Health Insurance Portability and Accountability Act of 1996 (HIPAA) (2024)

At a glance

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. The US Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule.

Background

HIPAA Privacy Rule

The Privacy Rule standards address the use and disclosure of individuals' health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called "covered entities."

The Privacy Rule also contains standards for individuals' rights to understand and control how their health information is used. A major goal of the Privacy Rule is to make sure that individuals' health information is properly protected while allowing the flow of health information needed to provide and promote high-quality healthcare, and to protect the public's health and well-being. The Privacy Rule permits important uses of information while protecting the privacy of people who seek care and healing.

Covered Entities

The following types of individuals and organizations are subject to the Privacy Rule and considered covered entities:

  • Healthcare providers: Every healthcare provider, regardless of size of practice, who electronically transmits health information in connection with certain transactions. These transactions include:
    • Claims
      • Benefit eligibility inquiries
        • Referral authorization requests
          • Other transactions for which HHS has established standards under the HIPAA Transactions Rule.
          • Health plans:
            Health plans include:
            • Health, dental, vision, and prescription drug insurers
              • Health maintenance organizations (HMOs)
                • Medicare, Medicaid, Medicare+Choice, and Medicare supplement insurers
                  • Long-term care insurers (excluding nursing home fixed-indemnity policies)
                    • Employer-sponsored group health plans
                      • Government- and church-sponsored health plans
                        • Multi-employer health plans

                        Exception: A group health plan with fewer than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity.

                        • Healthcare clearinghouses: Entities that process nonstandard information they receive from another entity into a standard (i.e., standard format or data content), or vice versa. In most instances, healthcare clearinghouses will receive individually identifiable health information only when they are providing these processing services to a health plan or healthcare provider as a business associate.
                          • Business associates: A person or organization (other than a member of a covered entity's workforce) using or disclosing individually identifiable health information to perform or provide functions, activities, or services for a covered entity. These functions, activities, or services include:
                            • Claims processing
                              • Data analysis
                                • Utilization review
                                  • Billing

                                  Permitted Uses and Disclosures

                                  The law permits, but does not require, a covered entity to use and disclose PHI, without an individual's authorization, for the following purposes or situations:

                                  • Disclosure to the individual (if the information is required for access or accounting of disclosures, the entity MUST disclose to the individual)
                                    • Treatment, payment, and healthcare operations
                                      • Opportunity to agree or object to the disclosure of PHI
                                        • An entity can obtain informal permission by asking the individual outright, or by circ*mstances that clearly give the individual the opportunity to agree, acquiesce, or object
                                        • Incident to an otherwise permitted use and disclosure
                                          • Limited dataset for research, public health, or healthcare operations
                                            • Public interest and benefit activities—The Privacy Rule permits use and disclosure of PHI, without an individual's authorization or permission, for 12 national priority purposes:
                                              1. When required by law
                                                1. Public health activities
                                                  1. Victims of abuse or neglect or domestic violence
                                                    1. Health oversight activities
                                                      1. Judicial and administrative proceedings
                                                        1. Law enforcement
                                                          1. Functions (such as identification) concerning deceased persons
                                                            1. Cadaveric organ, eye, or tissue donation
                                                              1. Research, under certain conditions
                                                                1. To prevent or lessen a serious threat to health or safety
                                                                  1. Essential government functions
                                                                    1. Workers' compensation

                                                                      HIPAA Security Rule

                                                                      While the HIPAA Privacy Rule safeguards PHI, the Security Rule protects a subset of information covered by the Privacy Rule. This subset is all individually identifiable health information a covered entity creates, receives, maintains, or transmits in electronic form. This information is called electronic protected health information, or e-PHI. The Security Rule does not apply to PHI transmitted orally or in writing.

                                                                      To comply with the HIPAA Security Rule, all covered entities must:

                                                                      • Ensure the confidentiality, integrity, and availability of all e-PHI
                                                                        • Detect and safeguard against anticipated threats to the security of the information
                                                                          • Protect against anticipated impermissible uses or disclosures that are not allowed by the rule
                                                                            • Certify compliance by their workforce

                                                                              Covered entities should rely on professional ethics and best judgment when considering requests for these permissive uses and disclosures. The HHS Office for Civil Rights enforces HIPAA rules, and all complaints should be reported to that office. HIPAA violations may result in civil monetary or criminal penalties.

                                                                              For more information, visit HHS's HIPAA website.

                                                                              Health Insurance Portability and Accountability Act of 1996 (HIPAA) (2024)

                                                                              References

                                                                              Top Articles
                                                                              Should You Buy Backlinks in 2024? It Depends
                                                                              The Blackening Showtimes Near Century Aurora And Xd
                                                                              Wyoming Dot Webcams
                                                                              Mw2 Other Apps Vram
                                                                              Best Boxing Gyms Near Me
                                                                              Miller Motte College Student Portal
                                                                              Triple A Flat Tire Repair Cost
                                                                              Dayton Overdrive
                                                                              Craigslist Greenville Pets Free
                                                                              Tyson Employee Paperless
                                                                              Barbershops near me in Jupiter
                                                                              Gay Pnp Zoom Meetings
                                                                              Espn Masters Leaderboard
                                                                              Lebenszahl 8: Ihre wirkliche Bedeutung
                                                                              73 87 Chevy Truck Air Conditioning Wiring Diagram
                                                                              Craigslist Jobs Glens Falls Ny
                                                                              Lucifer Season 1 Download In Telegram In Tamil
                                                                              The Courier from Waterloo, Iowa
                                                                              Offsale Roblox Items are Going Limited… What’s Next? | Rolimon's
                                                                              630251.S - CCB-PWRIO-05 - Vision Systems - Vision Systems In-Sight, Cognex - InSight 2800 Series - Accessories Cables / Brackets IS28XX -
                                                                              Araxotok
                                                                              Swissport Timecard
                                                                              Drug Stores Open 24Hrs Near Me
                                                                              ‘There’s no Planet B’: UNLV first Nevada university to launch climate change plan
                                                                              Cric7.Net Ipl 2023
                                                                              Seconds Valuable Fun Welcoming Gang Back Andy Griffith's Birthday A Top Wish So A Happy Birthday FZSW A Fabulous Man Kevin Talks About Times From Ten Day Weekend Fun Labor Day Break
                                                                              Southern Food Buffet Near Me
                                                                              Maine Marine Forecast Gyx
                                                                              Louisiana Funeral Services and Crematory | Broussard, Louisiana
                                                                              Kristen Stewart and Dylan Meyer's Relationship Timeline
                                                                              Baldurs Gate 3 Igg
                                                                              Ancestors The Humankind Odyssey Wikia
                                                                              Buzzy Shark Tank Net Worth 2020
                                                                              Societe Europeenne De Developpement Du Financement
                                                                              Pick N Pull Near Me [Locator Map + Guide + FAQ]
                                                                              Megan Eugenio Exposed
                                                                              O2 eSIM guide | Download your eSIM | The Drop
                                                                              Tapana Telugu Movie Download Kuttymovies
                                                                              Miawaiifu
                                                                              KOBALT K15CS-06AC MANUAL Pdf Download
                                                                              80s Z Cavaricci Pants
                                                                              "Rainbow Family" will im Harz bleiben: Hippie-Camp bis Anfang September geplant
                                                                              Business Banking Online | Huntington
                                                                              Roseberrys Obituaries
                                                                              G122 Pink Pill
                                                                              Jacksonville Jaguars should be happy they won't see the old Deshaun Watson | Gene Frenette
                                                                              This Eras Tour Detail Makes Us Wonder If Taylor & Karlie Still Have Bad Blood
                                                                              Theresa Alone Gofundme
                                                                              Ucla Football 247
                                                                              Bucks County fall festivals and events to keep you busy through the season
                                                                              Papitop
                                                                              Car Hire in Romania from £4/day - Search for car rentals on KAYAK
                                                                              Latest Posts
                                                                              Article information

                                                                              Author: Ray Christiansen

                                                                              Last Updated:

                                                                              Views: 6574

                                                                              Rating: 4.9 / 5 (49 voted)

                                                                              Reviews: 88% of readers found this page helpful

                                                                              Author information

                                                                              Name: Ray Christiansen

                                                                              Birthday: 1998-05-04

                                                                              Address: Apt. 814 34339 Sauer Islands, Hirtheville, GA 02446-8771

                                                                              Phone: +337636892828

                                                                              Job: Lead Hospitality Designer

                                                                              Hobby: Urban exploration, Tai chi, Lockpicking, Fashion, Gunsmithing, Pottery, Geocaching

                                                                              Introduction: My name is Ray Christiansen, I am a fair, good, cute, gentle, vast, glamorous, excited person who loves writing and wants to share my knowledge and understanding with you.