HIPAA (Health Insurance Portability and Accountability Act)
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the US federal statute whose administrative simplification provisions, implemented by the Department of Health and Human Services in 45 CFR Parts 160 and 164, protect the privacy and security of individually identifiable health information. Its main components are the Privacy Rule (2003), which governs uses and disclosures of protected health information (PHI); the Security Rule (2005), which requires administrative, physical and technical safeguards for electronic PHI; the Breach Notification Rule (2009, under the HITECH Act), which requires notification of individuals, HHS and sometimes the media following a breach of unsecured PHI; and the Enforcement Rule. Enforcement is by the HHS Office for Civil Rights, with civil penalties per violation category adjusted annually and criminal penalties for knowing misuse.
HIPAA applies to "covered entities", meaning health plans, healthcare clearinghouses and healthcare providers that transmit health information electronically in connection with standard transactions, and to their "business associates", vendors that create, receive, maintain or transmit PHI on their behalf under a business associate agreement. It does not apply to health information held by entities outside this perimeter, such as most wellness app developers, employers or, crucially, pharmaceutical sponsors receiving trial data, although those may be subject to state privacy laws (California's CCPA/CPRA, Washington's My Health My Data Act) and to FTC enforcement. Research uses of PHI by covered entities require either a HIPAA authorisation from the patient (typically embedded in the informed consent package), a waiver by an IRB or privacy board, use of a limited data set under a data use agreement, or de-identification under the Safe Harbor or Expert Determination methods.
HIPAA and the GDPR differ in structure: HIPAA is sector- and entity-based while the GDPR is comprehensive; HIPAA treats properly de-identified data as outside its scope while the GDPR treats coded data as pseudonymised personal data; HIPAA has no equivalent of the GDPR's transfer rules, DPO or DPIA; and the GDPR has no equivalent of the HIPAA authorisation. A transatlantic trial therefore needs both frameworks mapped: US sites operate under HIPAA and the Common Rule, EU sites under the GDPR and the CTR, and the sponsor must reconcile consent language, de-identification versus pseudonymisation and breach procedures. See iliomad's HIPAA compliance services and the CPRA page.
