HIPAA

Statute United States · 1996

HIPAA is the 1996 US law that governs the privacy and security of protected health information (PHI). Its Privacy Rule sets the terms under which PHI may be used and disclosed and grants patients a right of access to their own records (§164.524); its Security Rule mandates administrative, physical, and technical safeguards for electronic PHI. Enforced by the HHS Office for Civil Rights, HIPAA is the legal and ethical baseline every US healthcare API operates under — and the reason consent is not a nicety but a foundation.

Sectoral regime. It binds the industries below; companies outside them generally fall outside it.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.

Implemented by these standards

A regulation is the law; a standard is the machine-readable contract that satisfies it. Almost every regime in this catalog restricts an interface rather than requiring one — where a standard exists, it is the part a provider can actually publish.