Healthcare Privacy Law
Health information is regulated by who holds it, not by what it is. This guide describes the federal rules that bind healthcare providers, health plans and their vendors, the rights they give patients, how breaches are reported and penalised, and where state law adds obligations HIPAA does not.
What HIPAA Covers, and Who It Binds
HIPAA does not regulate health information as a category. It regulates a defined set of actors and the information they hold. Those actors are covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with a covered transaction. It also reaches business associates, meaning the vendors that create, receive, maintain or transmit protected health information on a covered entity’s behalf. Since the HITECH Act amendments those vendors are directly liable under the Security Rule and parts of the Privacy Rule, rather than only through the terms of their contracts.
Protected health information is individually identifiable health information held or transmitted in any form. It covers the obvious records, diagnoses, test results, prescriptions and billing, and it covers ordinary identifiers such as a name, address or phone number once they sit alongside health data. The Privacy Rule in 45 CFR Part 164 Subpart E governs use and disclosure. The Security Rule in Subpart C governs electronic protected health information specifically, through administrative, physical and technical safeguards.
The boundary matters more than it first appears. A fitness tracker, a symptom checker or a mental health app generally falls outside HIPAA entirely, because no covered entity stands behind it. The information is identical in sensitivity and different in legal status. That gap is where the FTC’s Health Breach Notification Rule at 16 CFR Part 318 operates instead, requiring notice from vendors of personal health records that HIPAA never reached.
The Right of Access, and Where It Breaks Down
The Privacy Rule gives individuals a right of access to their own designated record set at 45 CFR 164.524. A covered entity generally has 30 days to respond, must provide the records in the form and format requested where they are readily producible, and may charge only a reasonable cost-based fee. Electronic records requested electronically must be provided electronically.
This provision generates more enforcement activity than its profile suggests. The Office for Civil Rights has run a dedicated Right of Access initiative, and the resulting resolution agreements describe a consistent set of failures: no response within the window, records withheld pending payment of fees above the permitted basis, delivery in paper when an electronic copy was requested, and the request routed to a records vendor that never completed it. The obligation sits with the covered entity regardless of who it delegates the work to.
Breach Notification and What Triggers It
The Breach Notification Rule treats an impermissible use or disclosure of unsecured protected health information as a presumed breach. The presumption can be rebutted, but only through a documented risk assessment addressing the nature and extent of the information, who received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Information rendered unusable through encryption meeting the specified standard is not unsecured, which is why encryption status often decides whether an incident is reportable at all.
Where notice is required, individuals must be notified without unreasonable delay and no later than 60 days after discovery. A breach affecting 500 or more residents of a state or jurisdiction additionally requires notice to prominent media serving that area and contemporaneous notice to HHS. Smaller breaches are logged and submitted to HHS annually. Every reported breach at the 500-person threshold is published on the HHS breach portal, which is a public record of who has reported what.
Enforcement and Penalty Structure
The Office for Civil Rights enforces HIPAA, with concurrent authority for state attorneys general. Civil monetary penalties are tiered by culpability, and the tiers are annually adjusted for inflation, so any fixed figure ages quickly.
| Tier | Culpability | Character |
|---|---|---|
| 1 | Did not know, and would not have known through reasonable diligence | Lowest range |
| 2 | Reasonable cause, not willful neglect | Middle range |
| 3 | Willful neglect, corrected within 30 days | Higher range |
| 4 | Willful neglect, not corrected | Highest range |
Criminal liability sits with the Department of Justice under 42 U.S.C. 1320d-6 and escalates from knowing disclosure, through offences committed under false pretences, to disclosure with intent to sell or use the information for commercial advantage or malicious harm. Most matters, however, resolve through a resolution agreement and a corrective action plan rather than a penalty, and the corrective action plan is usually the more demanding half: multi-year reporting obligations, a fresh risk analysis, and revised policies subject to OCR approval.
Risk Analysis: the Most Cited Failure
The administrative safeguards standard requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of all electronic protected health information. It is a required implementation specification, not an addressable one, which means it cannot be satisfied by documenting a reasoned alternative.
Enforcement documents return to the same gaps repeatedly. Analyses that covered only part of an environment, omitting portable media, systems inherited through acquisition, vendor-managed environments or applications sitting outside the core electronic health record. Analyses performed once and never revisited after a material change. Assessments asserted but not evidenced, where no contemporaneous record of scope, findings or resulting decisions could be produced. The documentation standard at 45 CFR 164.316 requires records to be retained for six years and reviewed periodically, so an undocumented analysis is difficult to distinguish from one that never happened.
Telehealth, Apps and the Boundary Problem
Remote care moved a large volume of clinical interaction onto general-purpose consumer platforms. Where a covered entity uses such a platform to deliver care, the platform is typically a business associate, and the ordinary rules about agreements, safeguards and breach reporting apply to it. The enforcement discretion exercised during the COVID-19 public health emergency was time-limited and has ended.
The harder cases sit at the edge. Tracking technologies embedded in patient portals and appointment pages can transmit information to advertising platforms, and where that information relates to an individual’s health condition or care, its disclosure is regulated even though it was collected through an ordinary web page. Consumer apps operating with no covered entity behind them fall to the FTC instead, under the Health Breach Notification Rule and Section 5 of the FTC Act.
State Law Sits on Top, Not Underneath
HIPAA sets a floor. It does not preempt state law that is more stringent, so state statutes routinely add obligations rather than replace them. California’s Confidentiality of Medical Information Act reaches providers and, through later amendments, certain businesses handling medical information outside the traditional care setting. Illinois protects mental health and developmental disability records under a separate confidentiality act with its own consent mechanics. Texas defines covered entity far more broadly than the federal rule, sweeping in businesses that come into possession of health information in the ordinary course.
Newer state health-data statutes go further still. Washington’s My Health My Data Act regulates consumer health data held by entities HIPAA never reached, and carries a private right of action, which is a structural difference from HIPAA rather than a difference of degree.
What Cannot Be Brought Under HIPAA
HIPAA contains no private right of action. An individual whose information was mishandled cannot sue under the statute itself. Complaints go to the Office for Civil Rights, which decides whether to investigate, and to state attorneys general. Litigation over medical privacy therefore proceeds under other theories: negligence, breach of confidentiality or fiduciary duty, state medical privacy statutes that do provide a private right of action, state consumer protection law, and increasingly wiretapping and session-recording statutes where tracking technology is involved.
Frequently Asked Questions
Does HIPAA cover my fitness tracker or health app?
Usually not. HIPAA reaches covered entities (health plans, healthcare clearinghouses, and providers who transmit health information electronically in connection with a covered transaction) and their business associates. A direct-to-consumer app that no provider has contracted with generally sits outside it. The FTC’s Health Breach Notification Rule at 16 CFR Part 318 reaches some of those apps instead.
How long does a covered entity have to tell me about a breach?
The Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 days after discovery. A breach affecting 500 or more residents of a state also requires notice to HHS and to prominent media serving that area. Smaller breaches are logged and reported to HHS annually.
Can I sue a provider under HIPAA?
HIPAA contains no private right of action. Enforcement runs through HHS Office for Civil Rights and state attorneys general. Individuals who sue generally plead state-law claims instead, such as negligence, breach of confidentiality, or a state medical privacy statute.
Do I have a right to a copy of my own medical records?
Yes. The right of access at 45 CFR 164.524 requires a covered entity to provide access to the designated record set, generally within 30 days, in the form and format requested where readily producible, for a reasonable cost-based fee.
Are vendors directly liable, or only the hospital?
Business associates are directly liable. Amendments made under the HITECH Act extended the Security Rule and parts of the Privacy Rule to vendors handling protected health information on a covered entity’s behalf, independent of what their contract says.
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- 45 CFR Part 164 — HIPAA Security and Privacy Rules regulation
- 45 CFR Part 160 — General administrative requirements and enforcement regulation
- HHS Office for Civil Rights, HIPAA Privacy Rule agency guidance
- HHS Office for Civil Rights, HIPAA Security Rule agency guidance
- HHS Office for Civil Rights, Breach Notification Rule agency guidance
- HHS breach portal — reported breaches affecting 500 or more individuals enforcement data
- HHS Office for Civil Rights, HIPAA enforcement and resolution agreements enforcement action
- 16 CFR Part 318 — FTC Health Breach Notification Rule regulation
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.