42 U.S.C. §§ 1320d-1320d-9; 45 CFR Parts 160, 162, 164

Health Insurance Portability and Accountability Act

Statute — United States Federal
Effective: August 21, 1996 19 platforms tracked 310 provisions indexed Enforced by: U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), State Attorneys General Last reviewed May 9, 2026

Overview

The Health Insurance Portability and Accountability Act establishes national standards for the protection of individually identifiable health information. The HIPAA Privacy Rule regulates the use and disclosure of protected health information (PHI) by covered entities, while the Security Rule sets standards for safeguarding electronic PHI.

For platform governance, HIPAA is relevant when technology platforms process, store, or transmit health data on behalf of covered entities. Platforms that serve as business associates — handling PHI under contract with healthcare providers or health plans — must comply with HIPAA requirements including breach notification, minimum necessary standards, and administrative safeguards.

The Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500+ individuals must be reported to HHS and local media. The HHS Office for Civil Rights maintains a public "Wall of Shame" listing all breaches affecting 500+ individuals. Enforcement has intensified significantly, with penalties reaching tens of millions of dollars for systemic violations.

Penalties

Four-tier penalty structure: Tier 1 (no knowledge): $100-$50,000 per violation. Tier 2 (reasonable cause): $1,000-$50,000. Tier 3 (willful neglect, corrected): $10,000-$50,000. Tier 4 (willful neglect, not corrected): $50,000 per violation. Annual cap of $1.5 million per identical violation category. Criminal penalties up to $250,000 and 10 years imprisonment.

Key Articles & Sections

Platforms We Track Subject to HIPAA

Recent Changes Related to HIPAA

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by HIPAA (310 across 19 platforms)

Genetic Data Retention After Account Deletion 23andMe
Medium
Account Deletion and Sample Discard 23andMe
Medium
Telehealth and Medical Record Privacy Notice 23andMe
Medium
DNA Relatives and Sharing Features Consent 23andMe
Medium
International Data Transfers 23andMe
Medium
CCPA Rights for California Residents 23andMe
Medium
Separate Medical Record Privacy Notice for Telehealth 23andMe
Medium
California Consumer Privacy Rights 23andMe
Medium
Data Sharing with Third-Party Service Providers 23andMe
Medium
Terms Modification with Continued Use as Acceptance 23andMe
Medium
Sharing Features Participation (DNA Relatives and Connections) 23andMe
Medium
Genetic Data Research Use 23andMe
Medium
Sample Storage Choice 23andMe
Medium
Account Deletion Right 23andMe
Medium
Prohibition on Insurance Company and Employer Use 23andMe
Medium
Restriction on Insurance Companies and Employers 23andMe
Medium
Intellectual Property License 23andMe
Medium
Telehealth Services and Separate Medical Record Privacy Notice 23andMe
Medium
Age Restriction and Minimum Age Requirement 23andMe
Medium
Children's Use and Age Restriction Amazon
Medium
Unilateral Modification of Terms Amazon
Medium
Privacy Notice Reference and Data Practices Amazon
Medium
Law Enforcement Cooperation Authorization Amazon
Medium
Law Enforcement Cooperation and Investigation Rights Amazon
Medium
Account Security and User Responsibility Amazon
Medium
Law Enforcement Cooperation and Disclosure Amazon
Medium
Children's Access Restriction Amazon
Medium
Broad Royalty-Free Content License Amazon
Medium
User Content License Grant Amazon
Medium
Account Security and Responsibility Amazon
Medium

Showing 30 of 310 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies — including HIPAA-relevant provisions.

Subscribe to Monitor — $19/mo

Frequently Asked Questions

What does HIPAA require?

Which platforms does HIPAA apply to?

ConductAtlas tracks HIPAA-relevant provisions across 19 platforms. Each platform's specific provisions are classified by severity and mapped to HIPAA requirements.

How does ConductAtlas monitor HIPAA compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect HIPAA obligations. Every change is archived with cryptographic verification.