← Glossary

HIPAA

The US law governing privacy and security of protected health information, with breach notification duties and a leading role for email as a breach source.

Updated

HIPAA (the Health Insurance Portability and Accountability Act) is the US law governing the privacy and security of protected health information (PHI), enforced through its Privacy, Security and Breach Notification Rules. It applies to covered entities (providers, plans, clearinghouses) and to their business associates, vendors that touch PHI, under signed agreements. See HHS.gov for the official rules.

Key facts:

  • The Security Rule requires administrative, physical and technical safeguards for electronic PHI, calibrated to risk.
  • Breach notification duties reach individuals, the HHS and sometimes media, on defined timelines (verify current specifics at hhs.gov).
  • Hacking of email accounts is consistently among the leading breach types reported to HHS; phishing against healthcare staff is the standard entry.

Email and PHI

PHI lives in mailboxes far more than policies admit: referrals, lab discussions, patient correspondence. A single compromised healthcare mailbox is routinely a reportable breach affecting every patient mentioned in it. That makes email protection and fast compromise detection two of the highest-leverage technical safeguards a covered entity or business associate can deploy. Organizations also subject to GDPR face parallel notification duties for the same events.

Where email security fits, honestly

Sentaro supports the Security Rule's technical safeguards where they meet email: protection against phishing and account takeover, detection that makes breach assessment and notification timelines workable, and visibility into third-party apps holding access to mailboxes containing PHI. Risk analyses, policies, agreements and the notification process remain organizational obligations. Vendors serving US health systems typically pair HIPAA duties with HITRUST or SOC 2 for customer assurance.

This page is general guidance, not legal advice.

Questions we get asked.

What is HIPAA in simple terms?

The US law requiring healthcare organizations and their vendors to protect health information, secure their systems and report breaches.

Who must comply with HIPAA?

Covered entities (healthcare providers, health plans, clearinghouses) and business associates that create, receive or handle PHI on their behalf.

Is email allowed under HIPAA?

Yes, with appropriate safeguards; the practical risk is less the transmission than the mailbox itself, where accumulated PHI makes account compromise a mass breach.

How does HIPAA differ from GDPR?

HIPAA is US law limited to health information and its handlers; GDPR covers all personal data of EU residents across all sectors. Organizations serving both markets often must satisfy both.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.