1996 US federal statute that, with its implementing rules, governs the privacy, security, and breach notification obligations of health information.