Get fresh insights, pro tips, and thought starters–only the best of posts for you.
HIPAA, or the Health Insurance Portability and Accountability Act, is a U.S. federal law that sets rules for protecting certain health information. In business and cybersecurity contexts, a HIPAA policy usually means the documented privacy, security, and breach-response practices an organization uses to handle protected health information, or PHI, lawfully and securely.
HIPAA matters because healthcare data is highly sensitive. A patient record can include diagnoses, prescriptions, billing details, insurance information, contact details, and identifiers that could expose someone to fraud, discrimination, or privacy harm if mishandled.
HIPAA mainly applies to covered entities and business associates. Covered entities include health plans, healthcare clearinghouses, and healthcare providers that conduct certain electronic transactions. Business associates are vendors or service providers that handle PHI on behalf of a covered entity.
| Entity type | HIPAA relevance |
|---|---|
| Covered entity | Directly creates, receives, maintains, or transmits PHI for healthcare operations. |
| Business associate | Handles PHI while providing services such as billing, cloud hosting, analytics, or IT support. |
HIPAA does not automatically apply to every app, employer, school, or wellness service that collects health-related data. The context, relationship, and type of information decide whether HIPAA applies.
A strong HIPAA policy explains how an organization protects PHI throughout its lifecycle. It should define who can access PHI, how access is approved, how systems are secured, how employees are trained, and what happens if information is exposed.
Common policy areas include:
For organizations managing healthcare devices, tools such as Hexnode can support HIPAA-aligned operations by enforcing device encryption, access restrictions, app controls, remote actions, and security configurations across managed endpoints.
The Privacy Rule governs how PHI can be used and disclosed. It also gives individuals certain rights over their health information, such as the right to access their records.
The Security Rule focuses on electronic PHI, often called ePHI. It requires safeguards that protect the confidentiality, integrity, and availability of ePHI. In simple terms, privacy defines appropriate use, while security protects the systems and devices where the data lives.
HIPAA is not just a legal checklist. It requires practical risk management. Organizations must understand where PHI is stored, who can access it, which devices connect to it, and how threats such as phishing, stolen devices, weak passwords, or misconfigured cloud systems could expose it.
A useful HIPAA policy should therefore be clear, enforceable, and regularly reviewed. Policies only work when they match real workflows and are backed by training, monitoring, technical controls, and documented response steps.
No. HIPAA sets legal requirements for protecting PHI, while healthcare cybersecurity includes the broader tools, processes, and defenses used to protect healthcare systems, networks, users, and devices.
HIPAA treats encryption as an addressable safeguard, meaning organizations must assess whether it is reasonable and appropriate. In practice, encryption is widely used to reduce risk, especially for laptops, mobile devices, backups, and data transfers.