HIPAA establishes standards to protect sensitive patient health information. It covers identifiable health information held by covered entities, including demographic information, medical records, insurance forms, and billing information. HIPAA applies to both electronic and paper records. It gives patients rights over their protected health information and sets security standards for covered entities to safely store, use and transmit patient data. Covered entities must implement safeguards like access controls, disposal protocols and encryption and are subject to penalties for noncompliance.