Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

HIPAA (Health Insurance Portability Act)

Something is properly described as "HIPAA" (rather than another privacy regime) when it derives from the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191) or the federal regulations HHS issued under its Title II Administrative Simplification authority -- principally the Privacy Rule (45 CFR Part 160 and Subparts A/E of Part 164), the Security Rule (45 CFR Part 160 and Subparts A/C of Part 164), and the Breach Notification Rule (45 CFR Part 164, Subpart D, added via the HITECH Act of 2009). These rules apply only to a 'covered entity' (a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a standard transaction) or its business associates, and only to 'protected health information' (PHI) -- individually identifiable health information, as defined at 45 CFR 160.103, held or transmitted by one of those entities. HIPAA is a distinct federal regime from the Common Rule (45 CFR 46), which governs the ethics of human-subjects research (IRB review, informed consent) rather than the privacy/security of health data; the two frequently apply to the same study but are evaluated against different criteria by different offices.

ByCASRAI Editorial Board
· Last updated 17 Jul 2026

Examples

Worked examples

  • Is an instance

    An academic medical center's oncology department wants to use its own patients' electronic health records for a retrospective outcomes study. The hospital is a covered entity, the records are electronic PHI, and research is not a treatment/payment/operations purpose -- so both the Privacy Rule (does this use fit a permitted research pathway?) and the Security Rule (are the systems holding that e-PHI adequately safeguarded?) apply, alongside separate Common Rule/IRB review of the study's ethics.

  • Is an instance

    A hospital's IT department implements encryption, access logging, and role-based access controls for the electronic health record system used partly for research data extraction -- this is Security Rule compliance work, separate from and in addition to whatever Privacy Rule authorization or waiver governs whether a given research use of that data is permitted in the first place.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A university survey research center collects self-reported health-behavior data directly from consenting adult volunteers via an anonymous online questionnaire, with no involvement of any health plan, clearinghouse, or health care provider. This is Common Rule human-subjects research requiring IRB review, but it is outside HIPAA's scope entirely -- there is no covered entity anywhere in the data flow, so neither the Privacy Rule nor the Security Rule applies.

Editorial commentary

HIPAA is the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191), a US federal law whose Title II “Administrative Simplification” provisions gave the Department of Health and Human Services (HHS) authority to issue national standards for electronic health care transactions and for the privacy and security of health information. In research administration, “HIPAA” is almost always shorthand for two of the regulations HHS issued under that authority — the Privacy Rule and the Security Rule — plus the related Breach Notification Rule. These regulations apply only to covered entities (health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with certain standard transactions) and their business associates; a research project that never touches identifiable health data held by one of these entities is not subject to HIPAA at all, whatever else it may be subject to.

What HIPAA actually is: five titles, one relevant part

HIPAA (Pub. L. 104-191, enacted August 21, 1996) has five titles, and only one is doing the regulatory work research administrators actually encounter day to day:

  • Title I — Health Care Access, Portability, and Renewability. The original, headline purpose of the Act: protecting health insurance coverage for workers and their families when they change or lose a job. This is where the name comes from and is not itself a data-privacy or research regulation.
  • Title II — Preventing Health Care Fraud and Abuse; Administrative Simplification. The “Administrative Simplification” subtitle directed HHS to adopt standards for electronic transactions, code sets, unique identifiers, and — the part that matters for research — the privacy and security of individually identifiable health information. Everything a research administrator means by “HIPAA compliance” traces back to regulations HHS issued under this title.
  • Titles III–V address tax treatment of medical savings accounts, group health plan requirements, and other insurance/tax provisions unrelated to research data handling.

The regulations HHS issued under Title II’s authority are collected at 45 CFR Parts 160, 162, and 164. Three of them are the ones a covered entity engaged in research needs to track:

  • Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) — national standards limiting how a covered entity may use or disclose protected health information (PHI), with a compliance date of April 14, 2003 for most covered entities.
  • Security Rule (45 CFR Part 160 and Subparts A and C of Part 164) — administrative, physical, and technical safeguards a covered entity or business associate must implement to protect electronic PHI (e-PHI) specifically, with a compliance date of April 20, 2005 (April 20, 2006 for small health plans).
  • Breach Notification Rule (45 CFR Part 164, Subpart D) — added via the HITECH Act of 2009 and finalized in the 2013 Omnibus Rule; requires a covered entity or business associate to notify affected individuals, HHS, and (for breaches affecting 500 or more individuals) the media, following a breach of unsecured PHI, generally within 60 days of discovery.

The Enforcement Rule (45 CFR Part 160, Subparts C–E) sets the investigation and civil-penalty structure behind all three, administered by the HHS Office for Civil Rights (OCR).

Protected health information (PHI): the thing all three rules protect

Per the definitions at 45 CFR 160.103, individually identifiable health information is health information (including demographic data) that is created or received by a covered entity, relates to an individual’s past, present, or future physical or mental health, health care, or payment for health care, and either identifies the individual or offers a reasonable basis to believe it could be used to do so. Protected health information (PHI) is that same information when it is held or transmitted by a covered entity or its business associate — the qualifying term exists specifically to mark the subset of identifiable health information the Privacy and Security Rules actually reach, as distinct from the same kind of information sitting anywhere else. Once information meets the Safe Harbor or Expert Determination de-identification standard at 45 CFR 164.514, it is no longer PHI and falls outside HIPAA’s scope, regardless of who holds it.

Two consequences follow directly for a research context:

  • PHI is defined by who holds it and why, not just by content. The same lab-value or diagnosis is PHI in a hospital’s EHR and not PHI in a dataset a non-covered-entity research organization collected directly from consenting participants outside any covered entity’s systems.
  • Research is not one of the purposes (treatment, payment, or health care operations) for which the Privacy Rule lets a covered entity use or disclose PHI by default. Any research use of PHI held by a covered entity has to be routed through one of the Rule’s specific research pathways — authorization, an IRB/Privacy Board waiver, a limited data set, de-identification, or a narrow preparatory-review/decedent exception.

Privacy Rule vs. Security Rule: two different questions about the same data

Privacy Rule Security Rule
Scope PHI in any form — paper, oral, electronic Electronic PHI (e-PHI) only
Core question May this PHI be used or disclosed, and to whom? Is this e-PHI adequately safeguarded from unauthorized access, alteration, or loss?
Mechanism Permitted-use categories, individual rights (access, amendment, accounting of disclosures), authorization requirements Required and addressable administrative, physical, and technical safeguards (risk analysis, access controls, encryption where reasonable and appropriate, audit controls)
Research relevance Governs whether a study may use/disclose PHI at all (authorization, waiver, limited data set, de-identification) Governs how a covered entity or business associate must protect e-PHI it holds for research once use is otherwise permitted — e.g., a clinical data repository’s access controls and encryption

A study can be fully compliant with one and out of compliance with the other — a properly authorized data transfer (Privacy Rule) sent over an unencrypted channel with no access logging (Security Rule failure) is a real, common failure pattern, not a hypothetical.

How HIPAA differs from — and combines with — the Common Rule and IRB oversight

HIPAA and the Common Rule are frequently conflated because they often apply to the same study at the same institution, but they are separate federal regulatory regimes, administered under different legal authority, evaluated against different criteria:

  • The Common Rule (45 CFR 46, plus the parallel FDA human-subjects regulations at 21 CFR 50/56 for FDA-regulated research) governs the ethics of involving human beings in research: risk/benefit review by an IRB and informed consent to participate.
  • HIPAA’s Privacy and Security Rules govern the privacy and security of health data held by a covered entity or business associate — a question that exists independent of whether the study is human-subjects research at all, and independent of whether the individual has consented to participate in anything.

A hospital-based study is typically subject to both at once, and institutions commonly combine the paperwork into a single “Informed Consent and HIPAA Authorization” form for participant convenience — but the two legal analyses underneath that one document remain distinct and can diverge (a study can obtain a Common Rule waiver of consent while still needing a separate HIPAA waiver of authorization, since the waiver criteria at 45 CFR 46.116(f) and 45 CFR 164.512(i) are not identical). Conversely, research that involves no covered entity and no PHI — an anonymous survey of student volunteers, for example — can be Common Rule human-subjects research requiring IRB review while never triggering HIPAA at all.

For the detailed mechanics of how a study actually routes PHI through the Privacy Rule’s permitted research pathways — authorization, IRB/Privacy Board waiver, limited data sets, the two de-identification methods, and the preparatory-review/decedent exceptions, with worked examples — see CASRAI’s dedicated entry on HIPAA in Clinical Research. This page defines HIPAA itself; that one covers how it operates specifically inside a clinical trial or other human-subjects study.

Worked examples

Covered entity, PHI in play. An academic medical center’s oncology department wants to use its own patients’ electronic health records for a retrospective outcomes study. The hospital is a covered entity, the records are e-PHI, and the study is not treatment/payment/operations — so both the Privacy Rule (does this use fit a permitted research pathway?) and the Security Rule (are the systems holding that e-PHI adequately safeguarded?) apply, alongside separate Common Rule/IRB review of the study’s ethics.

No covered entity, HIPAA doesn’t engage. A university survey research center collects self-reported health-behavior data directly from consenting adult volunteers via an anonymous online questionnaire, with no involvement of any health plan, clearinghouse, or health care provider. This is Common Rule human-subjects research requiring IRB review, but it is outside HIPAA’s scope entirely — there is no covered entity anywhere in the data flow.

Frequently asked questions

Is HIPAA the same thing as the Privacy Rule?

No. HIPAA is the 1996 statute; the Privacy Rule is one of several regulations HHS issued under HIPAA’s Title II authority. In everyday conversation “HIPAA” is often used loosely to mean the Privacy Rule specifically, but the Act also produced the Security Rule, the Breach Notification Rule, and the Enforcement Rule, each governing something different.

Does HIPAA apply to all health-related research data?

No. It applies only to PHI held by a covered entity or its business associate. Health-related data collected by an entity that is not a covered entity, or data that has been properly de-identified, is outside HIPAA’s scope — though it may still be subject to the Common Rule, an institution’s own data-governance policy, or other privacy law (state privacy statutes, GDPR for EU participants, etc.).

Who enforces HIPAA?

The HHS Office for Civil Rights (OCR) investigates complaints and can impose civil monetary penalties for Privacy Rule, Security Rule, and Breach Notification Rule violations under the Enforcement Rule at 45 CFR Part 160, Subparts C–E.

Does getting a signed HIPAA authorization also satisfy IRB informed-consent requirements?

No. They are legally distinct requirements evaluated against different regulatory criteria, even when combined into one participant-facing form. See HIPAA in Clinical Research for the specific research-authorization pathways and how they interact with Common Rule consent.

How does HIPAA relate to FERPA?

HIPAA and FERPA (the Family Educational Rights and Privacy Act) are separate federal privacy statutes that generally do not both apply to the same records at the same time — education records maintained by a school under FERPA are typically excluded from HIPAA’s definition of PHI, even at a covered entity like a university-affiliated clinic serving students.

Related CASRAI resources

References

  • Public Law 104-191, Health Insurance Portability and Accountability Act of 1996
  • 45 CFR Parts 160 and 164 — HIPAA Administrative Simplification Regulations
  • HHS Office for Civil Rights, “Summary of the HIPAA Privacy Rule” and “Summary of the HIPAA Security Rule”
  • 45 CFR 160.103 — Definitions (individually identifiable health information, protected health information)
  • 45 CFR Part 164, Subpart D — Breach Notification Rule
  • HHS, “Covered Entities and Business Associates” guidance

Also known as

Health Insurance Portability and Accountability Act · HIPAA of 1996 · Public Law 104-191

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="HIPAA (Health Insurance Portability Act)"
      vocab-term-identifier="https://casrai.org/dictionary/term/hipaa" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/hipaa",
  "name": "HIPAA (Health Insurance Portability Act)",
  "identifier": "https://casrai.org/dictionary/term/hipaa",
  "description": "Something is properly described as \"HIPAA\" (rather than another privacy regime) when it derives from the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191) or the federal regulations HHS issued under its Title II Administrative Simplification authority -- principally the Privacy Rule (45 CFR Part 160 and Subparts A/E of Part 164), the Security Rule (45 CFR Part 160 and Subparts A/C of Part 164), and the Breach Notification Rule (45 CFR Part 164, Subpart D, added via the HITECH Act of 2009). These rules apply only to a 'covered entity' (a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a standard transaction) or its business associates, and only to 'protected health information' (PHI) -- individually identifiable health information, as defined at 45 CFR 160.103, held or transmitted by one of those entities. HIPAA is a distinct federal regime from the Common Rule (45 CFR 46), which governs the ethics of human-subjects research (IRB review, informed consent) rather than the privacy/security of health data; the two frequently apply to the same study but are evaluated against different criteria by different offices.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/hipaa",
  "sameAs": [
    "Health Insurance Portability and Accountability Act",
    "HIPAA of 1996",
    "Public Law 104-191"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-17T05:31:59",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →