It's not confusing at all - I went through this. HIPAA is commonly thought of primarily as a privacy law, but it is much more than that. As usual with the .gov plans, the devil is in the details. The Wikipedia page doesn't do it justice. For example - here's what I was paraphrasing from http://www.dol.gov/ebsa/faqs/fa…