HIPAA
HIPAA (the Health Insurance Portability and Accountability Act) is the US federal law that imposes privacy and security requirements on protected health information (PHI) and the covered entities and business associates that handle it.
What HIPAA Requires
HIPAA's Privacy Rule governs use and disclosure of protected health information. The Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for electronic PHI. The Breach Notification Rule requires notification of affected individuals, HHS, and in some cases the media when unsecured PHI is breached.
Covered entities include healthcare providers, health plans, and healthcare clearinghouses. Business associates include vendors who handle PHI on behalf of covered entities, which sweeps in a large range of technology and service providers.
HIPAA Enforcement
Enforcement runs through HHS Office for Civil Rights. Civil monetary penalties are tiered by culpability level, ranging from a minimum per-violation amount to substantial annual caps in the highest tier. Enforcement actions have increased in recent years, particularly around ransomware incidents affecting PHI.
HIPAA in Quantified Programs
For healthcare organizations and their business associates, HIPAA-driven exposure is a significant scenario in CRQ models. Penalty distributions calibrate against observed HHS settlements, adjusted for organization size, incident severity, and remediation posture. Notification and remediation costs are typically modeled separately from regulatory penalty exposure.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.






