Which US federal law PRIMARILY governs the protection of personal health information in the healthcare industry?