The HIPAA legislation required the Department of Health and Human Services (DHHS) to broadcast regulations on the specific areas of HIPAA, called the Rules. These Rules were finalized at various times and healthcare organizations had two or three years (depending on size) to comply with the specific requirements. 
The Rules are composed of Standards. The HIPAA Standards resulted from many years of public and private sector collaboration. Industry work groups were formed and reports written with recommendations on how to better manage and protect health information. The goal of this initiative was to define uniform standards for transferring health information among healthcare providers, health plans, and clearinghouses (covered entities) while securing health information and ensuring patient privacy and confidentiality.