Health Insurance Portability and Accountability Act
HIPAA is a U.S. federal law passed in 1996 that sets standards for protecting sensitive patient health information and also addresses the ability to transfer and continue health insurance coverage. It regulates how certain organizations handle, use, and disclose protected health information (PHI). It applies within the United States and is not a global standard.
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a U.S. federal statute that establishes federal standards for protecting sensitive health information and reforms aspects of the health insurance industry, including the portability and continuity of coverage. Its regulatory standards govern the lawful use and disclosure of protected health information (PHI). In a third-party risk context, HIPAA obligations typically extend to covered entities and their vendors that handle PHI, meaning organizations may need to assess suppliers for HIPAA-relevant safeguards; however, HIPAA addresses health information privacy and security within U.S. jurisdiction and does not, by itself, cover financial, operational, geopolitical, or broader ESG risk categories. Note that HIPAA sets requirements rather than conferring a certification, and adherence is generally demonstrated through compliance programs rather than a single attestation.
Why it matters
HIPAA matters to third-party risk professionals because its obligations do not stop at the boundary of the organization that first collects protected health information (PHI). When a covered entity engages vendors that handle PHI on its behalf, HIPAA-relevant safeguards typically become a consideration in how those suppliers are assessed, contracted, and monitored. This makes HIPAA a recurring reference point in vendor due diligence for organizations operating in or servicing the U.S. healthcare sector, where a supplier's handling of health information can create exposure that flows back to the engaging organization.
It is important to be precise about what HIPAA does and does not cover. HIPAA addresses the privacy and security of health information within U.S. jurisdiction; it is not a global standard, and it does not by itself cover financial, operational, geopolitical, or broader ESG risk categories that a comprehensive third-party risk program must also evaluate. Treating HIPAA as a proxy for overall vendor risk would leave material risk categories unaddressed.
A further point of care for expert readers: HIPAA sets requirements rather than conferring a certification. Adherence is generally demonstrated through ongoing compliance programs rather than a single attestation, so a vendor's claim of being "HIPAA compliant" is a self-representation that typically warrants verification rather than acceptance at face value. Because such representations can be point-in-time and self-reported, they may not reflect a supplier's current safeguards without independent validation and ongoing monitoring.
Who it's relevant to
Inside HIPAA
Common questions
Answers to the questions practitioners most commonly ask about HIPAA.
