No history yet

US Regulatory Landscape

The US Regulatory Framework

While the UK has the Information Commissioner's Office (ICO) overseeing GDPR, the United States has a different set of players. The primary authority is the Department of Health and Human Services (HHS). It's a vast government department responsible for protecting the health of all Americans.

Within HHS, the Office for Civil Rights (OCR) is the key enforcement agency for health information privacy. If an organisation mishandles patient data, the OCR is the body that investigates and issues penalties.

Lesson image

The Office for Civil Rights (OCR), a critical arm of the U.S. Department of Health and Human Services (HHS), is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA).

HIPAA and HITECH

The foundational law for health data in the US is the Health Insurance Portability and Accountability Act of 1996, universally known as HIPAA. Its main goal is to protect sensitive patient health information from being disclosed without the patient's consent or knowledge.

HIPAA is broadly split into two main components:

The Privacy Rule sets national standards for when protected health information (PHI) may be used and disclosed. It applies to PHI in any form: electronic, written, or oral.

The Security Rule establishes national standards specifically for protecting electronic protected health information (ePHI). It dictates the technical, physical, and administrative safeguards required.

In 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act was passed to promote the adoption and 'meaningful use' of health information technology. It strengthened HIPAA's enforcement, increased penalties for violations, and introduced new data breach notification requirements.

Who and What Is Covered?

HIPAA's rules don't apply to everyone. They are directed at specific 'Regulated Entities'. It's crucial to know the difference between the two main types:

Entity TypeDescriptionExamples
Covered EntityA health plan, health care clearinghouse, or health care provider who electronically transmits health information.Hospitals, doctor's offices, insurers, pharmacies.
Business AssociateA person or entity that performs functions on behalf of, or provides services to, a Covered Entity involving the use or disclosure of PHI.Billing companies, IT providers, cloud storage services, legal counsel.

These entities are responsible for safeguarding Protected Health Information (PHI). But what exactly constitutes PHI? Unlike the UK GDPR's broader definition of 'personal data', HIPAA is very specific. Information is considered PHI if it is created or received by a regulated entity and relates to an individual’s health, treatment, or payment for healthcare. Crucially, it must also include one or more of the 18 specific identifiers.

If a piece of health data contains even one of these identifiers, it is considered PHI and falls under HIPAA's protection. If all 18 are removed, the data is 'de-identified' and is no longer subject to the Privacy Rule.

HIPAA vs. GDPR: Key Differences

For those familiar with the UK's implementation of GDPR, HIPAA has some distinct differences. It's less about broad principles and more about specific rules for a particular sector.

FeatureHIPAAUK GDPR
ScopeSector-specific: Applies only to health plans, providers, clearinghouses, and their business associates.Economy-wide: Applies to any organisation processing personal data of UK residents, regardless of sector.
Data Subject'Individual''Data Subject'
Core DataProtected Health Information (PHI) - defined by 18 identifiers.'Personal Data' - broadly defined as any information relating to an identified or identifiable person.
Key RightsRight to access and amend PHI.Broader rights, including the right to erasure ('right to be forgotten'), data portability, and object to processing.
EnforcerHHS Office for Civil Rights (OCR)Information Commissioner's Office (ICO)

The most significant difference is scope. A health app that isn't offered by a healthcare provider or insurer might fall outside HIPAA's jurisdiction in the US, but a similar app in the UK would almost certainly be subject to GDPR.

Navigating the US healthcare system requires a firm grasp of these specific regulations. Understanding who is a Covered Entity, what constitutes PHI, and the distinct roles of HIPAA and HITECH is the first step towards compliant data handling.

Quiz Questions 1/5

Which organisation is the primary enforcement agency for health information privacy under HIPAA in the United States?

Quiz Questions 2/5

Under HIPAA, for a piece of information to be considered Protected Health Information (PHI), it must relate to an individual's health and be held by a regulated entity. What is the third crucial requirement?