HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law that sets national standards for protecting individuals’ health information.

HIPAA applies to covered entities (health plans, healthcare providers, and clearinghouses) and their business associates. Its Privacy Rule governs how protected health information (PHI) may be used and disclosed, while the Security Rule requires administrative, physical, and technical safeguards for electronic PHI. A separate Breach Notification Rule requires alerting affected individuals and regulators after a breach.

A cloud provider that stores patient records for a hospital is a business associate and must sign a business associate agreement, accepting its own HIPAA obligations. A frequent misconception is that HIPAA mandates specific technologies. It does not. The Security Rule is largely risk based, letting an organization choose reasonable and appropriate safeguards for its size and threat profile. Encryption, for example, is addressable rather than strictly required, though skipping it is hard to defend after a breach.

Why does HIPAA matter for the CISSP exam?

HIPAA sits in Domain 1, Security and Risk Management, under legal and regulatory compliance. Expect questions on who is covered, what counts as PHI, and the difference between the Privacy and Security Rules. Study it inside Domain 1 Security and Risk Management.