What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a 1996 federal law that sets national standards for protecting sensitive patient health information from being disclosed without the patient's consent or knowledge.
Updated September 2026
HIPAA Explained
HIPAA (Public Law 104-191) was signed in August 1996, and the privacy and security regulations most people mean when they say "HIPAA" were issued by the Department of Health and Human Services in the years after. The law's original purpose covered health insurance portability and administrative simplification. The patient-privacy framework grew out of the administrative simplification provisions, and it now spans four regulations that together govern how Protected Health Information (PHI) is used, secured, and disclosed.
For B2B teams that buy or sell healthcare provider business data, the practical question is narrower: which data falls under these rules and which doesn't. This entry covers the regulatory basics and that distinction. It's educational background, and questions about a specific dataset or campaign belong with your compliance team.
What are the main HIPAA rules?
| Rule | What it governs | Key facts |
|---|---|---|
| Privacy Rule | Use and disclosure of PHI in any form: paper, electronic, spoken | Compliance required since 2003; gives patients rights to access and amend their records |
| Security Rule | Electronic PHI only | Requires administrative, physical, and technical safeguards; compliance required since 2005 |
| Breach Notification Rule | Response when unsecured PHI is exposed | Added under the HITECH Act of 2009; individuals notified within 60 days, HHS notified, media notified for breaches affecting 500+ people in a state |
| Enforcement Rule | Investigations and penalties | Enforced by the HHS Office for Civil Rights, with tiered civil money penalties based on culpability |
The Privacy Rule and Security Rule get conflated constantly. The Privacy Rule decides who may see PHI and for what purposes. The Security Rule decides how electronic PHI must be protected once someone holds it: access controls, encryption decisions, audit logs, workforce training. A fax of a patient chart implicates the Privacy Rule alone. A database of patient charts implicates both.
Who has to comply with HIPAA?
HIPAA binds two groups. Covered entities are health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with standard transactions like claims and eligibility checks. Business associates are vendors that create, receive, maintain, or transmit PHI on a covered entity's behalf: billing companies, cloud hosts storing patient records, analytics firms processing claims. A covered entity must sign a Business Associate Agreement (BAA) with each such vendor, and since the 2013 Omnibus Rule, business associates are directly liable for violations themselves.
A company that never touches PHI is neither. A software vendor selling scheduling tools to dental offices, or a data company compiling provider business records from public registries, sits outside the covered entity and business associate categories so long as no patient information flows through its systems.
What counts as PHI?
PHI is individually identifiable health information held or transmitted by a covered entity or business associate. The identifiability standard is broad: the Privacy Rule's Safe Harbor de-identification method lists 18 identifiers (names, geographic subdivisions smaller than a state, dates tied to an individual, phone numbers, Social Security numbers, medical record numbers, and more) that must be removed before health data stops being PHI. Patient lists, claims files, appointment records, and treatment histories all qualify.
Provider business data sits on the other side of the line. A dentist's NPI number, practice address, specialty classifications, and business phone describe a professional in their business capacity, and CMS publishes them in the public NPPES download file precisely because they identify providers rather than patients. A file of 5,000 dermatology practice addresses contains no patient and no health condition, so HIPAA's definitions don't reach it. The moment a dataset links any individual to a health condition, treatment, or payment for care, it crosses back into PHI territory, which is why patient-level claims data carries HIPAA obligations that provider directories don't.
How does HIPAA treat marketing?
The Privacy Rule restricts using PHI for marketing. With limited exceptions, a covered entity needs the patient's written authorization before using their information to send marketing communications, and the HITECH Act tightened those exceptions further where a third party pays for the communication. That framework governs marketing to patients using patient data.
Marketing to providers is a different activity. A device company emailing an oral surgeon's business address, or a SaaS vendor calling a practice's front desk, is B2B outreach built on business contact information. No PHI is used, so the Privacy Rule's marketing authorization requirements don't apply. Other laws still govern the channel itself: CAN-SPAM for commercial email and the TCPA for calls and texts apply to provider outreach the same way they apply to any business audience. Teams running provider campaigns should clear those rules rather than HIPAA. Our B2B healthcare lead generation guide covers the outreach mechanics, and the healthcare data vendor comparison covers how vendors source provider records in the first place.
Why HIPAA Matters for Healthcare Data
HIPAA confusion creates unnecessary friction in healthcare data sales. Some buyers worry that purchasing provider contact data violates HIPAA. It doesn't. Provider business data is public information, not protected health information. Understanding this distinction helps you address buyer objections and close deals faster.
Real-World Example
A healthcare SaaS company's legal team initially blocks the purchase of provider contact data, citing HIPAA concerns. The data vendor clarifies that the dataset contains only provider business information (NPI numbers, practice addresses, professional credentials) sourced from the public NPPES registry and business listings. No patient data is involved. The legal team approves the purchase after reviewing the data dictionary.
Frequently Asked Questions
Is provider contact data covered by HIPAA?
No. HIPAA protects patient health information (PHI), not provider business data. Provider names, NPI numbers, practice addresses, specialty information, and business contact details are public information. Purchasing or using provider business data does not implicate HIPAA.
What data is considered PHI under HIPAA?
PHI includes any individually identifiable health information: patient names, addresses, dates (birth, admission, discharge), Social Security numbers, medical record numbers, health plan IDs, and any data that links to a patient's health condition, treatment, or payment for care.
Do I need a BAA to buy provider contact data?
No. A Business Associate Agreement (BAA) is required when a vendor handles Protected Health Information on your behalf. Provider business data does not contain PHI, so no BAA is needed for purchasing provider contact lists, practice data, or professional directories.
What is the difference between the HIPAA Privacy Rule and Security Rule?
The Privacy Rule governs who may use and disclose PHI, in any form, and has required compliance since 2003. The Security Rule applies only to electronic PHI and requires administrative, physical, and technical safeguards, with compliance required since 2005. Privacy answers when data may be shared; Security answers how electronic data must be protected.
Does HIPAA apply to marketing to doctors?
HIPAA's marketing restrictions govern the use of patient PHI for marketing communications. Outreach to providers at their business contact points uses no PHI, so those restrictions don't apply. Channel laws still do: CAN-SPAM governs commercial email and the TCPA governs calls and texts, for provider audiences as for any other business audience.
Who enforces HIPAA and what are the penalties?
The HHS Office for Civil Rights investigates complaints and breaches and can impose tiered civil money penalties that scale with culpability, from unknowing violations up to willful neglect. State attorneys general can also bring actions under the HITECH Act, and criminal violations are referred to the Department of Justice.
Sources and References
Related Resources
Get the Provider Data You Need
Tell us what you're looking for. We'll build a custom list matched to your target market.
Trusted by healthcare sales teams, medical device companies, and health IT vendors across the US.