The Law With Two Names That Every Healthcare Worker Should Know
I was running a compliance workshop for a hospital system in Atlanta when a new office manager raised her hand and asked, "Wait — is HIPAA the same thing as the Kennedy-Kassebaum Act?" Half the room looked confused. The other half had never even heard the second name.
She was right. HIPAA is also referred to as the Kennedy-Kassebaum Act, named after the two senators who championed it: Edward Kennedy of Massachusetts and Nancy Kassebaum of Kansas. The law's full title is the Health Insurance Portability and Accountability Act of 1996. But knowing its name is just the start — understanding what it actually requires is where most organizations fall short.
If you've ever searched "HIPAA is also referred to as the" something else, you're probably trying to connect the dots between the law's origins and what it demands from your organization today. That's exactly what this post delivers — the history, the structure, and the real-world consequences of getting it wrong.
Why Congress Passed the Kennedy-Kassebaum Act in the First Place
Before 1996, the American healthcare system had a massive gap. Workers who changed jobs or lost employment often couldn't get health insurance because of pre-existing conditions. There was no federal standard for protecting patient health information. Medical records were governed by a patchwork of state laws — some strong, most weak.
Senators Kennedy and Kassebaum introduced the bill to solve two problems at once: insurance portability and healthcare accountability. The "portability" piece meant people could carry their insurance coverage between jobs. The "accountability" piece laid the groundwork for what we now know as the Privacy Rule, the Security Rule, and the Breach Notification Rule.
President Clinton signed it into law on August 21, 1996. You can read the full text and regulatory guidance on HHS.gov.
What Most People Get Wrong About HIPAA's Original Purpose
Here's something I see constantly: people assume HIPAA was always a privacy law. It wasn't — at least not primarily. The original statute focused heavily on insurance reform. Titles I through V cover everything from healthcare access to tax provisions to group health plan requirements.
Title II is where things get interesting for compliance professionals. That's the Administrative Simplification section, which directed HHS to develop standards for electronic healthcare transactions, unique health identifiers, and — critically — the security and privacy of protected health information (PHI).
The Privacy Rule didn't become effective until April 2003. The Security Rule followed in April 2005 for most covered entities. So the law everyone associates with patient privacy actually spent its first seven years focused mainly on insurance portability.
The Five Titles of HIPAA at a Glance
- Title I: Health Care Access, Portability, and Renewability — protects insurance coverage for workers who change or lose jobs.
- Title II: Administrative Simplification — establishes national standards for electronic transactions, privacy, and security of PHI and ePHI.
- Title III: Tax-Related Health Provisions — covers medical savings accounts and other tax matters.
- Title IV: Group Health Plan Requirements — further defines coverage and access requirements.
- Title V: Revenue Offsets — addresses company-owned life insurance and other provisions.
What Does HIPAA Actually Require From Your Organization?
If you're a covered entity — a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically — HIPAA requires you to do several specific things. Business associates who handle PHI on your behalf carry many of the same obligations.
Here's the short list that matters most in day-to-day operations:
- Protect PHI and ePHI through administrative, physical, and technical safeguards as defined in the Security Rule.
- Provide patients with rights over their health information, including access, amendment, and accounting of disclosures under the Privacy Rule.
- Train your entire workforce — not just clinical staff — on HIPAA policies and procedures. This includes front desk staff, IT, billing, and volunteers.
- Report breaches to affected individuals, HHS, and in some cases the media, following the Breach Notification Rule timelines.
- Maintain documentation of policies, risk assessments, training records, and business associate agreements for at least six years.
If your team needs a structured path through these requirements, the HIPAA training catalog at HIPAACertify covers each rule with role-specific courses designed for real-world application.
The $16 Million Reminder That Names Don't Matter — Compliance Does
Whether you call it HIPAA or the Kennedy-Kassebaum Act, the Office for Civil Rights (OCR) enforces it the same way. And the penalties are not theoretical.
In 2018, Anthem Inc. paid $16 million to settle HIPAA violations after a massive data breach exposed the ePHI of nearly 79 million people. OCR's investigation found that Anthem had failed to conduct an enterprise-wide risk analysis — one of the most basic Security Rule requirements. You can review the details on the HHS enforcement page for Anthem.
That $16 million wasn't a fine for a sophisticated failure. It was the price of skipping the fundamentals.
I've seen the same pattern in smaller organizations. A 2023 OCR settlement with Banner Health for $1.25 million also centered on risk analysis failures and insufficient monitoring. The scale differs. The root cause doesn't.
HIPAA Is Also Referred to as the Foundation of Modern Health Privacy
The Kennedy-Kassebaum Act didn't just create a set of rules. It created the framework that every subsequent healthcare privacy regulation has built upon. The HITECH Act of 2009 expanded HIPAA's reach to business associates and strengthened breach notification requirements. The 2013 Omnibus Rule refined definitions, tightened enforcement, and increased penalties.
In 2026, proposed updates to the HIPAA Security Rule are pushing organizations toward even more rigorous cybersecurity standards — including mandatory encryption and more specific incident response requirements. The law that Kennedy and Kassebaum introduced thirty years ago continues to evolve.
Your compliance program needs to evolve with it.
How the HITECH Act Changed HIPAA's Teeth
Before HITECH, OCR had limited enforcement power and penalties were modest. HITECH introduced a tiered penalty structure that maxes out at $2,067,813 per violation category per year (adjusted for inflation). It also gave state attorneys general the authority to bring HIPAA enforcement actions — a game-changer for accountability.
HITECH also created the Breach Notification Rule, requiring covered entities to notify affected individuals within 60 days of discovering a breach involving unsecured PHI. Breaches affecting 500 or more individuals get posted on HHS's public breach portal — often called the "Wall of Shame."
What Your Workforce Training Program Should Actually Cover
Knowing that HIPAA is also referred to as the Kennedy-Kassebaum Act is a nice trivia fact. But what OCR auditors actually look for is proof that your workforce understands and applies the rules.
Effective training programs go beyond reading a slide deck once a year. They cover:
- What counts as PHI and ePHI — and how to handle both in daily workflows.
- The minimum necessary standard — only accessing or sharing the PHI needed for a specific task.
- How to recognize and report a potential breach internally before it becomes a reportable incident.
- Role-specific scenarios: what a billing specialist needs to know differs from what an IT administrator needs.
- Physical safeguards like workstation positioning, locked storage, and visitor protocols.
If your current program doesn't address these specifics, explore the role-based HIPAA training courses at HIPAACertify to fill the gaps before your next audit cycle.
Frequently Asked: What Is HIPAA Also Known As?
HIPAA is also referred to as the Kennedy-Kassebaum Act, after its co-sponsors Senator Edward Kennedy (D-MA) and Senator Nancy Kassebaum (R-KS). Its official name is the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191). The law established federal standards for health insurance portability, electronic healthcare transactions, and the privacy and security of protected health information.
Stop Memorizing Acronyms — Start Building Compliance
I've audited organizations that could recite HIPAA's history chapter and verse but couldn't produce a current risk assessment. I've seen others that didn't know what the Kennedy-Kassebaum Act was but had bulletproof safeguards, trained staff, and documented policies for every contingency.
OCR doesn't give points for historical knowledge. They look at what you've built, what you've documented, and whether your people know what to do when something goes wrong.
The name on the law matters less than whether your organization lives up to its requirements. That starts with understanding the rules, training your workforce, and treating compliance as an operational discipline — not an annual checkbox.