HIPAA
HIPAA (Health Insurance Portability and Accountability Act) is a US federal law from 1996 that, among other provisions, establishes national standards for protecting the privacy and security of individuals' health information. Its Privacy Rule and Security Rule govern how Protected Health Information (PHI) — any individually identifiable health data — may be used, disclosed, and safeguarded by covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates, meaning vendors that handle PHI on their behalf, who must sign Business Associate Agreements and carry direct compliance obligations. Enforcement by the HHS Office for Civil Rights includes breach investigation and penalties tiered by culpability, reaching millions of dollars in serious cases, plus mandatory breach notification to affected individuals and regulators. Two practical intersections matter for HR and L&D. First, HIPAA training is legally required: covered entities and business associates must train workforce members on privacy and security policies, at onboarding and after material changes, and document that training — a canonical compliance use case for an LMS, with role-based assignment, recurring refreshers, and audit-ready completion records. Second, a nuance HR teams often get wrong: employment records held by an employer, including sick notes and leave documentation, are generally not PHI under HIPAA — but health data flowing through employer-sponsored health plans is, and mixing the two creates avoidable compliance risk.