Back to HomeHIPAA · Title II · Administrative Simplification

The Privacy Rule

The Privacy Rule sets national standards for how protected health information may be used and disclosed — and gives individuals enforceable rights over their own health information.

Overview

EnactedHIPAA signed August 21, 1996. The Privacy Rule was published December 28, 2000, with compliance required by April 14, 2003 (April 14, 2004 for small health plans).
Primary citation45 CFR Parts 160 and 164, Subparts A and E
Official titleStandards for Privacy of Individually Identifiable Health Information
Who must complyCovered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with a covered transaction — plus their business associates.
Who enforces itHHS Office for Civil Rights (OCR)
Related rulesSecurity Rule (45 CFR Part 164 Subpart C), Breach Notification Rule (45 CFR Part 164 Subpart D), and the Enforcement Rule (45 CFR Part 160 Subparts C–E).

Understand the Rules

Know what matters and your obligations.

Protect Health Data

Apply safeguards to keep ePHI secure.

Reduce Risk, Stay Compliant

Follow best practices and avoid penalties.

Build Trust, Improve Care

Better data security leads to better care.

HIPAA Made Simple logoSIMPLE HIPAA

Understand the rules. Protect people. Build trust. Clear, citation-backed HIPAA education for covered entities, business associates, and the workforce that keeps health data safe.

HIPAA Made Simple.

Disclaimer

This site provides general educational information about HIPAA and is not legal advice. Always consult qualified compliance counsel for your specific circumstances, and refer to the official HHS guidance and the Code of Federal Regulations.

Strong Security. Smart Compliance. Better Outcomes. | HIPAA Made Simple.

© 2026 Simple HIPAA. Educational use only.

    base44
    Edit with Base44