The Health Insurance Portability And Accountability Act (HIPAA) is a legislation which sets the standard for sensitive patient data protection in the Healthcare industry. The legislation is enforced by periodic audits on the network and security systems of each business. The Audits are based on specific metrics set by the Office of Civil Rights (OCR) protocols and are a requirement of any business that stores or transfers patient information.
The ramifications for failing a HIPAA and/or PCI audit can range quite a bit. For PCI audit failures, hefty fines can be levied to businesses that don't comply but can quickly escalate to the loss of card processing privileges. HIPAA audit failures on the other hand can even extend to criminal and civil penalties.