Skip to content
FonteumPublic-records evidence
Fonteum Data GlossaryRegulatory

HIPAA: Definition and Healthcare Context

Full name: Health Insurance Portability and Accountability Act

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that established national standards for the privacy and security of individually identifiable health information and for electronic health care transactions. HIPAA's Administrative Simplification provisions mandate standard transaction formats (including NPI), require privacy protections for Protected Health Information (PHI), and establish security safeguards for electronic PHI. HHS's Office for Civil Rights enforces the HIPAA Privacy and Security Rules.

Source file
Not reported
Published
Not reported
Retrieved
Not reported
Snapshot
Not retained for this reference page
Data as of
Not reported
Last updated: 2026-07-11Reviewed by: Dr. Jennifer Montecillo, MDGullas College of Medicine, 2019. Non-practicing medical reviewer.

How it’s used

  • CMS NPPES NPI Registry: the NPI itself is a HIPAA Administrative Simplification requirement — HIPAA mandated a standard provider identifier, which became the NPI.
  • CMS PECOS Medicare Provider Enrollment: HIPAA-covered entities must use NPI on all standard transactions, making PECOS enrollment a prerequisite for Medicare billing.

Frequently asked questions

What does HIPAA stand for?
HIPAA stands for Health Insurance Portability and Accountability Act, a 1996 federal law establishing standards for health data privacy, security, and electronic transactions.
Who must comply with HIPAA?
Covered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically — and their business associates must comply with HIPAA.
What does HIPAA protect?
HIPAA's Privacy Rule protects Protected Health Information (PHI) — individually identifiable health information held by covered entities.

What’s on file, by the numbers

Platform snapshot · 2026-08-30

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
16fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access