The Health Insurance Portability and Accountability Act (HIPAA) lays out three rules for protecting
patient health information
-
The Privacy Rule
-
The Security Rule
-
The Breach Notification Rule
The Privacy Rule defines “Protected Health Information” (PHI) as: all "individually identifiable health
information" held or transmitted by a covered entity or its business associate, in any form or media, whether
electronic, paper, or oral.