42 U.S.C. §§ 1320d-1320d-9; 45 CFR Parts 160, 162, 164

Health Insurance Portability and Accountability Act

Statute — United States Federal
Effective: August 21, 1996 19 platforms tracked 816 provisions indexed Enforced by: U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), State Attorneys General Last reviewed May 9, 2026

Overview

The Health Insurance Portability and Accountability Act establishes national standards for the protection of individually identifiable health information. The HIPAA Privacy Rule regulates the use and disclosure of protected health information (PHI) by covered entities, while the Security Rule sets standards for safeguarding electronic PHI.

For platform governance, HIPAA is relevant when technology platforms process, store, or transmit health data on behalf of covered entities. Platforms that serve as business associates — handling PHI under contract with healthcare providers or health plans — must comply with HIPAA requirements including breach notification, minimum necessary standards, and administrative safeguards.

The Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500+ individuals must be reported to HHS and local media. The HHS Office for Civil Rights maintains a public "Wall of Shame" listing all breaches affecting 500+ individuals. Enforcement has intensified significantly, with penalties reaching tens of millions of dollars for systemic violations.

Penalties

Four-tier penalty structure: Tier 1 (no knowledge): $100-$50,000 per violation. Tier 2 (reasonable cause): $1,000-$50,000. Tier 3 (willful neglect, corrected): $10,000-$50,000. Tier 4 (willful neglect, not corrected): $50,000 per violation. Annual cap of $1.5 million per identical violation category. Criminal penalties up to $250,000 and 10 years imprisonment.

Key Articles & Sections

Platforms We Track Subject to HIPAA

Recent Changes Related to HIPAA

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by HIPAA (816 across 19 platforms)

Eligible users invited to participate in 23andMe Research 23andMe
Medium
User choice to store biological sample 23andMe
Medium
Research participation is voluntary with IRB consent 23andMe
Medium
User controls participation in sharing features 23andMe
Medium
Product development uses de-identified information 23andMe
Medium
User right to appeal denied privacy requests Ancestry
Medium
User may download DNA Data at own risk Ancestry
Medium
DNA survey responses used for product development Ancestry
Medium
User May Delete Their Content Ancestry
Medium
Survey responses used for research with informed consent Ancestry
Medium
Identity verification required for government ID-based privacy requests Ancestry
Medium
Personal information used for fraud and criminal activity detection Ancestry
Medium
Personal information used for marketing communications Ancestry
Medium
Family tree data retained until deletion of tree or account Ancestry
Medium
Personal information used for scientific and historical research Ancestry
Medium
Ancestry May Disclose Test Results to Authorized Parties Ancestry
Medium
Ancestry Compares DNA Data Across Users Ancestry
Medium
Ancestry Stores DNA Data Ancestry
Medium
Lab Partners May Use Samples for Calibration Ancestry
Medium
Ancestry Does Not Retain Facial Representations Ancestry
Medium
Ancestry May Extract and Genetically Test DNA Ancestry
Medium
User May Withdraw Biobanking Consent Ancestry
Medium
UK User Right to Claim for Content Takedown Breach Ancestry
Medium
Non-US users may contact supervisory authority to complain Ancestry
Medium
EU Users May Appeal Ancestry Content Decisions Ancestry
Medium
User content combined with Ancestry databases for insights Ancestry
Medium
Payment and billing information collected at purchase Ancestry
Medium
Communications with Member Services collected and stored Ancestry
Medium
User may unsubscribe from marketing emails and SMS Ancestry
Medium
Device and IP address information collected automatically Ancestry
Medium

Showing 30 of 816 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies, including HIPAA-relevant provisions.

Subscribe to Monitor, $19/mo

Frequently Asked Questions

What does HIPAA require?

Which platforms does HIPAA apply to?

ConductAtlas tracks HIPAA-relevant provisions across 19 platforms. Each platform's specific provisions are classified by severity and mapped to HIPAA requirements.

How does ConductAtlas monitor HIPAA compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect HIPAA obligations. Every change is archived with cryptographic verification.