HIPAA overview and the privacy rule
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that protects the privacy and confidentiality of patients. The following sections will examine the history, terminology, and standards of HIPAA.
Goals of HIPAA
With the anticipated changes in healthcare technology (e.g., the electronic health record [EHR]), Congress passed the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The US Department of Health and Human Services (HHS) is the agency responsible for developing the specific requirements of the law. The HHS Office for Civil Rights (OCR) enforces HIPAA.
Before HIPAA, the billing and payment processes were slow. Nationwide, insurance companies used many different coding systems. The coding systems were used to provide information on disease and treatments for payment purposes. It took months for facilities to receive insurance payments for services provided to patients. Paper transactions and paper checks were commonly used.
One of the goals of HIPAA was to simplify the electronic exchange of information. All health plans, claims clearinghouses, and healthcare facilities needed to be consistent with their electronic exchange of information. This meant they all needed to use the same coding systems. They also needed to follow the same requirements for the electronic exchange of information. Today, this is called administrative simplification. The goal is to reduce the clerical burden and increase electronic transaction adoption.
Four standards of HIPAA
With the increased electronic transactions, HIPAA also contained provisions for the privacy and security of the patients’ information. Primary provisions of the law were stated in four standards:
- Standard 1 related to transactions and code sets: HHS adopted standard transactions for the electronic exchange of administrative healthcare information. This included insurance claims, payment, and insurance eligibility information. The goal was to speed up the process of identifying insurance benefits, submitting insurance claims, and receiving payment. Standard 1 also included mandating universal coding systems. Processes become more efficient with everyone using the same coding systems:
- The Current Procedural Terminology (CPT) is used to code procedures and services.
- The International Classification of Diseases (ICD) is used to code diseases and disorders.
- Standard 2 related to the Privacy Rule: Healthcare facilities, insurance companies, and others need to protect written, electronic, and oral patient health information.
- Standard 3 related to the Security Rule: Healthcare facilities, insurance companies, and others need to protect patient information that is electronically stored and transmitted.
- Standard 4 related to unique identifiers:
- National Provider Identifier (NPI): Each covered healthcare provider has a unique identification number that is used for financial and administrative transactions. The NPI is a 10-digit number.
- Health Plan Identifier (HPI): Each health plan has a unique identifier.
- Employer Identification Number (EIN): Each employer has a unique identifier issued by the Internal Revenue Service.
In addition to these provisions, HIPAA focused on insurance portability. HIPAA states that employer health insurance plans may not exclude coverage for employees with preexisting conditions. HIPAA also allows extra opportunities to enroll in health insurance plans. For instance, a person can request special enrollment if there is a loss in coverage from another policy. HIPAA prohibited enrollment discrimination based on a person’s health history or genetics.
HIPAA-Related terminology
HIPAA has many unique terms:
Covered entities: Healthcare providers, health (insurance) plans, and claims clearinghouses that transmit protected health information electronically. Examples of covered entities include these:
- Providers (e.g., medical doctors, doctors of osteopathic medicine, nurse practitioners, physician assistants)
- Dentists, chiropractors, and psychologists
- Nursing homes, pharmacies, and ambulatory care facilities (e.g., clinics)
- Health insurance companies, government insurance programs (Medicare, Medicaid), and health maintenance organizations (HMOs)
- Claims clearinghouses and billing services
- Protected health information (PHI): Individually identifiable health information stored or transmitted by covered entities or business associates. Includes verbal, paper, or electronic information.
- Business associate: A person or business that provides a service to a covered entity that involves access to PHI. Examples include legal, billing, and management services; accreditation agencies; consulting firms; and claims processing organizations.
- Permission: A reason for releasing or disclosing patient information under HIPAA.
- De-identify: To remove all direct patient identifiers from the PHI. In other words, this is the process of removing anything that can link the information back to a specific person. Examples of direct patient identifiers include these:
- Personal demographic information (name, date of birth, address, phone number, Social Security number)
- Payment and insurance information
- Limited data set: PHI that has had all of the direct patient identifiers removed. This would include the name, contact information, Social Security number, and so on. The only information left would be health information. Examples of limited data set information include physical or mental health conditions, test results, medications currently taken, and allergies.
Privacy Rule
The HIPAA Privacy Rule has created national standards that protect health records and other patient information. The Privacy Rule’s main purpose is to define and limit the situations in which a patient’s information can be used or disclosed. The rule also describes patients’ rights over their information. Patients have the right to do the following:
- Examine their health information
- Obtain a copy of their health records
- Request corrections to be made if the information is incorrect
Covered entities must comply with the Privacy Rule. They must safeguard all patient information. Covered entities must ensure that business associates also keep PHI private. A written agreement detailing how the business associate will safeguard the PHI must be signed. Covered entities cannot give PHI to business associates until the agreement has been signed. Only PHI required for the job of the business associates can be given.
Permissions not requiring written authorization
The Privacy Rule lists permissions or reasons that the health information can be released. The following permissions do not require written authorization from the patient to release PHI:
- Treatment, payment, and healthcare operations (TPO): Treatment relates to when the covered entity discloses PHI when coordinating or managing healthcare. For instance, you do not need to sign a written authorization for your provider to send a prescription to a pharmacy. Payment relates to activities related to payment or reimbursement for services. For instance, if you were not paying your bill, the healthcare facility might turn your account over to a collection agency. The facility would not need written authorization from you to disclose your information. Healthcare operations relate to the financial, legal, quality improvement, and administrative activities that healthcare facilities need to complete to run and support their business, such as patient case management.
- Uses and disclosures with an opportunity to agree or object: The patient can give informal permission when asked outright or can be given an opportunity to agree or object. For example, a patient comes into the exam room with a friend. You ask the patient if they want the friend to remain. The patient can say yes or no.
- Incidental use and disclosure: We need to take reasonable precautions, so patient information is not overheard or seen by others. The Privacy Rule does not require that we get written authorization for incidental disclosures. For instance, you take precautions, but you are overheard discussing patient PHI on the phone. There is no need for you to get a written authorization from the patient on the phone for the incidental disclosure.
- Public interest and benefit activities: PHI can be released when required by law, law enforcement, and public health activities. PHI can also be released for research, organ and tissue donation, and workers’ compensation. Funeral directors, coroners, and medical examiners can also obtain PHI.
- Limited data set: The direct patient identifiers are removed from the PHI. The remaining information can be used for research, public health purposes, and healthcare operations.
- To the individual: A covered entity can disclose PHI to the patient. If you want a copy of your health record, you can get it without completing a written authorization (record release form).
Patients and their health information
The physical part of the record belongs to the facility or provider. Under HIPAA, patients own the information in their health records. They also control when the information in their record is released to another party. There are state laws that regulate the release. In most cases, patients have a right to receive a copy of their information. The following examples illustrate cases in which patients cannot get their information immediately:
- When a provider is treating a patient for emotional or mental conditions, the provider can exercise professional judgment to determine if the records should be released to the patient. This is known as the doctrine of professional discretion. The provider may feel that if the patient saw the records, more harm than good would result. For instance, you are obtaining a weight on a patient with an eating disorder. The provider’s policy is that you do not share the weight with the patient. The provider decides if the weight is shared. For some patients, a weight gain may harm their current success.
- Another situation in which patients cannot get health information immediately when requested relates to diagnostic tests. In the ambulatory care setting, patients have diagnostic tests done all the time. The provider must review the results before they are given to the patient. After reviewing the results, the provider instructs the medical assistant on what to tell the patient. The medical assistant contacts the patient and discusses what the provider stated. After the call, the medical assistant documents the call in the patient’s health record.