability of ePHI.
  3. Develop and document written policies and procedures that align with the Privacy and Security Rules.
  4. Execute Business Associate Agreements (BAAs) with all third-party vendors who have access to PHI.
  5. Implement technical safeguards, such as encryption and access controls, based on the findings of your risk analysis

Controls & requirements