HIPAA
Health Insurance Portability and Accountability Act
The US law for protecting patient health information.
Enforced by
HHS Office for Civil Rights
Region
United States
Protects
PHI / ePHI
Outcome
Demonstrated compliance
Overview
What is HIPAA?
HIPAA is the US federal law that sets national standards for protecting Protected Health Information (PHI). It applies to covered entities — healthcare providers, health plans, and clearinghouses — and to the business associates that handle PHI on their behalf.
Compliance is built around a set of rules and enforced by the HHS Office for Civil Rights. There is no government HIPAA certification — you demonstrate compliance through your safeguards, policies, risk analysis, and Business Associate Agreements.
Who needs it: Any company that creates, receives, stores, or transmits PHI in the US — including health-tech startups and the SaaS vendors (business associates) that serve healthcare customers.
Inside the framework
The core HIPAA rules
Privacy Rule
Governs how PHI may be used and disclosed, and gives patients rights over their information.
Security Rule
Requires administrative, physical, and technical safeguards for electronic PHI (ePHI).
Breach Notification Rule
Mandates notifying affected individuals, HHS, and sometimes the media after a breach of unsecured PHI.
Business Associate Agreements
Contracts that bind your vendors — and you, as a vendor — to protect the PHI you handle.
With RegShield
Get HIPAA-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right HIPAA controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for HIPAA is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your HIPAA readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Is there a HIPAA certification?
There's no official government certification. Vendors demonstrate compliance via safeguards, policies, risk analysis, and BAAs — exactly the evidence RegShield maps.
What's a business associate?
Any vendor that handles PHI for a covered entity. If you're a SaaS serving healthcare, you're likely a business associate and need a BAA.
What are the three safeguard types?
Administrative, physical, and technical — the structure of the HIPAA Security Rule.