This document is the testimony of Kirk J. Nahra of WilmerHale providing historical background on the HIPAA statute and the development of the HIPAA privacy and security rules. Nahra explains the limitations of HIPAA's coverage, the concept of "business associates," and the challenges faced by employers and health plans in complying with the security rule.