Glossary

What does HIPAA stand for?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996, a US federal law whose privacy and security rules govern how health information may be used, disclosed and safeguarded by healthcare providers and the vendors working on their behalf.

The name is a poor description of the part everybody means by it. HIPAA was passed in 1996 primarily to make health insurance portable between jobs, and the privacy regime it is now known for lives in one subtitle of it — the administrative simplification provisions — and in the rules the Department of Health and Human Services later wrote under them. When somebody says a tool "is HIPAA compliant", they are talking about those rules, not about insurance portability.

There are four rules that matter in practice. The Privacy Rule governs who may see protected health information and for what purpose. The Security Rule sets administrative, physical and technical safeguards for the electronic form of it. The Breach Notification Rule sets out who has to be told when it goes wrong, and how fast. The Enforcement Rule is what gives the Office for Civil Rights something to do about it.

Two consequences catch clinics out. The first is that HIPAA reaches vendors, not only providers: a company that handles your data on your behalf is a business associate and has direct obligations of its own. The second is that "HIPAA compliant" is not a certification anybody issues. There is no HIPAA certificate, no HIPAA logo, and no auditor whose sign-off makes a product compliant. Compliance is a property of how an organisation operates, which is why the only hard question you can ask a vendor is whether they will sign a contract accepting those obligations.

In an ABA clinic specifically.

An ABA clinic that bills insurance for treatment is inside HIPAA, and almost everything it would naturally tell a parent about their day is protected health information. The practical exposure is rarely the practice management system, which was bought deliberately and came with a BAA. It is the free tool a single site adopted informally to send photos home.

Questions people ask about HIPAA.

What does HIPAA stand for?

The Health Insurance Portability and Accountability Act of 1996. It is a US federal statute, Public Law 104-191, signed in August 1996. The privacy and security rules that people usually mean by "HIPAA" were written by the Department of Health and Human Services under its administrative simplification provisions, and appear in the Code of Federal Regulations at 45 CFR Parts 160, 162 and 164.

Is it HIPAA or HIPPA?

HIPAA. It is an initialism of Health Insurance Portability and Accountability Act, so the second A is the Accountability. "HIPPA" is the commonest misspelling in healthcare and it is worth getting right on anything a family or an auditor will read.

What does HIPAA mean in medical terms?

In day-to-day clinical use, HIPAA is shorthand for the rules on what you may say about a patient, to whom, and through what channel. It is not a clinical standard and it says nothing about how to treat anybody. It sets who is permitted to see a record, what safeguards must sit around the electronic version of it, and what has to happen if it is disclosed to someone who should not have seen it.

Who does HIPAA apply to?

Covered entities and their business associates. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically in connection with a transaction such as a claim. A business associate is a person or company that creates, receives, maintains or transmits protected health information on a covered entity’s behalf. HIPAA does not apply to schools, to childcare providers, or to a parent talking about their own child.

What is the difference between HIPAA and the HIPAA Privacy Rule?

HIPAA is the statute. The Privacy Rule is one of the regulations written under it, at 45 CFR Part 164 Subpart E, and it is the part that governs use and disclosure of protected health information. The Security Rule, at Subpart C, is a separate regulation covering safeguards for the electronic form of the same information. A vendor claim about encryption is a Security Rule claim and does not answer a Privacy Rule question.

Can a vendor be HIPAA certified?

No. There is no official HIPAA certification, and no government body issues one. A vendor may hold SOC 2 or ISO 27001, which are real audits of real controls and are worth having, but neither is a HIPAA certification and neither substitutes for a business associate agreement. The question that actually resolves anything is whether the vendor will sign a BAA for your clinic.

Does HIPAA apply to a school?

Generally no, and HHS has said so: a school is usually either not a covered entity, or is one but holds student health information only in records that are education records under FERPA, which the Privacy Rule excludes from protected health information. This is accurate and it is also the reason guidance written for schools does not transfer to a clinic delivering a billed medical treatment.

Written by Abdihafid, a behavior technician working in an in-person ABA clinic. This is a plain-language explanation for people evaluating software, not legal advice, and it is not a substitute for your own compliance counsel.

Other terms

Sources

The definitions on this page are quoted from the regulation itself rather than from a summary of it, linked below with the date we last read them there. This is a plain-language explanation for people evaluating software, not legal advice.

  1. [1] Public Law 104-191Health Insurance Portability and Accountability Act of 1996, Sec. 1(a) · checked August 31, 2026
  2. [2] 45 CFR 160.103Definitions — “Covered entity” · checked August 31, 2026
  3. [3] 45 CFR 160.103Definitions — “Protected health information”, paragraph (2) · checked August 31, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.