What is HIPAA?

HIPAA is the federal law requiring US healthcare providers and their business associates to protect patient health information through administrative, physical, and technical safeguards.

The Health Insurance Portability and Accountability Act of 1996 sets the federal floor for how Protected Health Information (PHI) must be handled inside any organization that creates, receives, maintains, or transmits it. The Office for Civil Rights (OCR) at HHS enforces it through investigations, fines, and corrective-action plans. Penalties scale by negligence tier and can run into millions of dollars per violation category per year.

HIPAA is split into the Privacy Rule (who can see PHI), the Security Rule (how PHI must be protected technically), and the Breach Notification Rule (who you tell if it leaks). Most enforcement actions hit on the Security Rule - specifically the requirement to have a current written Risk Assessment and documented Administrative, Physical, and Technical Safeguards.

Practically, that means an annual Risk Assessment, a written security policy, MFA on every account that touches PHI, encrypted devices, vendor BAAs, and a documented Incident Response Plan. security reviewers in 2026 ask to see all of this at renewal.

Why it matters for Florida small business

Every Florida medical, dental, and physical-therapy practice is HIPAA-covered. Your security reviewer won't quote you without seeing the Risk Assessment.

What to do

Run a written Risk Assessment within 12 months of any change to your systems, your staff, or your vendors. The Florida HIPAA Starter Kit walks you through it.

Related terms