Module 01 · Free · 5:33
HIPAA Fundamentals
The history of HIPAA, the two federal bodies that enforce it, the two main Rules, and the vocabulary every workforce member should be able to define — PHI, ePHI, encryption, breach, covered entity, business associate.
This module walks through what HIPAA is, how it evolved from the 1996 statute through HITECH (2009) and the Omnibus Rule (2013), the two federal bodies that enforce it, and the specific vocabulary every workforce member should be able to define — PHI, ePHI, encryption, breach, covered entity, and business associate. It is the foundational context every subsequent module builds on.
Regulatory anchors
- 45 CFR §160.103
- HITECH Act (Pub. L. 111–5)
- Omnibus Rule (78 FR 5566)
Hosted on the Patient Protect YouTube channel
What is HIPAA? Everything Your Practice Needs to Know
Learning objectives
What the workforce should be able to do after this module.
- Understand the history of HIPAA — the 1996 origin, the 2009 HITECH Act, and the 2013 Omnibus Rule — and why each was enacted
- Define and understand the key HIPAA terminology used across the rest of the series (PHI, ePHI, encryption, breach, covered entity, business associate)
- Differentiate between the Privacy Rule and the Security Rule and understand the role each plays
Assessment: 5 knowledge-check questions per module, 80% passing standard.
Module outline
Section-by-section walkthrough.
01
The evolution of HIPAA — 1996, 2009, 2013
HIPAA (Health Insurance Portability and Accountability Act) was passed in 1996 to protect the communication and disclosure of health information. The HITECH Act (2009) extended liability to Business Associates, increased breach penalties, and made breach reporting mandatory. The Omnibus Rule (2013) finalized HITECH — updated BAA requirements, mandated electronic encryption, expanded patient rights over PHI, and prohibited marketing and sales of patient information.
02
HHS and OCR — the enforcement bodies
The Department of Health and Human Services (HHS) and its Office for Civil Rights (OCR) are the federal bodies that implement and enforce HIPAA. They determine fees, conduct audits, and issue penalties. Both are at record levels due to the growth of tech in patient care and the misuse of ePHI.
03
The two main HIPAA Rules — Privacy and Security
The Privacy Rule ensures rules, regulations, and physical privacy restrictions are in place for PHI and ePHI, and gives patients the right to access, control, and request changes to their information. The Security Rule ensures technical security measures — including data encryption and secure platforms — are in place to protect ePHI in transit and at rest.
04
PHI vs ePHI
PHI (Protected Health Information) is any patient health information the covered entity maintains. ePHI (electronic Protected Health Information) is that information in electronic form. The Privacy Rule covers all PHI; the Security Rule covers ePHI specifically.
05
Encryption — what it is and why it matters
Encryption converts readable text into unreadable text while data is at rest and in transit, protecting against breaches. It is a foundational safeguard under the Security Rule and one of the two conditions (along with proper destruction) that renders PHI "secured" under the Breach Notification Rule.
06
What is a breach?
A breach is when confidential information — PHI or ePHI — is compromised through a cyberattack or security neglect, or when an unauthorized source has gained access to patient information. HIPAA exists to prevent breaches and protect patient confidentiality.
07
Covered Entities (CE) — the three types
A Covered Entity is a provider that electronically transmits health information. There are three types: Healthcare Providers (doctors, dentists, therapists), Health Plans (insurance companies), and Healthcare Clearinghouses (entities that process nonstandard health information into standard formats).
08
Business Associates (BA)
HHS defines a Business Associate as a person or entity that performs certain functions or activities involving the use or disclosure of protected health information on behalf of — or provides services to — a covered entity. Vendors that touch PHI require a signed Business Associate Agreement (BAA).
Sample knowledge check
A representative question from this module.
Sample question · 5 per module in the live series
Which of the following statements about the evolution of HIPAA is correct?
- A.HIPAA was passed in 1996; the 2009 HITECH Act extended liability to Business Associates and made breach reporting mandatory; the 2013 Omnibus Rule mandated encryption and expanded patient rights.
- B.HIPAA was passed in 2009 as part of the HITECH Act.
- C.The Omnibus Rule replaced HIPAA and is the only federal law that applies today.
- D.Business Associates were only made liable for HIPAA violations after the 2013 Omnibus Rule.
Show explanation
Correct answer: A. HIPAA was enacted in 1996. HITECH (2009) extended liability to Business Associates and required breach reporting. The Omnibus Rule (2013) finalized HITECH by updating BAA requirements, mandating encryption, and expanding patient rights.
Module 01 of the HIPAA Foundations series
Every learner. Every module. One office price.
When you are ready to train the whole practice, the complete 19-module HIPAA Foundations series unlocks for up to 25 personnel at $39/office/month — with per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
