# HIPAA Overview | Secureframe

> Learn the basics of HIPAA, including its history, purpose, and to whom the law applies. 

canonical: https://secureframe.com/hub/hipaa/overview

According to a recent [American Medical Association survey](https://www.ama-assn.org/press-center/press-releases/patient-survey-shows-unresolved-tension-over-health-data-privacy), more than 92% of patients believe privacy is a right and their health data should not be available for purchase. Yet nearly 75% of patients also express concern about the privacy of their personal data.

In response to growing concerns about data privacy, governments around the world have passed legislation to address varied risks to the security and confidentiality of patient data.  

In 1996, the United States passed the Health Insurance Portability and Accountability Act (HIPAA) in part to establish a set of requirements for healthcare organizations to protect sensitive patient data. The purpose of this landmark legislation is to keep data safe while giving patients more power over who can access their personal data and for what purpose. 

In this overview for beginners, we’ve broken down HIPAA rules and regulations into clear-cut fundamentals so you can quickly and easily understand whether you need to be compliant. 

You’ll learn the essentials of HIPAA legislation, including the types of organizations affected by the law and how it applies to your business and patients.

## Beginner: I'm New to HIPAA

**Let’s start at the beginning. **

Understanding the essentials of HIPAA legislation helps streamline the entire compliance process, allowing you to get compliant faster and with less stress.

Here are the essentials you need to know.

![](https://images.prismic.io/secureframe-com/d7b5761e-ad0f-4fb2-94c8-2c66f74c668a_hippa-policies-and-procedures-hero.png?auto=compress,format)

## The Basics of HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a milestone piece of legislation for the US healthcare industry. 

Signed into law by President Bill Clinton in 1996, HIPAA applies to healthcare providers, health plans, healthcare clearinghouses, and business associates of HIPAA-covered entities.

HIPAA was passed to address two key issues: 

- Ensure health insurance coverage for employees who are between jobs. Without HIPAA, individuals in this situation could be left without access to health insurance and potentially unable to pay for necessary healthcare. 
- Prevent healthcare fraud by securing protected health information (PHI). HIPAA’s [Privacy Rule](https://secureframe.com/blog/hipaa-privacy-rule) introduced critical changes to how healthcare organizations can store, handle, access, and share sensitive patient information. 

HIPAA is now widely known for its impact on improving the privacy and security of patient health data. 

## The Purpose and Importance of HIPAA

Here are a few reasons why HIPAA is so important: 

### HIPAA introduces a higher level of standardization

HIPAA legislation was introduced during a time of major transition between paper and electronic health records. It created ways to help healthcare providers manage that transition by streamlining administrative tasks, improving efficiency, and ensuring PHI is stored and shared securely. 

These changes helped standardize processes, since all organizations covered by HIPAA must use the same code sets and identifiers. Transferring information between healthcare providers, insurance companies, and other entities is simpler and more secure. 

### HIPAA establishes safeguards for protecting personal health information

PHI includes all kinds of sensitive information. It goes beyond names and addresses to include credit card information, social security numbers, and details around medical conditions and procedures. 

Because of its potential for identity theft, PHI holds significant value. 

Without HIPAA, there would be no legal requirement for healthcare organizations to protect this private data — and no penalties if they didn’t. 

Now, healthcare organizations are legally required to put a series of strict security controls in place to protect personal health information. They must train their staff to protect patient data. And they must prove to an auditor that they are HIPAA compliant. 

### HIPAA grants patients greater control over their personal information

Before the HIPAA Privacy Rule, healthcare organizations did not have to release copies of a patient’s health information. 

Now, a patient’s request to access their health records must be honored within 30 days. If a patient changes healthcare providers, they can request that their old provider share their complete records. Their new doctor can have access to their health history so they can provide better care. 

In addition, covered entities cannot use private data for marketing, fundraising, or research purposes without express written permission from patients. 

### HIPAA ensures that anyone violating its standards is held accountable 

Covered entities that fail to protect PHI are subject to strict fines and, in some cases, criminal penalties. 

The Department of Health and Human Services Office for Civil Rights enforces HIPAA and investigates any reported [HIPAA violations](https://secureframe.com/blog/hipaa-violations). OCR also conducts periodic audits of covered entities and their business associates. 

Violations are broken down into tiers, depending on the offending organization’s level of negligence and the steps they took to resolve the issue afterward. Fines range from $100-$1.5M, and the harshest criminal penalties can include up to 10 years in jail.

## Who needs to be HIPAA compliant? 

HIPAA rules apply to both covered entities and business associates.

Covered entities include:

- **Healthcare providers**: doctors’ offices, clinics, psychologists, dentists, chiropractors, nursing homes, pharmacies, labs
- **Health plans:** health insurance companies, HMOs, company health plans, and government programs that pay for healthcare including Medicare/Medicaid and veterans’ healthcare programs 
- **Healthcare clearinghouses:** organizations that process nonstandard health information to conform to standards for data content or format on behalf of another organization

Business associates are individuals or organizations that provide services on behalf of a covered entity and also interface with PHI or ePHI. Examples of business associates include:

- Software providers whose products interact with systems that contain ePHI, as well as cloud service providers, cloud platforms, and file storage companies 
- Claims processing services
- Data analysis services
- Quality assurance services
- Billing services
- Attorneys or legal consulting services
- CPA firms
- Accounting services
