HIPAA protects healthcare information in the US. If you handle PHI (Protected Health Information), HIPAA applies.
Who must comply:
- Healthcare providers and insurers
- Business associates handling PHI
The three rules:
Privacy Rule. Limits PHI access and use.
Security Rule. Requires administrative, physical, and technical safeguards.
Breach Notification. Notify within days of discovery.
Penalties range from 100$ to 50,000 per violation, up to $$1.5 million per year.