Which federal law primarily governs the privacy and security of patient health information in US ambulatory care settings?