Health Insurance Portability and Accountability Act (HIPAA)
HIPAA is a US law that protects health information privacy & security, also helps maintain health insurance during job changes.
What is health insurance portability and accountability act (HIPAA)?
The Health Insurance Portability and Accountability Act (HIPAA) is a United States law that was enacted in 1996. It includes provisions to protect the privacy and security of certain health information, known as protected health information (PHI). The law applies to health plans, healthcare clearinghouses, and certain healthcare providers who transmit health information in electronic form.

The regulations under health insurance portability and accountability act establish national standards for protecting the privacy and security of PHI and provide for civil and criminal penalties for violations of the law. It also provides for individuals’ rights to access and control their health information, and sets limits on certain uses and disclosures of PHI without patient authorization. HBR’s organizational management research highlights HIPAA compliance failures : often resulting from inadvertent disclosure rather than intentional breach : as among the most costly HR compliance risks, with penalties ranging from $100 to $50,000 per violation.
What is the purpose of HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that was enacted in 1996. The primary purpose of HIPAA is to make it easier for people to keep health insurance coverage when they change or lose their jobs, and to help protect the confidentiality and security of certain health information. The law includes several provisions that work together to achieve these goals.
The first set of provisions in HIPAA, known as the “portability” provisions, help to make it easier for people to keep their health insurance coverage when they change or lose their jobs. These provisions prohibit group health plans and health insurance issuers from denying coverage to people based on pre-existing medical conditions, and from charging higher premiums to people based on their health status or medical history.
The second set of provisions in health insurance portability and accountability act, known as the “administrative simplification” provisions, help to protect the confidentiality and security of certain health information, known as protected health information (PHI). These provisions establish national standards for protecting the privacy and security of PHI and provide for civil and criminal penalties for violations of the law.
The law applies to health plans, healthcare clearinghouses, and certain healthcare providers who transmit health information in electronic form. It also provides for individuals’ rights to access and control their health information, and sets limits on certain uses and disclosures of PHI without patient authorization.
HIPAA also includes a provision that requires employers to notify employees of any breaches of unsecured PHI. This is intended to help individuals take steps to protect themselves from identity theft or other harms that might result from a breach.
Overall, the main purpose of HIPAA is to protect the privacy and security of certain health information, and to make it easier for people to keep health insurance coverage when they change or lose their jobs. SHRM’s HIPAA compliance guidance provides detailed frameworks for HR professionals covering the intersection of HIPAA, the ADA, FMLA, and workers’ compensation : situations where employee health information is involved in multiple regulatory contexts simultaneously.
HIPAA compliance requires HR professionals to understand exactly when and how employee health information can be used. Organizations using pre-employment assessments ensure every hire is grounded in verified skills. A data-driven hiring plan reduces mis-hire risk, while strong talent acquisition practices focused on skills-based hiring help organizations attract and retain top talent.
Frequently asked questions
The Health Insurance Portability and Accountability Act (1996) has two main components: Title I provides health insurance continuity protections for workers changing jobs. Title II establishes privacy and security rules for protected health information (PHI). For HR, HIPAA primarily governs how employers handle employee health information received through group health plans, FMLA certification, ADA accommodation processes, workers’ compensation, and wellness programs.
Get started.
Hire on proof, not resumes.
Run your first skills-based assessment free — no credit card required.