Free quizlet.com Pursuant to the HIPAA Security Rule, covered entities must maintain secure access (for example, facility door locks) in areas where PHI is located. Allowing an unidentified individual to bypass a security entrance in this scenario violates the HIPAA Security Rule and exposes the MTF and its patients to a potential breach situation. The US Congress passed the Health Insurance Portability and Accountability Act (HIPAA), Public Law 104-191, in 1996. This law addresses a variety of issues related to health care. HIPAA required the US Department of Health and Human Services to adopt standards regarding the electronic exchange, privacy, and security of health information.