Which federal law primarily governs the privacy and security of protected health information (PHI) in electronic health records?