Get certified in HIPAA for just $29.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Now let’s talk about the history of HIPAA, what it is, and what it covers. Back in the 1990s, with the growth of the internet, congress recognized they needed a system to enforce the rights of patients and protect the privacy of their medical records. This lead to the creation of the HIPAA act of 1996. HIPAA stands for Health Insurance Portability and Accountability Act of 1996. As health records were digitized, this lead to the HITECH rule of 2009, also known as the Health Information Technology for Economic and Clinical Health rule. The Omnibus rule of 2013 expanded how technology companies protect that information. It enforces the security and policies set forth by the HHS’ Office of Civil Rights. In 2026, updates aligning 42 CFR Part 2 with HIPAA tightened protections for substance use disorder records, require explicit patient consent prior to disclosure. As a result, organizations must update, post, and distribute their Notice of Privacy Practices to detail these heightened protections. The United States legislation provides data privacy and security provisions for safeguarding medical information. It includes the portability of insurance information between covered entities and providers to insurance companies. It also covers the Protection and Privacy of Healthcare Information transmitted in electronic form, it helped improve standardization and efficiency in healthcare data, and it is also designed to prevent discrimination and fraud.
In this lesson, we'll go over the history of HIPAA, what it is, what it covers, the evolution of healthcare data privacy, and the key regulatory updates that shape modern patient protections.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides landmark data privacy and security provisions for safeguarding medical information across the United States healthcare system.
In the 1990s, with the rapid growth of the internet, Congress recognized the need for a system to enforce patient rights and protect the privacy of medical records. Over time, key updates expanded these safeguards as healthcare technology evolved:
Updates aligning 42 CFR Part 2 with HIPAA tightened protections for substance use disorder records, requiring explicit patient consent prior to disclosure. As a result, healthcare organizations must update, post, and distribute their Notice of Privacy Practices to detail these heightened protections.
HIPAA legislation provides comprehensive data privacy and security provisions for safeguarding medical information, including:
Pro Tip: The main objective of HIPAA regulations is to protect individual medical privacy while encouraging efficiency and standardization across covered entities and business associates.