← ALL FRAMEWORKS

HIPAA

Healthcare Privacy

Issued by U.S. Department of Health & Human Services

HIPAA's Privacy, Security, and Breach Notification Rules — administered and enforced by the HHS Office for Civil Rights — govern how "covered entities" (healthcare providers, health plans, and healthcare clearinghouses) and their "business associates" (vendors handling protected health information on their behalf) must safeguard PHI. The Privacy Rule limits use and disclosure of PHI, the Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule sets deadlines and procedures for notifying affected individuals, HHS, and in some cases the media, following a breach.

Get notified the moment HIPAA actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.