What Is 42 USC 1320d? Definitions, Compliance & Penalties

Section 1320d of Title 42 of the US Code is the definitions provision of HIPAA’s Administrative Simplification subchapter. It sets the vocabulary — health information, individually identifiable health information, health plan, healthcare clearinghouse — that the rest of HIPAA is built on. Those definitions feed directly into the Privacy Rule, the Security Rule, the Breach Notification Rule, and the civil and criminal penalties that govern how hospitals, insurers, billing companies, and their contractors handle patient data.

What 42 USC 1320d Actually Defines

Health information is any data, spoken or recorded in any format, that relates to a person’s past, present, or future health condition, the care they received, or payment for that care, as long as it was created or received by a healthcare provider, health plan, employer, public health authority, or similar entity.1Office of the Law Revision Counsel. 42 US Code 1320d – Definitions The definition is deliberately broad. A lab result, a therapy session note, and a billing statement all qualify.

Individually identifiable health information is a narrower subset: health information that either identifies the person or could reasonably be used to identify them.1Office of the Law Revision Counsel. 42 US Code 1320d – Definitions The statute itself doesn’t list identifiers, but the Privacy Rule regulations name 18, including names, dates of birth, Social Security numbers, and medical record numbers. Once health information carries any of those identifiers, it becomes protected health information (PHI), and HIPAA’s full privacy and security requirements attach.

The statute also defines health care clearinghouse as any entity that converts nonstandard health data into a standard electronic format, and health plan to cover individual and group insurance plans, HMOs, Medicare, Medicaid, and similar programs. A companion provision, 42 USC 1320d-2, tells the Secretary of HHS to adopt uniform standards for electronic transactions like claims processing, payment, and eligibility checks.2Office of the Law Revision Counsel. 42 US Code 1320d-2 – Standards for Information Transactions and Data Elements Those standards are what force the healthcare system to speak a common electronic language.

Who Has to Comply

The definitions in 1320d flow into HIPAA’s regulations, which identify three categories of “covered entity” that must follow the Privacy, Security, and Breach Notification Rules.3eCFR. 45 CFR 160.103 – Definitions

  • Healthcare providers who transmit any health information electronically in connection with a covered transaction — hospitals, physician practices, pharmacies, dentists, chiropractors, and labs that submit electronic claims or verify insurance eligibility.
  • Health plans, including private insurers, employer-sponsored group plans, Medicare, Medicaid, and HMOs. A group health plan with fewer than 50 participants that the employer administers itself is not treated as a covered entity.4HHS.gov. Summary of the HIPAA Privacy Rule
  • Healthcare clearinghouses that translate nonstandard formats into standardized electronic ones for billing and claims.

If a provider handles everything on paper and never transmits an electronic transaction, HIPAA’s Administrative Simplification rules technically don’t reach them. In practice, that scenario has nearly disappeared.

Business Associates

Covered entities routinely hire outside companies to handle functions involving PHI: billing services, cloud storage providers, IT contractors, attorneys reviewing medical records. Those companies become business associates, and before any PHI changes hands, a written business associate agreement must spell out how the data will be used, safeguarded, and returned or destroyed.

The HITECH Act of 2009 extended the Security Rule directly to business associates and made them subject to the same civil and criminal penalties as covered entities.5Office of the Law Revision Counsel. 42 US Code 17931 – Application of Security Provisions and Penalties to Business Associates HHS can act against a business associate that fails to comply with the Security Rule, fails to report a breach, improperly uses or discloses PHI, or retaliates against someone who files a HIPAA complaint. Business associates that hire subcontractors must put agreements in place with them too, and the chain of responsibility runs all the way down.6HHS.gov. Direct Liability of Business Associates

What Compliance Requires

Privacy Rule

The Privacy Rule, in 45 CFR Part 164 Subparts A and E, governs how covered entities use and share PHI. The baseline is simple: PHI cannot be used or disclosed except as the rule specifically permits. Three purposes need no authorization — treatment, payment, and healthcare operations.7HHS.gov. Uses and Disclosures for Treatment, Payment, and Health Care Operations Certain other disclosures are also allowed without patient consent, including those required by law, public health reporting, and specific law-enforcement situations.8eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required Anything outside those categories requires the patient’s written authorization.

Even a permitted disclosure carries limits. Covered entities must make reasonable efforts to share only the minimum amount of information needed for the purpose at hand.9eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information The minimum-necessary standard does not apply to disclosures for treatment, disclosures to the patient, disclosures the patient has authorized, or disclosures required by law.

Patients also have concrete rights over their own data. The most practical is the right to inspect and obtain a copy of PHI held in a covered entity’s designated record set — medical records, billing records, enrollment or claims data — and to direct that a copy be sent to someone else.10HHS.gov. Individuals’ Right Under HIPAA to Access Their Health Information The covered entity has 30 days to respond, with one 30-day extension available if it notifies the patient in writing. Psychotherapy notes kept separate from the medical record, and information compiled in anticipation of litigation, sit outside the access right.11eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information

Security Rule

The Security Rule, at 45 CFR Part 164 Subpart C, applies to electronic PHI and requires covered entities and business associates to protect its confidentiality, integrity, and availability through administrative, physical, and technical safeguards.12eCFR. 45 CFR Part 164 Subpart C – Security Standards for the Protection of Electronic Protected Health Information13HHS.gov. The Security Rule That means written policies, workforce training, designated security officers, and periodic risk analyses; controlled facility and workstation access and secure disposal of hardware; and access controls, encryption, audit logs, and user authentication. OCR guidance has highlighted multi-factor authentication as a best practice, since weak authentication has driven many recent healthcare breaches.14HHS.gov. June 2023 OCR Cybersecurity Newsletter The rule does not mandate specific technologies, but it does require regular risk analyses and updates as threats change.

Breach Notification

When unsecured PHI is compromised, notifications cascade on strict deadlines. A covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach, describing what happened, what information was involved, protective steps the individual can take, and what the organization is doing.15eCFR. 45 CFR 164.404 – Notification to Individuals If a breach affects 500 or more people, HHS must be notified at the same time; smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year in which they were discovered.16eCFR. 45 CFR 164.408 – Notification to the Secretary Breaches affecting more than 500 residents of a single state or jurisdiction also trigger notice to prominent local media.17HHS.gov. Breach Notification Rule A business associate that discovers a breach has 60 calendar days to notify the covered entity, and missing that deadline is itself an enforceable violation.18eCFR. 45 CFR 164.410 – Notification by a Business Associate

Civil Penalties Under 42 USC 1320d-5

Civil monetary penalties follow a four-tier structure based on the violator’s level of awareness and whether the problem was fixed. The statutory base amounts sit in 42 USC 1320d-5, and HHS adjusts them each year for inflation.19GovInfo. 42 USC 1320d-5 – General Penalty for Failure to Comply With Requirements and Standards The 2026 inflation-adjusted figures, effective for penalties assessed on or after January 28, 2026, are:20Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Did not know, and could not have known with reasonable diligence: $145 to $73,011 per violation, up to $2,190,294 per calendar year for identical violations.
  • Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, with a $2,190,294 annual cap.

The jump between tiers is sharp. An organization that genuinely didn’t know about a violation starts at $145; one that knew and didn’t fix it starts at $73,011 per violation, and the annual cap applies per identical provision, so different types of violations stack.

Criminal Penalties Under 42 USC 1320d-6

Section 1320d-6 targets individuals who knowingly obtain or disclose individually identifiable health information in violation of HIPAA. Penalties escalate in three tiers based on intent:21Office of the Law Revision Counsel. 42 US Code 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

  • Knowing violation: up to $50,000 in fines and up to one year in prison.
  • Violation under false pretenses: up to $100,000 and up to five years.
  • Violation with intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm: up to $250,000 and up to ten years.

The Department of Justice, not HHS, prosecutes these cases. They tend to involve the most egregious conduct: employees snooping through the records of celebrities or ex-partners, insiders selling patient data, or schemes to use stolen medical identities for fraudulent billing. The statute reaches any person who accessed or disclosed the information without authorization, as long as it was maintained by a covered entity, not only employees.

How Enforcement Works in Practice

Most enforcement begins with a complaint or a breach report reaching the HHS Office for Civil Rights. Anyone can file a complaint alleging noncompliance by a covered entity or business associate.22eCFR. 45 CFR 160.306 – Complaints to the Secretary OCR must investigate complaints where the facts suggest willful neglect, and has discretion to investigate others. Investigations look at the organization’s policies, its risk analyses, and whether it actually implemented the safeguards it claimed to have.

Most matters resolve informally through a corrective action plan: fix the problem, retrain staff, and report back over a monitoring period. When an organization refuses to cooperate or the violation is severe, OCR imposes civil monetary penalties under the tiered structure above.23eCFR. 45 CFR 160.404 – Amount of a Civil Money Penalty For criminal conduct, OCR refers the case to the Department of Justice. In practice, the heaviest penalties fall on organizations with large breaches, patterns of noncompliance, or basic failures like never conducting a risk analysis or leaving laptops unencrypted. A single accidental disclosure rarely ends in a fine.