HIPAA establishes standards to protect private health information and electronic health information. It covers protected health information, which is individually identifiable health information that is created or received by a covered entity. HIPAA applies to forms, spoken communication, emails, faxes and other media. It gives patients rights over their private health information and requires covered entities to have security measures, compliance policies, and penalties for violations or noncompliance.