← All terms

HIPAA

HIPAA sets US rules for protecting health information — including a required security awareness and training program for the entire workforce.

HIPAA (the Health Insurance Portability and Accountability Act of 1996) is the US law governing how protected health information (PHI) must be handled. Its Security Rule applies to covered entities — healthcare providers, health plans, clearinghouses — and their business associates, and requires administrative, physical and technical safeguards for electronic PHI. Enforcement sits with the HHS Office for Civil Rights, which can impose civil monetary penalties per violation category and publishes breach investigations on its public "wall of shame" for incidents affecting 500 or more people.

How it works

HIPAA is directly relevant to human risk because it is one of the few laws that names workforce training explicitly. The Security Rule's administrative safeguards (45 CFR §164.308(a)(5)) require a "security awareness and training program for all members of its workforce" — including management — with addressable specifications for security reminders, protection from malicious software, log-in monitoring and password management. The Breach Notification Rule then puts a clock on failure: breaches of unsecured PHI must be reported to affected individuals and HHS, within 60 days of discovery for larger incidents.

Attackers know exactly where the weak point is. Healthcare is a persistent top target for phishing, stolen credentials and social engineering, because PHI is valuable, clinical staff are busy and interruption-driven, and downtime pressure makes organizations more likely to pay extortion.

How to defend against it

Treat §164.308(a)(5) as a floor, not the program. An annual slideshow technically satisfies a checkbox but leaves the phishing failure rates that cause real breaches untouched. A defensible program looks like the one regulators increasingly expect under GDPR and NIS2 as well — the overlap is covered in our guide to what data-protection law requires of awareness training: role-based, continuous training with simulation-based practice, documented completion and measured outcomes, so that when an incident is investigated you can show the program existed, ran and worked.

Related terms

PCI DSSPCI DSS is the security standard for organizations handling card payments. Requirement 12.6 makes ongoing security awareness training mandatory.ISO 27001ISO/IEC 27001 is the international standard for information security management systems — and it makes security awareness a required, auditable control.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo