What Is Health Insurance Portability and Accountability Act?
HIPAA is the federal framework for protecting Protected Health Information (PHI) held by healthcare providers, health plans, and healthcare clearinghouses (collectively, 'covered entities') and their 'business associates.' The three pillars, the Privacy Rule, the Security Rule, and the Breach Notification Rule, govern PHI across use, disclosure, safeguarding, and incident reporting. Critically, HIPAA's scope is narrower than most consumers assume. Health-adjacent data held by non-covered entities, fitness apps, period trackers, mental-health apps, pharmacy loyalty programs used outside a provider relationship, and most data brokers, is typically NOT subject to HIPAA. This gap is why the FTC, not HHS, has pursued recent enforcement against companies like BetterHelp (2023) and GoodRx (2023) for sharing consumer health data with advertisers.
At a glance
- Full name
- Health Insurance Portability and Accountability Act
- Short code
- HIPAA
- Enacted
- 1996
- Last major update
- Privacy Rule 2003; Security Rule 2005; HITECH/Omnibus Rule 2013; 2024 reproductive-health Privacy Rule (most provisions vacated June 18, 2025; remaining NPP changes due February 16, 2026)
- Jurisdiction
- United States (federal)
- Private right of action
- No
- Primary enforcer
- HHS Office for Civil Rights (OCR); state Attorneys General (granted authority by HITECH 2009)
- Statutory citation
- 42 U.S.C. § 1320d; implementing regulations at 45 CFR Parts 160-164
Scope, who HIPAA covers
Protected data
Consumer rights & protections
Right to a Notice of Privacy Practices describing how a covered entity uses and discloses PHI
Right of access, obtain a copy of your medical records (usually within 30 days; one 30-day extension allowed)
Right to amend, request corrections to inaccurate PHI
Right to an accounting of disclosures for purposes other than treatment, payment, or healthcare operations (going back 6 years)
Right to request restrictions on uses and disclosures (covered entity must agree if disclosure would be to a health plan for services paid out-of-pocket in full)
Right to confidential communications (alternative addresses / phone numbers for receiving PHI)
Right to file a complaint with HHS Office for Civil Rights
Notable features
HIPAA's scope is limited to covered entities, business associates, and PHI handled in those relationships. A health-adjacent company may fall outside HIPAA while still being subject to the FTC Health Breach Notification Rule, the FTC Act, or state law. Which rule applies depends on the company's role, data flow, and conduct; no single gap-law hierarchy applies to every app or broker.
Enforcement & penalties
Enforcing agency: HHS Office for Civil Rights (OCR); state Attorneys General (granted authority by HITECH 2009)
Penalties: HIPAA civil money penalties are tiered by culpability and adjusted by HHS; criminal penalties depend on the statutory conduct and intent. Because amounts and annual caps can change, use the current HHS enforcement materials and 45 CFR Part 160 rather than treating a fixed dollar range as current in perpetuity.
Private right of action: HIPAA itself has no private right of action, so consumers cannot sue a covered entity directly for a HIPAA violation under HIPAA. Remedies flow through complaints to HHS OCR or authorized state AG actions. Some state courts may use HIPAA as evidence of a duty of care in state-law claims, and state privacy laws may separately cover health data; the availability of those claims depends on the jurisdiction and facts.
Landmark enforcement cases
HHS OCR v. Anthem
2018Anthem paid $16 million to HHS, the largest HHS OCR HIPAA settlement as of 2018, following a 2015 cyberattack that compromised PHI of nearly 79 million people. The settlement included ongoing compliance monitoring.
Official source →FTC v. BetterHelp
2023The FTC announced a $7.8M proposed order with BetterHelp over allegations that the company disclosed consumers' mental-health information for advertising and failed to honor privacy promises. The action illustrates that non-HIPAA-covered health services may still face FTC enforcement; it does not establish that every similar service is subject to the same result.
Official source →Relevance to data brokers
Most data brokers are not HIPAA-covered, even when they handle health-adjacent data such as pharmacy loyalty information, wellness-app data, or lifestyle indicators. Broker activity in this area may instead implicate the FTC Act §5, the FTC Health Breach Notification Rule, and state laws such as Washington's My Health My Data Act, whose scope differs from HIPAA.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
Frequently Asked Questions
Does HIPAA cover fitness trackers, period-tracking apps, or mental-health apps?
+
Generally no. These apps are not covered entities or business associates unless they flow data to a healthcare provider or health plan. The FTC Health Breach Notification Rule (16 CFR Part 318) and FTC Act §5 are the primary federal tools for these companies, alongside state laws like Washington's My Health My Data Act.
Can I get a copy of my medical records under HIPAA?
+
Yes. Under 45 CFR § 164.524, you have a right of access to your designated record set held by a covered entity. The covered entity must respond within 30 days (one 30-day extension is permitted with notice). Reasonable cost-based fees may apply for copies but not for viewing.
What is the difference between HIPAA and the FTC Health Breach Notification Rule?
+
HIPAA applies to covered entities and business associates; the FTC Health Breach Notification Rule (HBNR) applies to 'vendors of personal health records' not otherwise covered by HIPAA, filling the gap for consumer health apps. After a 2024 update, HBNR now applies more clearly to health apps and requires notification of breaches to affected consumers, the FTC, and (for large breaches) the media.
Can I sue my doctor under HIPAA?
+
HIPAA has no private right of action, so not directly. However, you can file a complaint with HHS OCR (which may investigate and fine the provider) and, in most states, can pursue common-law claims (negligence, breach of confidentiality) that use HIPAA as evidence of the standard of care. Some states have separate private rights of action for medical privacy.
Official sources & citations
Other federal privacy laws
Federal privacy law is sectoral, each statute covers a specific data type or industry. Here are the other federal regimes to know alongside HIPAA:
