Achievable logoAchievable logo
CCMA
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. Medical assistant
2. Electronic records
3. Medical terminology and anatomy
4. The fundamentals of infection control
5. Introduction to vital signs
6. The patient interview and history
7. The physical examination
8. Appointment scheduling
9. Insurance billing
9.1 Health insurance basics
9.2 Government health plans: Medicare and Medicaid programs
9.3 Other government and private health plans
9.4 The medical assistant's role
9.5 HIPAA overview and the privacy rule
9.6 Other private laws
9.7 Healthcare laws overview
10. Diagnostic coding and the ICD-10-CM System
11. Procedural coding
12. Medical billing and reimbursement essentials
13. Assisting with medical specialties
14. Assisting with the musculoskeletal system
15. Assisting with the cardiovascular system
16. Assisting with the respiratory system
17. Assisting with the nervous system
18. Anatomy and physiology of the urinary system
19. Assisting in obstetrics and gynecology
20. Assisting in endocrinology
21. Assisting in ophthalmology & otolaryngology
22. Assisting in gastroenterology
23. Assisting in the immune & lymphatic systems
24. Assisting in pediatrics: the developmental stages and care
25. The medical assistant’s role in caring for the older patient
26. The role of the medical assistant in physical therapy examination and assessment
27. Preparing for minor surgery: room, solutions, and supplies
28. Introduction to the clinical laboratory
29. Urinalysis
30. Blood collection
31. Analysis of blood
32. Electrocardiography and heart structure
33. The principles of pharmacology
34. Essential calculations and measurement systems
35. Solid, liquid, & solutions medication doses
36. Administering medications
37. Metabolism and core nutrient roles
38. Medical emergencies in the healthcare setting
Achievable logoAchievable logo
9.5 HIPAA overview and the privacy rule
Achievable CCMA
9. Insurance billing
Our CCMA course is currently in development and is a work-in-progress.

HIPAA overview and the privacy rule

8 min read
Font
Discuss
Share
Feedback

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that protects the privacy and confidentiality of patients. The following sections will examine the history, terminology, and standards of HIPAA.

Goals of HIPAA

With the anticipated changes in healthcare technology (e.g., the electronic health record [EHR]), Congress passed the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The US Department of Health and Human Services (HHS) is the agency responsible for developing the specific requirements of the law. The HHS Office for Civil Rights (OCR) enforces HIPAA.

Before HIPAA, the billing and payment processes were slow. Nationwide, insurance companies used many different coding systems. The coding systems were used to provide information on disease and treatments for payment purposes. It took months for facilities to receive insurance payments for services provided to patients. Paper transactions and paper checks were commonly used.

One of the goals of HIPAA was to simplify the electronic exchange of information. All health plans, claims clearinghouses, and healthcare facilities needed to be consistent with their electronic exchange of information. This meant they all needed to use the same coding systems. They also needed to follow the same requirements for the electronic exchange of information. Today, this is called administrative simplification. The goal is to reduce the clerical burden and increase electronic transaction adoption.

Four standards of HIPAA

With the increased electronic transactions, HIPAA also contained provisions for the privacy and security of the patients’ information. Primary provisions of the law were stated in four standards:

  • Standard 1 related to transactions and code sets: HHS adopted standard transactions for the electronic exchange of administrative healthcare information. This included insurance claims, payment, and insurance eligibility information. The goal was to speed up the process of identifying insurance benefits, submitting insurance claims, and receiving payment. Standard 1 also included mandating universal coding systems. Processes become more efficient with everyone using the same coding systems:
  • The Current Procedural Terminology (CPT) is used to code procedures and services.
  • The International Classification of Diseases (ICD) is used to code diseases and disorders.
  • Standard 2 related to the Privacy Rule: Healthcare facilities, insurance companies, and others need to protect written, electronic, and oral patient health information.
  • Standard 3 related to the Security Rule: Healthcare facilities, insurance companies, and others need to protect patient information that is electronically stored and transmitted.
  • Standard 4 related to unique identifiers:
  • National Provider Identifier (NPI): Each covered healthcare provider has a unique identification number that is used for financial and administrative transactions. The NPI is a 10-digit number.
  • Health Plan Identifier (HPI): Each health plan has a unique identifier.
  • Employer Identification Number (EIN): Each employer has a unique identifier issued by the Internal Revenue Service.

In addition to these provisions, HIPAA focused on insurance portability. HIPAA states that employer health insurance plans may not exclude coverage for employees with preexisting conditions. HIPAA also allows extra opportunities to enroll in health insurance plans. For instance, a person can request special enrollment if there is a loss in coverage from another policy. HIPAA prohibited enrollment discrimination based on a person’s health history or genetics.

HIPAA-Related terminology

HIPAA has many unique terms:

Covered entities: Healthcare providers, health (insurance) plans, and claims clearinghouses that transmit protected health information electronically. Examples of covered entities include these:

  • Providers (e.g., medical doctors, doctors of osteopathic medicine, nurse practitioners, physician assistants)
  • Dentists, chiropractors, and psychologists
  • Nursing homes, pharmacies, and ambulatory care facilities (e.g., clinics)
  • Health insurance companies, government insurance programs (Medicare, Medicaid), and health maintenance organizations (HMOs)
  • Claims clearinghouses and billing services
  • Protected health information (PHI): Individually identifiable health information stored or transmitted by covered entities or business associates. Includes verbal, paper, or electronic information.
  • Business associate: A person or business that provides a service to a covered entity that involves access to PHI. Examples include legal, billing, and management services; accreditation agencies; consulting firms; and claims processing organizations.
  • Permission: A reason for releasing or disclosing patient information under HIPAA.
  • De-identify: To remove all direct patient identifiers from the PHI. In other words, this is the process of removing anything that can link the information back to a specific person. Examples of direct patient identifiers include these:
  • Personal demographic information (name, date of birth, address, phone number, Social Security number)
  • Payment and insurance information
  • Limited data set: PHI that has had all of the direct patient identifiers removed. This would include the name, contact information, Social Security number, and so on. The only information left would be health information. Examples of limited data set information include physical or mental health conditions, test results, medications currently taken, and allergies.

Privacy Rule

The HIPAA Privacy Rule has created national standards that protect health records and other patient information. The Privacy Rule’s main purpose is to define and limit the situations in which a patient’s information can be used or disclosed. The rule also describes patients’ rights over their information. Patients have the right to do the following:

  • Examine their health information
  • Obtain a copy of their health records
  • Request corrections to be made if the information is incorrect

Covered entities must comply with the Privacy Rule. They must safeguard all patient information. Covered entities must ensure that business associates also keep PHI private. A written agreement detailing how the business associate will safeguard the PHI must be signed. Covered entities cannot give PHI to business associates until the agreement has been signed. Only PHI required for the job of the business associates can be given.

Permissions not requiring written authorization

The Privacy Rule lists permissions or reasons that the health information can be released. The following permissions do not require written authorization from the patient to release PHI:

  • Treatment, payment, and healthcare operations (TPO): Treatment relates to when the covered entity discloses PHI when coordinating or managing healthcare. For instance, you do not need to sign a written authorization for your provider to send a prescription to a pharmacy. Payment relates to activities related to payment or reimbursement for services. For instance, if you were not paying your bill, the healthcare facility might turn your account over to a collection agency. The facility would not need written authorization from you to disclose your information. Healthcare operations relate to the financial, legal, quality improvement, and administrative activities that healthcare facilities need to complete to run and support their business, such as patient case management.
  • Uses and disclosures with an opportunity to agree or object: The patient can give informal permission when asked outright or can be given an opportunity to agree or object. For example, a patient comes into the exam room with a friend. You ask the patient if they want the friend to remain. The patient can say yes or no.
  • Incidental use and disclosure: We need to take reasonable precautions, so patient information is not overheard or seen by others. The Privacy Rule does not require that we get written authorization for incidental disclosures. For instance, you take precautions, but you are overheard discussing patient PHI on the phone. There is no need for you to get a written authorization from the patient on the phone for the incidental disclosure.
  • Public interest and benefit activities: PHI can be released when required by law, law enforcement, and public health activities. PHI can also be released for research, organ and tissue donation, and workers’ compensation. Funeral directors, coroners, and medical examiners can also obtain PHI.
  • Limited data set: The direct patient identifiers are removed from the PHI. The remaining information can be used for research, public health purposes, and healthcare operations.
  • To the individual: A covered entity can disclose PHI to the patient. If you want a copy of your health record, you can get it without completing a written authorization (record release form).

Patients and their health information

The physical part of the record belongs to the facility or provider. Under HIPAA, patients own the information in their health records. They also control when the information in their record is released to another party. There are state laws that regulate the release. In most cases, patients have a right to receive a copy of their information. The following examples illustrate cases in which patients cannot get their information immediately:

  • When a provider is treating a patient for emotional or mental conditions, the provider can exercise professional judgment to determine if the records should be released to the patient. This is known as the doctrine of professional discretion. The provider may feel that if the patient saw the records, more harm than good would result. For instance, you are obtaining a weight on a patient with an eating disorder. The provider’s policy is that you do not share the weight with the patient. The provider decides if the weight is shared. For some patients, a weight gain may harm their current success.
  • Another situation in which patients cannot get health information immediately when requested relates to diagnostic tests. In the ambulatory care setting, patients have diagnostic tests done all the time. The provider must review the results before they are given to the patient. After reviewing the results, the provider instructs the medical assistant on what to tell the patient. The medical assistant contacts the patient and discusses what the provider stated. After the call, the medical assistant documents the call in the patient’s health record.

Goals of HIPAA

  • Simplify electronic exchange of health information (administrative simplification)
  • Standardize coding systems for efficiency (CPT, ICD)
  • Reduce clerical burden, speed up billing/payment processes

Four standards of HIPAA

  • Standard 1: Transactions and code sets (standardized electronic claims, CPT, ICD)
  • Standard 2: Privacy Rule (protect all forms of patient health information)
  • Standard 3: Security Rule (protect electronic patient information)
  • Standard 4: Unique identifiers (NPI, HPI, EIN for providers, plans, employers)
  • Insurance portability: prohibits preexisting condition exclusions, allows special enrollment, bans discrimination based on health/genetics

HIPAA-Related terminology

  • Covered entities: providers, health plans, clearinghouses transmitting PHI electronically
  • Protected health information (PHI): identifiable health info in any form
  • Business associate: outside person/business with PHI access for services
  • De-identify: remove direct identifiers (name, DOB, SSN, etc.) from PHI
  • Limited data set: PHI minus direct identifiers, used for research/operations

Privacy Rule

  • Sets national standards for PHI protection and patient rights
  • Patients can examine, copy, and request corrections to their records
  • Covered entities/business associates must safeguard PHI and sign agreements before sharing

Permissions not requiring written authorization

  • Treatment, payment, healthcare operations (TPO): routine sharing for care, billing, operations
  • Uses/disclosures with opportunity to agree/object: informal patient permission (e.g., friend in exam room)
  • Incidental disclosures: accidental overhearing/seeing PHI despite precautions
  • Public interest/benefit: law enforcement, public health, research, organ donation, workers’ comp
  • Limited data set: for research/public health without identifiers
  • To the individual: patients can access their own records without written request

Patients and their health information

  • Facility owns the record, patient owns the information
  • Patients control release of their info, with some exceptions:
    • Provider discretion for mental/emotional health records (doctrine of professional discretion)
    • Diagnostic test results reviewed by provider before release

Permission requiring written authorization

  • Written authorization needed for third-party disclosures (e.g., other providers, employers, insurers, lawyers)
  • Disclosure forms must specify info, recipient, expiration, and revocation rights

Disclosure authorization process

  • Medical assistants help patients complete disclosure forms, which are added to records
  • Info only released to individuals listed on authorization form or with code word/number
  • Cannot confirm patient status or release info if not authorized

Records release process

  • Patients must complete/sign records release form for transfer (including images/videos)
  • Higher confidentiality for psychotherapy notes, substance abuse, HIV info
    • Psychotherapy notes stored separately, limited access
    • Substance abuse/HIV info protected by additional federal/state laws

Safeguards of the security rule

  • Administrative safeguards: security officer, policies, risk assessment, cyberattack prevention
  • Physical safeguards: secure facilities, workstations, device procedures
  • Technical safeguards: restrict ePHI access, audit trails, encryption, prevent unauthorized changes/transmissions
  • Employees must follow security procedures; violations can result in job loss, fines, or loss of credentials

Sign up for free to take 18 quiz questions on this topic

Previous
Next  | 9.6 Other private laws
All rights reserved ©2016 - 2026 Achievable, Inc.

HIPAA overview and the privacy rule

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that protects the privacy and confidentiality of patients. The following sections will examine the history, terminology, and standards of HIPAA.

Goals of HIPAA

With the anticipated changes in healthcare technology (e.g., the electronic health record [EHR]), Congress passed the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The US Department of Health and Human Services (HHS) is the agency responsible for developing the specific requirements of the law. The HHS Office for Civil Rights (OCR) enforces HIPAA.

Before HIPAA, the billing and payment processes were slow. Nationwide, insurance companies used many different coding systems. The coding systems were used to provide information on disease and treatments for payment purposes. It took months for facilities to receive insurance payments for services provided to patients. Paper transactions and paper checks were commonly used.

One of the goals of HIPAA was to simplify the electronic exchange of information. All health plans, claims clearinghouses, and healthcare facilities needed to be consistent with their electronic exchange of information. This meant they all needed to use the same coding systems. They also needed to follow the same requirements for the electronic exchange of information. Today, this is called administrative simplification. The goal is to reduce the clerical burden and increase electronic transaction adoption.

Four standards of HIPAA

With the increased electronic transactions, HIPAA also contained provisions for the privacy and security of the patients’ information. Primary provisions of the law were stated in four standards:

  • Standard 1 related to transactions and code sets: HHS adopted standard transactions for the electronic exchange of administrative healthcare information. This included insurance claims, payment, and insurance eligibility information. The goal was to speed up the process of identifying insurance benefits, submitting insurance claims, and receiving payment. Standard 1 also included mandating universal coding systems. Processes become more efficient with everyone using the same coding systems:
  • The Current Procedural Terminology (CPT) is used to code procedures and services.
  • The International Classification of Diseases (ICD) is used to code diseases and disorders.
  • Standard 2 related to the Privacy Rule: Healthcare facilities, insurance companies, and others need to protect written, electronic, and oral patient health information.
  • Standard 3 related to the Security Rule: Healthcare facilities, insurance companies, and others need to protect patient information that is electronically stored and transmitted.
  • Standard 4 related to unique identifiers:
  • National Provider Identifier (NPI): Each covered healthcare provider has a unique identification number that is used for financial and administrative transactions. The NPI is a 10-digit number.
  • Health Plan Identifier (HPI): Each health plan has a unique identifier.
  • Employer Identification Number (EIN): Each employer has a unique identifier issued by the Internal Revenue Service.

In addition to these provisions, HIPAA focused on insurance portability. HIPAA states that employer health insurance plans may not exclude coverage for employees with preexisting conditions. HIPAA also allows extra opportunities to enroll in health insurance plans. For instance, a person can request special enrollment if there is a loss in coverage from another policy. HIPAA prohibited enrollment discrimination based on a person’s health history or genetics.

HIPAA-Related terminology

HIPAA has many unique terms:

Covered entities: Healthcare providers, health (insurance) plans, and claims clearinghouses that transmit protected health information electronically. Examples of covered entities include these:

  • Providers (e.g., medical doctors, doctors of osteopathic medicine, nurse practitioners, physician assistants)
  • Dentists, chiropractors, and psychologists
  • Nursing homes, pharmacies, and ambulatory care facilities (e.g., clinics)
  • Health insurance companies, government insurance programs (Medicare, Medicaid), and health maintenance organizations (HMOs)
  • Claims clearinghouses and billing services
  • Protected health information (PHI): Individually identifiable health information stored or transmitted by covered entities or business associates. Includes verbal, paper, or electronic information.
  • Business associate: A person or business that provides a service to a covered entity that involves access to PHI. Examples include legal, billing, and management services; accreditation agencies; consulting firms; and claims processing organizations.
  • Permission: A reason for releasing or disclosing patient information under HIPAA.
  • De-identify: To remove all direct patient identifiers from the PHI. In other words, this is the process of removing anything that can link the information back to a specific person. Examples of direct patient identifiers include these:
  • Personal demographic information (name, date of birth, address, phone number, Social Security number)
  • Payment and insurance information
  • Limited data set: PHI that has had all of the direct patient identifiers removed. This would include the name, contact information, Social Security number, and so on. The only information left would be health information. Examples of limited data set information include physical or mental health conditions, test results, medications currently taken, and allergies.

Privacy Rule

The HIPAA Privacy Rule has created national standards that protect health records and other patient information. The Privacy Rule’s main purpose is to define and limit the situations in which a patient’s information can be used or disclosed. The rule also describes patients’ rights over their information. Patients have the right to do the following:

  • Examine their health information
  • Obtain a copy of their health records
  • Request corrections to be made if the information is incorrect

Covered entities must comply with the Privacy Rule. They must safeguard all patient information. Covered entities must ensure that business associates also keep PHI private. A written agreement detailing how the business associate will safeguard the PHI must be signed. Covered entities cannot give PHI to business associates until the agreement has been signed. Only PHI required for the job of the business associates can be given.

Permissions not requiring written authorization

The Privacy Rule lists permissions or reasons that the health information can be released. The following permissions do not require written authorization from the patient to release PHI:

  • Treatment, payment, and healthcare operations (TPO): Treatment relates to when the covered entity discloses PHI when coordinating or managing healthcare. For instance, you do not need to sign a written authorization for your provider to send a prescription to a pharmacy. Payment relates to activities related to payment or reimbursement for services. For instance, if you were not paying your bill, the healthcare facility might turn your account over to a collection agency. The facility would not need written authorization from you to disclose your information. Healthcare operations relate to the financial, legal, quality improvement, and administrative activities that healthcare facilities need to complete to run and support their business, such as patient case management.
  • Uses and disclosures with an opportunity to agree or object: The patient can give informal permission when asked outright or can be given an opportunity to agree or object. For example, a patient comes into the exam room with a friend. You ask the patient if they want the friend to remain. The patient can say yes or no.
  • Incidental use and disclosure: We need to take reasonable precautions, so patient information is not overheard or seen by others. The Privacy Rule does not require that we get written authorization for incidental disclosures. For instance, you take precautions, but you are overheard discussing patient PHI on the phone. There is no need for you to get a written authorization from the patient on the phone for the incidental disclosure.
  • Public interest and benefit activities: PHI can be released when required by law, law enforcement, and public health activities. PHI can also be released for research, organ and tissue donation, and workers’ compensation. Funeral directors, coroners, and medical examiners can also obtain PHI.
  • Limited data set: The direct patient identifiers are removed from the PHI. The remaining information can be used for research, public health purposes, and healthcare operations.
  • To the individual: A covered entity can disclose PHI to the patient. If you want a copy of your health record, you can get it without completing a written authorization (record release form).

Patients and their health information

The physical part of the record belongs to the facility or provider. Under HIPAA, patients own the information in their health records. They also control when the information in their record is released to another party. There are state laws that regulate the release. In most cases, patients have a right to receive a copy of their information. The following examples illustrate cases in which patients cannot get their information immediately:

  • When a provider is treating a patient for emotional or mental conditions, the provider can exercise professional judgment to determine if the records should be released to the patient. This is known as the doctrine of professional discretion. The provider may feel that if the patient saw the records, more harm than good would result. For instance, you are obtaining a weight on a patient with an eating disorder. The provider’s policy is that you do not share the weight with the patient. The provider decides if the weight is shared. For some patients, a weight gain may harm their current success.
  • Another situation in which patients cannot get health information immediately when requested relates to diagnostic tests. In the ambulatory care setting, patients have diagnostic tests done all the time. The provider must review the results before they are given to the patient. After reviewing the results, the provider instructs the medical assistant on what to tell the patient. The medical assistant contacts the patient and discusses what the provider stated. After the call, the medical assistant documents the call in the patient’s health record.
Key points

Goals of HIPAA

  • Simplify electronic exchange of health information (administrative simplification)
  • Standardize coding systems for efficiency (CPT, ICD)
  • Reduce clerical burden, speed up billing/payment processes

Four standards of HIPAA

  • Standard 1: Transactions and code sets (standardized electronic claims, CPT, ICD)
  • Standard 2: Privacy Rule (protect all forms of patient health information)
  • Standard 3: Security Rule (protect electronic patient information)
  • Standard 4: Unique identifiers (NPI, HPI, EIN for providers, plans, employers)
  • Insurance portability: prohibits preexisting condition exclusions, allows special enrollment, bans discrimination based on health/genetics

HIPAA-Related terminology

  • Covered entities: providers, health plans, clearinghouses transmitting PHI electronically
  • Protected health information (PHI): identifiable health info in any form
  • Business associate: outside person/business with PHI access for services
  • De-identify: remove direct identifiers (name, DOB, SSN, etc.) from PHI
  • Limited data set: PHI minus direct identifiers, used for research/operations

Privacy Rule

  • Sets national standards for PHI protection and patient rights
  • Patients can examine, copy, and request corrections to their records
  • Covered entities/business associates must safeguard PHI and sign agreements before sharing

Permissions not requiring written authorization

  • Treatment, payment, healthcare operations (TPO): routine sharing for care, billing, operations
  • Uses/disclosures with opportunity to agree/object: informal patient permission (e.g., friend in exam room)
  • Incidental disclosures: accidental overhearing/seeing PHI despite precautions
  • Public interest/benefit: law enforcement, public health, research, organ donation, workers’ comp
  • Limited data set: for research/public health without identifiers
  • To the individual: patients can access their own records without written request

Patients and their health information

  • Facility owns the record, patient owns the information
  • Patients control release of their info, with some exceptions:
    • Provider discretion for mental/emotional health records (doctrine of professional discretion)
    • Diagnostic test results reviewed by provider before release

Permission requiring written authorization

  • Written authorization needed for third-party disclosures (e.g., other providers, employers, insurers, lawyers)
  • Disclosure forms must specify info, recipient, expiration, and revocation rights

Disclosure authorization process

  • Medical assistants help patients complete disclosure forms, which are added to records
  • Info only released to individuals listed on authorization form or with code word/number
  • Cannot confirm patient status or release info if not authorized

Records release process

  • Patients must complete/sign records release form for transfer (including images/videos)
  • Higher confidentiality for psychotherapy notes, substance abuse, HIV info
    • Psychotherapy notes stored separately, limited access
    • Substance abuse/HIV info protected by additional federal/state laws

Safeguards of the security rule

  • Administrative safeguards: security officer, policies, risk assessment, cyberattack prevention
  • Physical safeguards: secure facilities, workstations, device procedures
  • Technical safeguards: restrict ePHI access, audit trails, encryption, prevent unauthorized changes/transmissions
  • Employees must follow security procedures; violations can result in job loss, fines, or loss of credentials

More from Insurance billing

  • Health insurance basics
  • Government health plans: Medicare and Medicaid programs
  • Other government and private health plans
  • The medical assistant's role
  • Other private laws