The Health Insurance Portability and Accountability Act (HIPAA) protects private health information and requires security of electronic health records. HIPAA sets standards for handling protected health information (PHI) such as patient names, diagnoses, and billing information. It restricts disclosure of PHI without patient consent to treatment providers, for healthcare operations, and as required by law. Covered entities such as hospitals and insurance companies must notify patients of their privacy practices and allow complaints to be filed with the Office of Civil Rights for violations.