Health Insurance Portability and Accountability Act
Tier 1 In forceThe health-sector rules that make the US a patchwork rather than a gap. HIPAA carries the clearest criminal/regulatory split in the Atlas: a Department of Justice criminal track with real custody alongside a civil enforcement track run by HHS Office for Civil Rights — two regimes, two prosecutors, one set of facts. There is no private right of action, so individuals litigate through state negligence and privacy torts with HIPAA as the standard of care rather than the cause of action.
Identity
- Citation
- Pub. L. 104-191, as amended by the HITECH Act 2009; 45 CFR Parts 160 and 164
- Jurisdiction
- United States
- Type
- sectoral
- Structure
- 45 CFR Parts 160 and 164 — Privacy Rule, Security Rule, Breach Notification Rule and Enforcement Rule
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap. Checked by Fable on 26 July 2026.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | Asymmetry found | The federal rules apply uniformly across the United States and its territories, with no regional carve-out in the statute or the Parts 160 and 164 rules. The asymmetry is in the effective standard rather than the text: HIPAA pre-empts only LESS stringent state law, so any state provision more protective of the individual survives and governs. A covered entity's actual obligations therefore vary state by state, and "HIPAA-compliant" is never a complete answer to what a given entity must do in a given state. |
| 2 | Commencement | Asymmetry found | The statute and the Privacy, Security, Breach Notification and Enforcement Rules are long in force, but the current rule set is not stable. The 2024 Reproductive Health Privacy Rule (89 Fed. Reg. 32976) was vacated nationwide in Purl v. HHS (N.D. Tex., 2025-06-18), with the Fifth Circuit dismissing the appeal on 2025-09-10; only the substance-use-disorder notice-of-privacy-practices provision survived, with a compliance date of 2026-02-16 that has now passed. Separately, the Security Rule overhaul proposed on 2025-01-06 has NOT been finalised and sits on the HHS long-term agenda with final action estimated for July 2027. Practitioners must check which rule version governs rather than assume the published 2024 package applies. |
| 3 | Sunset / mandatory review | None found — checked | None found — checked. Neither HIPAA nor HITECH contains an expiry, lapse or mandatory periodic review provision, and the implementing rules are amended by ordinary notice-and-comment rulemaking rather than on a statutory review cycle. Civil money penalty figures are adjusted annually for inflation, but that is an indexation mechanism, not a review clause. |
| 4 | Criminal liability | Asymmetry found | This is the clearest criminal/regulatory split in the Atlas. The civil track runs from HHS Office for Civil Rights against the organisation; the criminal track runs from the Department of Justice under 42 U.S.C. 1320d-6 and is available against individuals. Custody IS available and is tiered by mens rea: up to one year for knowingly obtaining or disclosing individually identifiable health information; up to five years where the offence is committed under false pretences; and up to ten years where it is committed with intent to sell, transfer or use the information for commercial advantage, personal gain or malicious harm. The two tracks have different defendants, different forums and different triggers, and a single incident can produce both. |
| 5 | Civil liability | None found — checked | None found — checked. HIPAA creates NO private right of action; an individual cannot sue a covered entity for a HIPAA violation as such. Claimants instead bring state-law claims — negligence, invasion of privacy, breach of confidence, or state consumer-protection statutes — and courts in several states permit HIPAA to be pleaded as evidence of the applicable standard of care rather than as the cause of action itself. Summaries that describe patients "suing under HIPAA" are wrong. |
| 6 | Regulatory enforcement toolkit | Asymmetry found | HHS OCR can require corrective action plans, enter resolution agreements with monitoring, and impose civil money penalties on a four-tier culpability scale. On the 2026-01-28 inflation adjustment, Tier 1 runs from USD 145 to USD 73,011 per violation and Tier 4 from USD 73,011 to USD 2,190,294, with an annual cap of USD 2,190,294 per identical provision — though OCR's 2019 Notice of Enforcement Discretion applies lower caps to Tiers 1 to 3 and has not itself been embedded in a final rule. State attorneys general hold concurrent civil enforcement authority under HITECH, so there are multiple civil enforcers as well as the separate DOJ criminal track. |
| 7 | Personal / director liability | Asymmetry found | Individuals face direct exposure, and not only through the organisation. Employees and officers can be prosecuted personally under 42 U.S.C. 1320d-6 with custody available, and prosecutions of individual clinical and administrative staff for snooping or data theft are a recurring feature of the enforcement record. Separately, the 2013 Omnibus Rule made business associates directly liable for specified Privacy and Security Rule obligations rather than liable only through their contract with the covered entity, which shifted a whole class of service providers into primary regulatory exposure. |
| 8 | Public vs private sector split | Asymmetry found | HIPAA is not a general health-data law. It binds only covered entities (health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with covered transactions) and their business associates. Identical health information held by an entity outside that definition — a consumer wellness app, a wearable manufacturer, a direct-to-consumer testing service, most employers acting as employers — falls entirely outside HIPAA and is governed, if at all, by FTC authority or state law. This scope boundary, not the strength of the rules, is the single most consequential feature of the regime. |
| 9 | Legal-person coverage | None found — checked | None found — checked. The regime protects the individually identifiable health information of natural persons; protected health information is defined by reference to an individual, including a deceased individual for 50 years after death. Organisations appear only as duty-bearers (covered entities and business associates), never as protected subjects. |
| 10 | Exemptions — with conditions | Asymmetry found | The exemption regime works by removing data from scope and by permitting disclosure without authorisation, rather than by suspending the rules wholesale. De-identified information falls outside PHI entirely once either the Safe Harbor identifier-removal method or the expert determination method is satisfied; limited data sets may be used for research, public health and operations under a data use agreement. Layered on top are the permitted-disclosure categories — treatment, payment and health care operations, plus public health, law enforcement, judicial process and others — each with its own conditions and, for several, a minimum-necessary requirement. Naming the category is never the answer; the conditions attached to it are. |
Criminal liability
A distinct track, separate from the regulatory penalties below. The same failure can attract both — a penalty notice against the organisation and a prosecution of the individual.
42 U.S.C. 1320d-6 — Wrongful disclosure of individually identifiable health information
Knowingly obtaining or disclosing individually identifiable health information in violation of HIPAA. Prosecuted by the Department of Justice, entirely separately from the HHS civil track.
- Penalty
- Up to 1 year; up to 5 years where the offence is committed under false pretences; up to 10 years where committed with intent to sell, transfer or use for commercial advantage, personal gain or malicious harm.
- Imprisonment
- Available
Civil liability
None found — checked. HIPAA creates no private right of action. Individuals bring state negligence, invasion of privacy or confidentiality claims instead, with HIPAA frequently used to establish the standard of care. This is the single most misunderstood point about the statute.
Regulatory enforcement
- Penalty ceiling
- Four culpability tiers, inflation-adjusted annually. As published in the Federal Register on 28 January 2026 (OMB multiplier 1.02598): Tier 1 from $145 to $73,011 per violation; Tier 4 from $73,011 to $2,190,294, with an annual cap of $2,190,294 per identical provision. OCR's 2019 Notice of Enforcement Discretion reduces the annual caps for tiers 1 to 3.
Breach notification runs to 60 days, with a 500-individual threshold triggering media notice and contemporaneous notice to HHS.
Legal-person coverage
- Covers legal persons
- No — natural persons only
Protected health information relates to individuals.
Public / private sector split
- Separate regimes
- Yes
Sectoral by design. HIPAA binds covered entities — health plans, clearinghouses and providers transmitting electronically — and their business associates. It does not reach health data held outside that perimeter, which is why consumer health apps frequently fall outside it entirely.
Interactions and conflicts
Pre-emption operates as a FLOOR: more stringent state law survives, which is why HIPAA compliance alone does not answer a state-law question. The CCPA carves out HIPAA-regulated data at data level rather than exempting the entity, so a covered entity can be inside both regimes for different datasets.
Live issues
Sources
- Primary HIPAA Administrative Simplification, 45 CFR Parts 160 and 164 US Department of Health and Human Services no verified URL yet
URL unconfirmed.
- Primary Annual civil monetary penalty inflation adjustment, Federal Register 28 January 2026 HHS no verified URL yet
URL unconfirmed.
- Case law Purl v. HHS, No. 2:24-CV-228-Z (N.D. Tex. 2025) no verified URL yet
URL unconfirmed.
Never independently verified — seeded from the prototype.