HIPAA
HIPAA sets US rules for protecting health information — including a required security awareness and training program for the entire workforce.
HIPAA (the Health Insurance Portability and Accountability Act of 1996) is the US law governing how protected health information (PHI) must be handled. Its Security Rule applies to covered entities — healthcare providers, health plans, clearinghouses — and their business associates, and requires administrative, physical and technical safeguards for electronic PHI. Enforcement sits with the HHS Office for Civil Rights, which can impose civil monetary penalties per violation category and publishes breach investigations on its public "wall of shame" for incidents affecting 500 or more people.
How it works
HIPAA is directly relevant to human risk because it is one of the few laws that names workforce training explicitly. The Security Rule's administrative safeguards (45 CFR §164.308(a)(5)) require a "security awareness and training program for all members of its workforce" — including management — with addressable specifications for security reminders, protection from malicious software, log-in monitoring and password management. The Breach Notification Rule then puts a clock on failure: breaches of unsecured PHI must be reported to affected individuals and HHS, within 60 days of discovery for larger incidents.
Attackers know exactly where the weak point is. Healthcare is a persistent top target for phishing, stolen credentials and social engineering, because PHI is valuable, clinical staff are busy and interruption-driven, and downtime pressure makes organizations more likely to pay extortion.
How to defend against it
Treat §164.308(a)(5) as a floor, not the program. An annual slideshow technically satisfies a checkbox but leaves the phishing failure rates that cause real breaches untouched. A defensible program looks like the one regulators increasingly expect under GDPR and NIS2 as well — the overlap is covered in our guide to what data-protection law requires of awareness training: role-based, continuous training with simulation-based practice, documented completion and measured outcomes, so that when an incident is investigated you can show the program existed, ran and worked.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo