This advisory discusses the finalized privacy rules under the Health Insurance Portability and Accountability Act (HIPAA) and their implications for the health care marketplace. On the eve of the Clinton administration's departure from power, the Department of Health and Human Services (HHS) announced the finalized national uniform standards for privacy in health care transactions, as required by HIPAA; the new rule will take effect in two years, and achieving timely compliance will be a challenge for all. The article examines the scope of the final rule and the definition of "covered entities" and "business associates." It also discusses requirements for patients' consent, standards for implementation, and the authority of HHS to regulate the rules.