Cybersecurity 101back-iconWhat is HIPAA?

What is HIPAA?

HIPAA, or the Health Insurance Portability and Accountability Act, is a U.S. federal law that sets rules for protecting certain health information. In business and cybersecurity contexts, a HIPAA policy usually means the documented privacy, security, and breach-response practices an organization uses to handle protected health information, or PHI, lawfully and securely.

HIPAA matters because healthcare data is highly sensitive. A patient record can include diagnoses, prescriptions, billing details, insurance information, contact details, and identifiers that could expose someone to fraud, discrimination, or privacy harm if mishandled.

Who must follow HIPAA?

HIPAA mainly applies to covered entities and business associates. Covered entities include health plans, healthcare clearinghouses, and healthcare providers that conduct certain electronic transactions. Business associates are vendors or service providers that handle PHI on behalf of a covered entity.

Entity type HIPAA relevance
Covered entity Directly creates, receives, maintains, or transmits PHI for healthcare operations.
Business associate Handles PHI while providing services such as billing, cloud hosting, analytics, or IT support.

HIPAA does not automatically apply to every app, employer, school, or wellness service that collects health-related data. The context, relationship, and type of information decide whether HIPAA applies.

What does a HIPAA policy cover?

A strong HIPAA policy explains how an organization protects PHI throughout its lifecycle. It should define who can access PHI, how access is approved, how systems are secured, how employees are trained, and what happens if information is exposed.

Common policy areas include:

  • Privacy practices for using and disclosing PHI
  • Administrative, physical, and technical safeguards for electronic PHI
  • Role-based access controls and authentication
  • Device, endpoint, and mobile security rules
  • Incident response and breach notification procedures
  • Vendor management and business associate agreements

For organizations managing healthcare devices, tools such as Hexnode can support HIPAA-aligned operations by enforcing device encryption, access restrictions, app controls, remote actions, and security configurations across managed endpoints.

HIPAA Privacy Rule vs Security Rule

The Privacy Rule governs how PHI can be used and disclosed. It also gives individuals certain rights over their health information, such as the right to access their records.

The Security Rule focuses on electronic PHI, often called ePHI. It requires safeguards that protect the confidentiality, integrity, and availability of ePHI. In simple terms, privacy defines appropriate use, while security protects the systems and devices where the data lives.

Why HIPAA policy compliance is a cybersecurity issue

HIPAA is not just a legal checklist. It requires practical risk management. Organizations must understand where PHI is stored, who can access it, which devices connect to it, and how threats such as phishing, stolen devices, weak passwords, or misconfigured cloud systems could expose it.

A useful HIPAA policy should therefore be clear, enforceable, and regularly reviewed. Policies only work when they match real workflows and are backed by training, monitoring, technical controls, and documented response steps.

FAQs

No. HIPAA sets legal requirements for protecting PHI, while healthcare cybersecurity includes the broader tools, processes, and defenses used to protect healthcare systems, networks, users, and devices.

HIPAA treats encryption as an addressable safeguard, meaning organizations must assess whether it is reasonable and appropriate. In practice, encryption is widely used to reduce risk, especially for laptops, mobile devices, backups, and data transfers.