The Health Insurance Portability and Accountability Act of 1996 (HIPAA) establishes national standards for electronic health care transactions, national identifiers, and security/privacy rules to protect personal health information. HIPAA compliance requirements took effect in 2003, applying to covered entities like health plans, providers, and businesses with access to protected health information. Covered entities must implement policies governing access to and handling of personal health information.