HIPAA's Privacy Rule and Security Rule govern how covered entities, including healthcare providers, health plans, and healthcare clearinghouses, and their business associates must handle PHI. PHI includes any information that could identify a patient and relates to their health condition, the healthcare they received, or payment for that care.
The Privacy Rule limits how PHI can be used and disclosed without patient authorization and grants patients rights to access and correct their records. The Security Rule mandates specific administrative, physical, and technical safeguards for electronic PHI. Violations carry tiered civil penalties up to $1.9 million per violation category per year.
As health data increasingly flows into consumer applications, wearables, and AI health tools, the scope of what qualifies as PHI and who qualifies as a covered entity has become a more contested compliance boundary. Organizations using health-adjacent data need to carefully assess whether HIPAA applies to their data environment.