HIPAA

The US health-privacy regime: three rules that follow protected health information wherever it goes.

Conditional standard · Health Insurance Portability and Accountability Act (Privacy, Security & Breach Rules)

Issued by

US Department of Health & Human Services

Region

United States

Effective

1996; Privacy Rule 2003, Security Rule 2005, Omnibus 2013

Oversight

HHS Office for Civil Rights

Applies when

You handle protected health information for US patients, plans or providers

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

HIPAA governs protected health information in the United States through three operative rules: Privacy (how PHI may be used and disclosed), Security (administrative, physical and technical safeguards for electronic PHI) and Breach Notification (who must be told, and how fast, when it goes wrong).

It reaches beyond US borders through contracts: a health-tech company anywhere in the world that processes PHI for a US covered entity signs a business associate agreement and inherits the obligations. For African health-tech selling into the US market, HIPAA is usually the first regime a buyer's counsel asks about.

Where programmes are tested.

01

The Privacy Rule

Permitted uses and disclosures of PHI, minimum necessary access, and patient rights over their records.

02

The Security Rule

Administrative, physical and technical safeguards for electronic PHI, risk analysis first, controls traced to it.

03

Breach notification

Individuals notified without unreasonable delay and within 60 days; HHS and the media brought in at scale.

04

Business associates

Downstream processors bound by agreement and held to the same safeguards, with liability that flows through.

Curated once, evidenced continuously.

  • HIPAA's rules are curated as requirements and cross-mapped to the same technical and privacy controls that serve ISO 27001 and the African data-protection acts: implement once, answer both markets.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

HIPAA, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Does HIPAA apply to companies outside the United States?

Yes, through the business associate chain: if you create, receive, maintain or transmit protected health information for a US covered entity, a business associate agreement binds you to the Security and Breach rules regardless of where you operate. Enforcement lands through the contract and through HHS's reach over the covered entity.

What counts as protected health information?

Individually identifiable health information held or transmitted by a covered entity or business associate, in any form: diagnoses, treatment records, billing data, and identifiers linked to them. De-identified data, done to the standard, falls outside the rules.

What does the Security Rule actually require?

A risk analysis first, then administrative, physical and technical safeguards traced to it: access management, workforce training, encryption decisions, audit controls and contingency planning. It is deliberately technology-neutral, which makes the evidence trail, not the tool list, the thing an auditor tests.

What are the breach notification deadlines?

Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery; breaches affecting 500 or more people also go to HHS and prominent media without delay, and smaller ones to HHS in an annual log.

Where it connects.

The full catalog
Cross-mapped with

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.