Skip to content

HIPAA

What is HIPAA?

The Health Insurance Portability and Accountability Act, a US federal law that establishes standards for protecting sensitive health information. Includes the Privacy Rule and Security Rule.

Privacy

What the standards actually require on hipaa

Requirements naming hipaa across 6 standards, quoted from the control text.

HITECH Act9 controls

HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls;

HITECH-Crosswalk-HIPAA-NIST-CSF-405d-Sectoral · HITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws

HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encr...

HBNR-Crosswalk-NIST-CSF-ISO-HIPAA · Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA

Florida FDBR coordination with sectoral federal privacy + data protection laws. COPPA (Children Online Privacy Protection Act, 15 USC 6501 + 16 CFR Part 312): FTC-administered; covers online services collecting from children under 13;

FDBR-Coord-COPPA-FERPA-HIPAA-Sectoral · Coordination with COPPA, FERPA, HIPAA, GLBA, FCRA and Sectoral Federal Laws

HL7 FHIR Coordination + 2024-2025 pipeline. COORDINATION WITH US REGULATORY FRAMEWORKS: (1) HIPAA PRIVACY + SECURITY RULES (45 CFR Parts 160 + 164, VERIFIED SEPARATELY) - foundational US healthcare privacy + security law;

HL7-FHIR-Coord-HIPAA-ONC-Cures-USCDI-TEFCA · HL7 FHIR Coordination with HIPAA, ONC Information Blocking, 21st Century Cures Act, USCDI, TEFCA + 2024-2025 Pipeline

Coordination positions INCDPA within the broader US and international privacy regulatory landscape. (1) US State Privacy Law Patchwork: 20+ comprehensive US state privacy laws as of 2026 (California CCPA/CPRA + Virginia VCDPA + Colorado CPA + Utah UCPA + Conne...

INCDPA-Coord-USStatePrivacy-VCDPA-CPA-CTDPA-CCPA-Federal-FTC-DPDP-GDPR-International · Indiana CDPA Coordination - US State Privacy Laws (Virginia/Colorado/Connecticut/Utah/Texas/Iowa+) + Federal Sectoral (HIPAA/GLBA/FCRA/FERPA/COPPA) + FTC Section 5 + GDPR + India DPDP + International Privacy Frameworks
MARS-E4 controls

Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45...

MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E · MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

Questions people ask about hipaa

What is HIPAA?
The Health Insurance Portability and Accountability Act, a US federal law that establishes standards for protecting sensitive health information. Includes the Privacy Rule and Security Rule.
Why is HIPAA important for compliance?
HIPAA is a key concept in Privacy. Understanding hipaa helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to HIPAA?
Key concepts related to HIPAA include PHI (Protected Health Information). Understanding these interconnected concepts provides a more comprehensive view of Privacy requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address HIPAA?
HIPAA appears in the requirement text of HITECH Act, FTC Health Breach Notification Rule, Florida Digital Bill of Rights (FDBR), HL7 FHIR Security Framework, Indiana Consumer Data Protection Act. Across these standards we have identified 32 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about HIPAA?
Explore our compliance framework pages to see how hipaa applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how HIPAA applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.