A Single Stolen Laptop Started It All

In 2013, Advocate Medical Group in Illinois lost four million patient records because of unencrypted laptops. The settlement? $5.55 million paid to the Office for Civil Rights. That case is a perfect illustration of what happens when an organization doesn't understand what is the function of HIPAA — and what it costs to ignore it.

If you've ever Googled that phrase, you're probably trying to cut through the legal jargon. Maybe you're new to healthcare. Maybe your compliance officer just handed you a stack of policies and said "read these." Either way, I've spent years helping organizations answer this exact question, and I'm going to give you the version I wish someone had given me when I started.

HIPAA exists for one overarching purpose: to create enforceable national standards for protecting individuals' health information while still allowing the flow of data needed to deliver and pay for quality healthcare. That's it. Everything else — the Privacy Rule, the Security Rule, the Breach Notification Rule — is a mechanism for achieving that single purpose.

What Is the Function of HIPAA in Plain English?

HIPAA — the Health Insurance Portability and Accountability Act of 1996 — does two things that most people don't realize are connected. First, it made it easier for workers to keep health insurance when they changed jobs (the "portability" part). Second, it required HHS to develop regulations protecting the privacy and security of protected health information, or PHI.

Over time, the second function swallowed the first in terms of public attention. When someone asks what is the function of HIPAA today, they're almost always asking about data protection. And that's where the rubber meets the road for your organization.

The Five Core Functions

  • Privacy protection: The Privacy Rule limits who can access, use, and disclose PHI. It gives patients rights over their own records — the right to access, amend, and receive an accounting of disclosures.
  • Security standards: The Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI). Think encryption, access controls, audit logs.
  • Breach notification: When a breach of unsecured PHI occurs, HIPAA mandates that covered entities notify affected individuals, HHS, and in some cases the media — within specific timeframes.
  • Portability: HIPAA limits exclusions for pre-existing conditions, prohibits discrimination based on health status, and guarantees renewability of coverage in certain markets.
  • Administrative simplification: HIPAA standardized electronic transactions like claims, enrollment, and eligibility inquiries — saving the healthcare system billions in administrative waste.

Who Has to Follow These Rules?

HIPAA applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. It also applies to business associates: any vendor, contractor, or partner that handles PHI on behalf of a covered entity.

I've seen startups assume HIPAA doesn't apply to them because they're "just a tech company." If you're processing claims data, storing patient records, or building an app that touches ePHI, you're likely a business associate. And HIPAA's teeth are just as sharp for you.

The $16 Million Wake-Up Call

Anthem Inc. paid $16 million to OCR in 2018 — the largest HIPAA settlement in history at the time — after a cyberattack exposed nearly 79 million records. The investigation found that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient access controls, and lacked proper monitoring. You can review this and other enforcement actions on the HHS enforcement outcomes page.

That case didn't happen because Anthem had malicious intent. It happened because they had gaps in the foundational functions HIPAA requires: risk analysis, safeguards, and workforce oversight. In my experience, most violations stem from the same root causes — not criminal behavior, but neglect.

How OCR Enforces the Function of HIPAA

The Office for Civil Rights within HHS is HIPAA's enforcement arm. They investigate complaints, conduct compliance reviews, and issue penalties that range from $100 per violation to over $2 million per violation category per year. The penalty tiers depend on the level of culpability — from "did not know" all the way up to "willful neglect, not corrected."

Since 2003, OCR has received over 350,000 complaints and resolved the vast majority through corrective action rather than fines. But the fines they do issue make headlines for a reason. They're designed to make noncompliance more expensive than compliance.

The Penalty Tiers You Need to Know

  • Tier 1: Unaware of violation — $100 to $50,000 per incident
  • Tier 2: Reasonable cause (not willful neglect) — $1,000 to $50,000 per incident
  • Tier 3: Willful neglect, corrected within 30 days — $10,000 to $50,000 per incident
  • Tier 4: Willful neglect, not corrected — $50,000 per incident (annual cap applies)

You can review the full penalty structure in the Code of Federal Regulations at 45 CFR Part 160, Subpart D.

The Function Most Organizations Get Wrong: Workforce Training

Here's what I tell every client on day one: HIPAA's function isn't just about firewalls and encryption. It's about people. The Privacy Rule at 45 CFR §164.530(b) requires covered entities to train all workforce members on policies and procedures relevant to their job functions.

"All workforce members" means everyone. Not just clinicians. Your front desk staff. Your billing team. Your janitorial crew if they have access to areas where PHI is stored. I've seen organizations get tripped up because they trained the nurses but forgot the medical assistants.

The training can't be a one-and-done event either. It needs to happen at onboarding and whenever material changes occur. If your organization hasn't refreshed its training content for 2026, you're already behind. Our HIPAA Introduction Training for 2026 covers the core functions your workforce needs to understand — from PHI handling to breach notification obligations.

What Does HIPAA Actually Protect?

PHI includes any individually identifiable health information held or transmitted by a covered entity or its business associate. That covers 18 specific identifiers, including names, Social Security numbers, dates of birth, medical record numbers, and even IP addresses when linked to health data.

The protection extends to every format: paper records in a file cabinet, ePHI on a server, verbal disclosures across a waiting room. I've investigated incidents where a nurse discussed a patient's diagnosis in a hospital elevator with visitors standing two feet away. That's a potential HIPAA violation — no hacking required.

The Minimum Necessary Standard

One of HIPAA's most practical functions is the minimum necessary standard. It requires covered entities to make reasonable efforts to limit PHI access to the minimum amount needed to accomplish the task at hand. Your billing department doesn't need access to clinical notes. Your IT team doesn't need to read diagnosis codes.

This principle should drive every access control decision in your organization. If you can't explain why a specific role needs access to a specific data set, you probably shouldn't grant it.

HIPAA's Function in the Age of Telehealth and AI

HIPAA was written in 1996, but its framework is surprisingly durable. The Security Rule's requirement for risk analysis doesn't name specific technologies — it requires you to evaluate threats to ePHI regardless of the platform. That means your telehealth vendor, your AI-powered transcription tool, and your cloud-based EHR all fall under the same umbrella.

What's changed is the attack surface. Remote workforces, mobile devices, and third-party integrations have multiplied the ways PHI can be exposed. The function of HIPAA hasn't changed. But the work required to fulfill that function has grown exponentially.

If your team is navigating these complexities, structured training is the fastest way to close knowledge gaps. Explore our full HIPAA training catalog to find courses that match your organization's risk profile.

Three Things to Do This Week

Understanding what is the function of HIPAA is step one. Here's how to turn that understanding into action:

  • Run a risk analysis. If you haven't completed one in the past 12 months, you're out of compliance. OCR has cited inadequate risk analysis in nearly every major settlement.
  • Audit workforce training records. Verify that every current workforce member has completed HIPAA training — and that the content reflects 2026 regulatory guidance.
  • Review your business associate agreements. Every vendor that touches PHI needs a signed BAA. No exceptions, no handshake deals.

HIPAA's function is straightforward: protect people's health information while letting the healthcare system work. The execution is where organizations stumble. Don't wait for an OCR investigation to find the gaps. Find them yourself, fix them, and train your people to keep them fixed.