Compliance & Regulation

HIPAA (HIPAA)

The US federal law governing the privacy and security of protected health information (PHI), with specific requirements for any portal handling patient data.

Also known as: Health Insurance Portability and Accountability Act

HIPAA (Health Insurance Portability and Accountability Act of 1996) is the US federal law governing the privacy and security of protected health information (PHI). It applies to “Covered Entities” (healthcare providers, health plans, healthcare clearinghouses) and their “Business Associates” (vendors who handle PHI on the Covered Entity’s behalf — including portal vendors).

HIPAA includes the Privacy Rule (how PHI is used and disclosed), the Security Rule (safeguards for electronic PHI), and the Breach Notification Rule. Enforcement and penalty calculations depend on current law, circumstances, and corrective action, so implementation decisions should use current official guidance rather than a static penalty table.

For portals, HIPAA compliance requires encryption, access controls, audit logging, identity verification, and a signed BAA with every vendor handling PHI. See our HIPAA compliance guide and HIPAA-compliant patient portal article.

A vendor saying its product is “HIPAA ready” is not enough. Confirm the BAA scope, subcontractors, data locations, backup and deletion behavior, incident process, and which controls remain the healthcare organization’s responsibility.