Federal regulations like HIPAA establish standards to protect individuals' protected health information (PHI). HIPAA's Privacy Rule governs who can access and use PHI. The law also requires reporting any breaches of PHI security. PHI includes any health or medical information that can identify an individual. Patients have rights to access, request restrictions on use of, and amend their own PHI records. Employees must limit access and disclosure of PHI to only those required or permitted for their job duties and take steps to secure PHI through measures like encryption, shredding documents, and limiting discussions of PHI.