Skip to main content
Federal Law Explainer · Reviewed September 2026

What Is Health Insurance Portability and Accountability Act?

HIPAA is the federal framework for protecting Protected Health Information (PHI) held by healthcare providers, health plans, and healthcare clearinghouses (collectively, 'covered entities') and their 'business associates.' The three pillars, the Privacy Rule, the Security Rule, and the Breach Notification Rule, govern PHI across use, disclosure, safeguarding, and incident reporting. Critically, HIPAA's scope is narrower than most consumers assume. Health-adjacent data held by non-covered entities, fitness apps, period trackers, mental-health apps, pharmacy loyalty programs used outside a provider relationship, and most data brokers, is typically NOT subject to HIPAA. This gap is why the FTC, not HHS, has pursued recent enforcement against companies like BetterHelp (2023) and GoodRx (2023) for sharing consumer health data with advertisers.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 7, 2026

At a glance

Full name
Health Insurance Portability and Accountability Act
Short code
HIPAA
Enacted
1996
Last major update
Privacy Rule 2003; Security Rule 2005; HITECH/Omnibus Rule 2013; 2024 reproductive-health Privacy Rule (most provisions vacated June 18, 2025; remaining NPP changes due February 16, 2026)
Jurisdiction
United States (federal)
Private right of action
No
Primary enforcer
HHS Office for Civil Rights (OCR); state Attorneys General (granted authority by HITECH 2009)

Scope, who HIPAA covers

Three types of 'covered entities': (1) healthcare providers (doctors, hospitals, pharmacies, dentists) who transmit health information electronically in connection with standard transactions; (2) health plans (insurance, HMOs, government programs like Medicare/Medicaid, employer group health plans); (3) healthcare clearinghouses (entities processing health-data transactions between other entities). HIPAA also applies to 'business associates' that handle PHI on behalf of covered entities.

Protected data

Protected Health Information (PHI): individually identifiable health information transmitted or maintained in any form by a covered entity or business associate. Includes diagnoses, test results, prescriptions, billing records, and the fact of treatment. The definition does NOT include employment records held by the entity as an employer or education records under FERPA.

Consumer rights & protections

Right to a Notice of Privacy Practices describing how a covered entity uses and discloses PHI

Right of access, obtain a copy of your medical records (usually within 30 days; one 30-day extension allowed)

Right to amend, request corrections to inaccurate PHI

Right to an accounting of disclosures for purposes other than treatment, payment, or healthcare operations (going back 6 years)

Right to request restrictions on uses and disclosures (covered entity must agree if disclosure would be to a health plan for services paid out-of-pocket in full)

Right to confidential communications (alternative addresses / phone numbers for receiving PHI)

Right to file a complaint with HHS Office for Civil Rights

Notable features

HIPAA's scope is limited to covered entities, business associates, and PHI handled in those relationships. A health-adjacent company may fall outside HIPAA while still being subject to the FTC Health Breach Notification Rule, the FTC Act, or state law. Which rule applies depends on the company's role, data flow, and conduct; no single gap-law hierarchy applies to every app or broker.

Enforcement & penalties

Enforcing agency: HHS Office for Civil Rights (OCR); state Attorneys General (granted authority by HITECH 2009)

Penalties: HIPAA civil money penalties are tiered by culpability and adjusted by HHS; criminal penalties depend on the statutory conduct and intent. Because amounts and annual caps can change, use the current HHS enforcement materials and 45 CFR Part 160 rather than treating a fixed dollar range as current in perpetuity.

Private right of action: HIPAA itself has no private right of action, so consumers cannot sue a covered entity directly for a HIPAA violation under HIPAA. Remedies flow through complaints to HHS OCR or authorized state AG actions. Some state courts may use HIPAA as evidence of a duty of care in state-law claims, and state privacy laws may separately cover health data; the availability of those claims depends on the jurisdiction and facts.

Landmark enforcement cases

HHS OCR v. Anthem

2018

Anthem paid $16 million to HHS, the largest HHS OCR HIPAA settlement as of 2018, following a 2015 cyberattack that compromised PHI of nearly 79 million people. The settlement included ongoing compliance monitoring.

Official source →

FTC v. BetterHelp

2023

The FTC announced a $7.8M proposed order with BetterHelp over allegations that the company disclosed consumers' mental-health information for advertising and failed to honor privacy promises. The action illustrates that non-HIPAA-covered health services may still face FTC enforcement; it does not establish that every similar service is subject to the same result.

Official source →

Relevance to data brokers

Most data brokers are not HIPAA-covered, even when they handle health-adjacent data such as pharmacy loyalty information, wellness-app data, or lifestyle indicators. Broker activity in this area may instead implicate the FTC Act §5, the FTC Health Breach Notification Rule, and state laws such as Washington's My Health My Data Act, whose scope differs from HIPAA.

Generate requests in under 60 seconds

Generate removal requests for 1,034 US/global profiles, $9

Review the provider route, applicable law, and information you intend to send. You send from your own inbox and remain in control of the request; a draft is not a legal determination or provider outcome.

Frequently Asked Questions

Does HIPAA cover fitness trackers, period-tracking apps, or mental-health apps?

+

Generally no. These apps are not covered entities or business associates unless they flow data to a healthcare provider or health plan. The FTC Health Breach Notification Rule (16 CFR Part 318) and FTC Act §5 are the primary federal tools for these companies, alongside state laws like Washington's My Health My Data Act.

Can I get a copy of my medical records under HIPAA?

+

Yes. Under 45 CFR § 164.524, you have a right of access to your designated record set held by a covered entity. The covered entity must respond within 30 days (one 30-day extension is permitted with notice). Reasonable cost-based fees may apply for copies but not for viewing.

What is the difference between HIPAA and the FTC Health Breach Notification Rule?

+

HIPAA applies to covered entities and business associates; the FTC Health Breach Notification Rule (HBNR) applies to 'vendors of personal health records' not otherwise covered by HIPAA, filling the gap for consumer health apps. After a 2024 update, HBNR now applies more clearly to health apps and requires notification of breaches to affected consumers, the FTC, and (for large breaches) the media.

Can I sue my doctor under HIPAA?

+

HIPAA has no private right of action, so not directly. However, you can file a complaint with HHS OCR (which may investigate and fine the provider) and, in most states, can pursue common-law claims (negligence, breach of confidentiality) that use HIPAA as evidence of the standard of care. Some states have separate private rights of action for medical privacy.

Official sources & citations

Other federal privacy laws

Federal privacy law is sectoral, each statute covers a specific data type or industry. Here are the other federal regimes to know alongside HIPAA:

Related concepts & guides