Is HIPAA a Federal Law?

The Health Insurance Portability and Accountability Act (HIPAA) is Federal law that was enacted in 1996 with the primary objective of eliminating obstacles to economic movement by ensuring continued health insurance coverage when employees changed – or were between – jobs. The HIPAA Administrative Simplification Regulations – of which the Privacy and Security Rules are a part – are a by-product of the Federal law.

When Bill Clinton won the Presidential election in 1991, much of his success was attributable to an election promise to reform the healthcare system. On taking office, President Clinton immediately set up a Health Task Force and, in 1993, the ambitious Health Security Act (S.1757) was introduced into Congress. The Act failed to become a Federal law, but some of the proposals were repackaged into smaller Acts and reintroduced into Congress separately.

One of the smaller Acts was the Health Insurance Reform Act (S.1028). Among other measures, this Act aimed to address the lack of health insurance continuity between jobs, which was seen as an obstacle to economic movement (see definition of “job lock”). However, these measures by themselves had the potential to increase the cost of health insurance for employers and employees in the form of higher (tax-deductible) premiums, and reduce federal tax revenues.

The proposals of the Health Insurance Reform Act were adopted by Congress but merged with a companion bill – the Health Coverage Availability and Affordability Act (HR.3103) – which  included provisions to neutralize the cost of health insurance reform by addressing health insurance fraud and simplifying the administration of healthcare transactions. The proposals  to simplify the administration of healthcare transactions are what most people now recognize as “HIPAA”.

Is What Most People Now Recognize as HIPAA a Federal Law?

The HIPAA Administrative Simplification Regulations that most people now recognize as HIPAA is not a Federal law, but Federal regulations that were published by the Department of Health and Human Services (HHS) on the instruction of Congress in Title II of HIPAA. This is why HIPAA the Federal law was enacted in 1996, but the HIPAA Transaction Rules, Privacy Rule, and Security Rule (what most people now recognize as HIPAA) did not emerge until some years later.

The Federal regulations provide a “floor of privacy protections” that covered entities – and, where applicable, business associates – are required to comply with unless a provision of state law provides more stringent privacy protections for individually identifiable health information or more patients’  rights. Most states also now have their own breach notification regulations which may preempt HIPAA if HIPAA covered entities are not exempted from compliance.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

It can also sometime be the case that provisions of “Healthcare HIPAA” (the Administrative Simplification Regulations) conflict with the provisions of other Federal laws – for example, the Privacy Act and the Family Education Rights and Privacy Act (FERPA). In these cases, which law it is necessary to comply with is case specific – although the HIPAA regulations are frequently being updated to address conflicts and potential contradictions.

Is HIPAA a Federal Law? Summary

  • HIPAA is a Federal law, but “Healthcare HIPAA” consists of Federal regulations.
  • State laws with more stringent privacy and rights’ provisions preempt HIPAA.
  • Where conflicts exist with other Federal laws, which law takes precedence is case specific.
  • The HIPAA regulations are frequently updated to address conflicts and potential contradictions.
  • Covered entities are advised to seek professional advice if they are unsure which regulations/laws apply.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/