Table of Contents

Written by Justin Goodman, CIC, CISC, CLCS, CEO and Co-Founder, Total CSR
Published: August 3, 2026 · Last reviewed: August 3, 2026

In plain language: The 1996 Health Insurance Portability Act helps people keep health coverage when they change jobs, lose a job, or have a pre-existing medical condition. It limits how long a new employer’s health plan can deny coverage for conditions a person already had before enrolling.

Technical definition: The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a HIPAA law amending ERISA, the Internal Revenue Code, and the Public Health Service Act. This HIPAA definition encompasses federal standards that restrict pre-existing condition exclusion periods, require creditable coverage crediting, mandate guaranteed renewability for group plans, and establish national privacy regulations and security standards for protected health information (PHI).

1996 Health Insurance Portability Act at a Glance

AttributeDetail
Also known asHIPAA, Health Insurance Portability and Accountability Act, Kassebaum-Kennedy Act
CategoryFederal health insurance regulation
Lines of businessGroup health insurance, individual health insurance, employee benefits
Industries most affectedHealthcare providers, employee benefits administration, HR departments, health insurance carriers, health maintenance organizations (HMOs), healthcare clearinghouses
Related forms or endorsementsCertificate of Creditable Coverage (no longer required after ACA implementation)
Who bears the riskEmployers, group health plan sponsors, insurance carriers, and covered entities handling health data
Common solutionGroup health plan enrollment procedures, HIPAA privacy and security compliance programs
Also interacts withCOBRA, ERISA, Affordable Care Act, HITECH Act, state insurance codes

Key Takeaways

  • The 1996 Health Insurance Portability Act is a HIPAA law that protects workers’ access to health coverage during job transitions and sets federal standards for protecting personal health information privacy.
  • Agencies working with group health clients must understand HIPAA regulations including the Privacy Rule and HIPAA Security Rule because mishandling PHI during enrollment or claims processing creates direct legal liability for the agency.
  • A common misunderstanding is treating HIPAA as only privacy regulations; its original and equally important purpose was guaranteeing portability and limiting pre-existing condition exclusions, though the Affordable Care Act later eliminated most of those exclusion limits for major medical plans.
  • Agencies should maintain a written HIPAA privacy policy and train all workforce members who touch enrollment forms, claims data, medical records, or health questionnaires, since even small agencies handling group benefits are treated as covered entities or business associates under the law.

On This Page

  1. What Is the 1996 Health Insurance Portability Act in Insurance?
  2. How Does the 1996 Health Insurance Portability Act Work?
  3. Real Claim Examples Involving the 1996 Health Insurance Portability Act
  4. 1996 Health Insurance Portability Act vs. COBRA: What Is the Difference?
  5. What Are the Most Common Mistakes With the 1996 Health Insurance Portability Act?
  6. How to Explain the 1996 Health Insurance Portability Act to a Client
  7. Frequently Asked Questions About the 1996 Health Insurance Portability Act
  8. Related Insurance Terms
  9. Sources and References
  10. About the Author

What Is the 1996 Health Insurance Portability Act in Insurance?

The 1996 Health Insurance Portability Act is a federal statute, commonly called HIPAA, passed to solve a specific problem: workers who left a job often lost health coverage entirely or faced new waiting periods for pre-existing conditions when they enrolled in a new employer’s plan. Congress designed the HIPAA law to reduce “job lock,” the phenomenon of employees staying in jobs they wanted to leave solely to keep health coverage for a sick family member or chronic condition.

The law operates through two main pillars that agencies still deal with today. The portability pillar limited pre-existing condition exclusion periods to 12 months (18 for late enrollees) and required prior coverage to be credited against that waiting period, provided there was no gap of 63 days or more. The privacy and security pillar, added through later HIPAA regulations under HIPAA’s authority, created the Privacy Rule and HIPAA Security Rule governing how covered entities and business associates handle PHI and sensitive health information.

A worked example shows the original portability mechanism. An employee with diabetes leaves Employer A, where she had continuous group coverage for three years, and starts at Employer B two weeks later. Under HIPAA’s crediting rules, her prior three years of coverage offset any pre-existing condition exclusion period at Employer B’s plan, so the new plan could not deny diabetes-related claims during a waiting period. The Affordable Care Act later eliminated pre-existing condition exclusions for most major medical plans, but HIPAA’s privacy regulations and security framework remains fully active and is the piece agencies interact with most today.

How Does the 1996 Health Insurance Portability Act Work?

  1. The enrollment. A group health plan sponsor or carrier collects personal health information from an applicant during enrollment, triggering HIPAA’s status as a covered transaction involving PHI and medical records.
  2. The privacy notice. The plan or carrier issues a Notice of Privacy Practices explaining patient rights and how the applicant’s health information will be used, disclosed, and protected, satisfying the Privacy Rule’s notice requirement and providing an accounting of disclosures.
  3. The data handling. Anyone who touches that PHI, including the agency, the carrier, and any third-party administrator, must apply HIPAA’s minimum necessary standard and administrative safeguards, physical safeguards, and technical safeguards under the HIPAA Security Rule to protect e-PHI.
  4. The disclosure request. A patient, employer, law enforcement, or another party requests health information for purposes such as utilization review, public health activities, or health oversight activities, and the covered entity must verify authorization exists before releasing anything beyond what HIPAA permits without consent, such as treatment, payment, or healthcare operations.
  5. The breach or violation. Unauthorized disclosure of PHI or impermissible uses of sensitive health information triggers breach notification obligations to affected individuals and potentially the Department of Health and Human Services, along with possible civil monetary penalties and criminal penalties against the covered entity or business associate for HIPAA violations.

Real Claim Examples Involving the 1996 Health Insurance Portability Act

Agency employee emails health questionnaire to wrong recipient

A commercial lines account manager processing a small group health renewal accidentally emails a completed health history questionnaire, containing medical records of an employee’s cancer diagnosis, to an unrelated client instead of the carrier underwriter. The agency, acting as a business associate under its agreement with the carrier, faced a breach notification obligation to the affected employee and had to report the HIPAA violation under its HIPAA compliance program. The error stemmed from address auto-fill and no double-check procedure for documents containing PHI and sensitive health information.

Employer denies rehire based on medical history disclosed during benefits enrollment

An employee on medical leave applies for rehire after a layoff, and a manager who had seen her health plan enrollment forms references her diagnosis during the interview process. The applicant filed a complaint alleging the employer improperly used PHI obtained through the group health plan for an employment decision, representing impermissible uses that HIPAA does not permit without separate authorization. The case illustrated why HR and benefits administration functions must be firewalled from employment decision-makers and why disclosure policies must protect confidential communications.

Third-party administrator retains data past plan termination

A TPA administering a self-funded group health plan continued storing claims data with identifiable health information for two years after the employer terminated the plan, without proper disposal methods or a data destruction schedule required by its business associate agreement. When the employer’s new broker requested confirmation of data disposal during due diligence for a new carrier placement, the TPA could not produce documentation, exposing both parties to potential HIPAA violations and compliance findings.

1996 Health Insurance Portability Act vs. COBRA: What Is the Difference?

The 1996 Health Insurance Portability Act and COBRA continuation coverage are both federal laws addressing coverage gaps after employment changes, but they solve different problems. HIPAA governs pre-existing condition limits, coverage crediting, and health information privacy regulations, while COBRA gives departing employees the right to temporarily purchase continued coverage under the former employer’s group plan at their own expense.

Comparison area1996 Health Insurance Portability ActCOBRA
Primary use caseLimiting pre-existing condition exclusions and protecting health data privacy through HIPAA regulationsAllowing temporary continuation of group coverage after a qualifying event
Coverage / concept typeFederal regulatory framework with privacy regulations, not a coverage extensionCoverage continuation right, paid entirely by the beneficiary
Typical exclusionsDoes not extend coverage; only governs conditions and PHI data handlingDoes not apply to employers with fewer than 20 employees
Who is most affected by errorsCovered entities and business associates handling PHI and medical recordsHR departments failing to send timely COBRA election notices
Common mistakesConfusing HIPAA privacy regulations with data security software compliance aloneMissing the 60-day election window or 44-day notice deadline

What Are the Most Common Mistakes With the 1996 Health Insurance Portability Act?

  • Agencies assume HIPAA only applies to healthcare providers and HMOs, when any agency handling group health enrollment, claims, or underwriting data as a business associate is also subject to the Privacy Rule and HIPAA Security Rule.
  • Workforce members email or fax health questionnaires containing PHI without verifying encryption or recipient accuracy, creating reportable HIPAA violations even when the disclosure was accidental and unintentional.
  • Agencies confuse HIPAA’s original pre-existing condition limits with current law, not recognizing that the Affordable Care Act eliminated most pre-existing condition exclusions for major medical plans in 2014.
  • Business associate agreements between agencies and carriers or TPAs are outdated or missing entirely, leaving unclear responsibility for breach notification, data use agreement terms, and data retention obligations.
  • Agencies lack a documented HIPAA privacy policy or workforce members training program, which becomes a significant liability finding during a Department of Health and Human Services audit or client due diligence review.
  • CSRs discuss a client’s specific medical condition or sensitive health information in shared workspaces or over unsecured messaging platforms, violating the minimum necessary standard even without any external disclosure.

How to Explain the 1996 Health Insurance Portability Act to a Client

Explaining the 1996 Health Insurance Portability Act to a personal lines client

You know that HIPAA law that keeps your health information private and protects patient rights when you switch jobs? That is HIPAA, from 1996. It mostly matters to you now for the privacy regulations side, meaning your doctor, your health plan, and even our agency have to protect your medical records and personal health information and can only share it with your permission.

Explaining the 1996 Health Insurance Portability Act to a small business owner

HIPAA affects your group health plan in two ways. First, it limits how a carrier can restrict coverage for employees with pre-existing conditions, though the Affordable Care Act has taken over most of that job now. Second, and this is the part that catches employers off guard, it requires you to keep employee PHI and medical records separate from regular HR files and restrict which workforce members in your company can see sensitive health information.

Explaining the 1996 Health Insurance Portability Act to a CFO or risk manager

HIPAA creates compliance exposure at two levels for your organization: as a plan sponsor handling PHI, and potentially as a business associate if any internal team processes claims data or medical records. I recommend confirming your business associate agreements with your TPA and carrier are current, and that your privacy policy addresses breach notification timelines under the HHS Breach Notification Rule and the HITECH Act. This is a compliance and reputational risk item involving potential criminal penalties for HIPAA violations, not just a benefits administration detail.

Frequently Asked Questions About the 1996 Health Insurance Portability Act

Does HIPAA still limit pre-existing condition exclusions today?

HIPAA’s original 12-month pre-existing condition exclusion limits still exist in statute, but the Affordable Care Act effectively eliminated pre-existing condition exclusions for most major medical group and individual plans starting in 2014. HIPAA’s provisions remain relevant mainly for certain excepted benefits, like some limited-scope dental or vision plans, that fall outside ACA’s reach.

Is an insurance agency considered a covered entity under HIPAA?

An insurance agency is typically classified as a business associate rather than a covered entity, since agencies handle PHI and medical records on behalf of health plans or carriers rather than being the health plan itself. Business associate status still requires a signed business associate agreement and compliance with the HIPAA Security Rule’s administrative safeguards, physical safeguards, and technical safeguards for any health data the agency accesses.

What triggers a HIPAA breach notification requirement?

A breach notification is triggered when PHI or sensitive health information is used or disclosed in a way not permitted under the Privacy Rule, and the covered entity or business associate cannot demonstrate a low probability that the information was compromised. Examples include emailing medical records to the wrong recipient, a stolen laptop containing unencrypted e-PHI, or workforce members accessing records without a legitimate reason, all representing HIPAA violations.

Can an employer see an employee’s health plan claims history?

An employer generally cannot access individually identifiable health claims information or medical records through its role as plan sponsor without the employee’s authorization, since HIPAA firewalls plan administration functions from other employer functions like hiring and management decisions. Employers can receive summary health information or a limited data set, meaning de-identified data stripped of most identifiers, for purposes like plan design, data analysis, benefit eligibility inquiries, or obtaining bids from carriers. In a hybrid entity with designated healthcare components, access is further restricted.

Does HIPAA apply to short-term health plans or excepted benefits?

HIPAA’s portability provisions generally do not apply to short-term limited duration insurance or excepted benefits like most dental, vision, and certain fixed-indemnity plans, since these are exempt from many HIPAA regulations. The HIPAA Privacy Rule and HIPAA Security Rule can still apply to entities administering these plans if they otherwise qualify as covered entities or business associates handling PHI.

  • Certificate of Creditable Coverage: A document that formerly proved an individual’s prior health coverage duration to offset pre-existing condition waiting periods; largely obsolete since the Affordable Care Act eliminated most such exclusions.
  • COBRA Continuation Coverage: A separate federal law allowing employees to temporarily continue group health coverage after job loss or other qualifying events, at the employee’s own expense, distinct from HIPAA’s privacy regulations and portability functions.
  • Pre-Existing Condition Exclusion: A policy provision, now mostly prohibited by the Affordable Care Act for major medical plans, that denied or limited coverage for medical conditions that existed before a policy’s effective date; HIPAA originally capped how long such exclusions could last.
  • Guaranteed Issue: A requirement that insurers offer coverage regardless of health status, a concept HIPAA introduced for certain group markets and the Affordable Care Act later expanded broadly.
  • Privacy Rule: The HIPAA regulation establishing federal standards for protecting individually identifiable PHI and personal health information, enforced by the Department of Health and Human Services Office for Civil Rights.
  • Business Associate Agreement: A contract required under HIPAA regulations between a covered entity and any vendor, including many insurance agencies, that handles PHI or medical records on the covered entity’s behalf, establishing disclosure policies and proper disposal methods.

Sources and References

About the Author

Justin Goodman, CIC, CCIP, CISC, CLCS, CRIS, PCIA, QCLS, MFHR
CEO and Co-Founder, Total CSR, Inc.

Justin Goodman is a third-generation insurance broker with over two decades in agency operations. He has trained more than 50,000 CSRs, account managers, and producers in commercial and personal lines coverage, from workers’ compensation to construction risk. He was named 2024 Insurance Journal Agent of the Year and one of the nation’s top five construction insurance experts by Risk & Insurance. He is the author of Retain, which applies cognitive science research on memory and knowledge transfer to insurance training, and speaks nationally on how agencies build durable technical expertise in their teams.

Connect with Justin on LinkedIn