Quality Healthcare Software Solutions Skip Navigation Links
 
HIPAA

Introduction

The Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”) establishes, for the first time, a set of national standards for the protection of certain health information. The U.S. Department of Health and Human Services (“HHS”) issued the Privacy Rule to implement the requirement of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).1 The Privacy Rule standards address the use and disclosure of individuals’ health information—called “protected health information” by organizations subject to the Privacy Rule — called “covered entities,” as well as standards for individuals' privacy rights to understand and control how their health information is used. Within HHS, the Office for Civil Rights (“OCR”) has responsibility for implementing and enforcing the Privacy Rule with respect to voluntary compliance activities and civil money penalties.

A major goal of the Privacy Rule is to assure that individuals’ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public's health and well being. The Rule strikes a balance that permits important uses of information, while protecting the privacy of people who seek care and healing. Given that the health care marketplace is diverse, the Rule is designed to be flexible and comprehensive to cover the variety of uses and disclosures that need to be addressed.

Who is Covered by the Privacy Rule

The Privacy Rule, as well as all the Administrative Simplification rules, apply to health plans, health care clearing houses, and to any health care provider who transmits health information in electronic form in connection with transactions for which the Secretary of HHS has adopted standards under HIPAA (the “covered entities”). For help in determining whether you are covered, use CMS's decision tool.

Health Plans. Individual and group plans that provide or pay the cost of medical care are covered entities.4 Health plans include health, dental, vision, and prescription drug insurers, health maintenance organizations (“HMOs”), Medicare, Medicaid, Medicare+Choice and Medicare supplement insurers, and long-term care insurers (excluding nursing home fixed-indemnity policies). Health plans also include employer-sponsored group health plans, government and church-sponsored health plans, and multi-employer health plans. There are exceptions—a group health plan with less than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity. Two types of government-funded programs are not health plans: (1) those whose principal purpose is not providing or paying the cost of health care, such as the food stamps program; and (2) those programs whose principal activity is directly providing health care, such as a community health center,5 or the making of grants to fund the direct provision of health care. Certain types of insurance entities are also not health plans, including entities providing only workers’ compensation, automobile insurance, and property and casualty insurance. If an insurance entity has separable lines of business, one of which is a health plan, the HIPAA regulations apply to the entity with respect to the health plan line of business.

Health Care Providers. Every health care provider, regardless of size, who electronically transmits health information in connection with certain transactions, is a covered entity. These transactions include claims, benefit eligibility inquiries, referral authorization requests, or other transactions for which HHS has established standards under the HIPAA Transactions Rule.6 Using electronic technology, such as email, does not mean a health care provider is a covered entity; the transmission must be in connection with a standard transaction. The Privacy Rule covers a health care provider whether it electronically transmits these transactions directly or uses a billing service or other third party to do so on its behalf. Health care providers include all “providers of services” (e.g., institutional providers such as hospitals) and “providers of medical or health services” (e.g., non-institutional providers such as physicians, dentists and other practitioners) as defined by Medicare, and any other person or organization that furnishes, bills, or is paid for health care.

Health Care Clearing houses. Health care clearing houses are entities that process nonstandard information they receive from another entity into a standard (i.e., standard format or data content), or vice versa.7 In most instances, health care clearing houses will receive individually identifiable health information only when they are providing these processing services to a health plan or health care provider as a business associate. In such instances, only certain provisions of the Privacy Rule are applicable to the health care clearing house’s uses and disclosures of protected health information.8 Health care clearing houses include billing services, repricing companies, community health management information systems, and value-added networks and switches if these entities perform clearinghouse functions.

Men's Carolina Panthers Nike Panther Blue Legend Icon Performance T-Shirt,Minnesota Vikings Historic Logo 8-Bit Team Logo T-Shirt - Purple,Men's Denver Broncos Majestic Navy For All Time T-Shirt.Men's Carolina Panthers Nike Charcoal Stadium Touch Hooded Performance Long Sleeve T-Shirt,New Era Miami Dolphins Super Bowl VII Super Wide Point Knit Beanie - Aqua,Men's Kansas City Chiefs Nike Red Empower Knit Full-Zip Jacket.Infant Girl's Tampa Bay Buccaneers Gray Field Goal Creeper Set,Men's Buffalo Bills Nike Gray Wordmark T-Shirt,Womens Denver Broncos WinCraft Helmet Logo Necklace Understanding Jameis Winston.Women's San Francisco 49ers Canvas Stripe Shoes,Nike Cincinnati Bengals Fast Wordmark T-Shirt - Black,Mens Green Bay Packers Antigua Black Victor Quarter Zip Pullover Jacket Cheap Tampa Bay Buccaneers Mike Glennon Jersey.Mens Chicago Bears '47 Brand Charcoal Hanover 1/4 Button Pullover Sweatshirt,Men's Green Bay Packers Majestic Charcoal Heart & Soul III T-Shirt,Men's Green Bay Packers Majestic Charcoal Kick Return Pullover Hoodie NFL Jerseys Tampa Bay Buccaneers Outlet.Women's Chicago Bears Nike Gray Stadium Game Day Long Sleeve T-Shirt,Men's New York Jets Darrelle Revis Nike White Game Jersey.Dallas Cowboys Highland Mint 12" x 20" Man Cave Panoramic Photomint,Minnesota Vikings iPhone 6 Solid Case,Youth Baltimore Ravens Black Tactical Polar Fleece Full-Zip Jacket.Men's San Francisco 49ers Justin Smith Nike Scarlet Team Color Limited Jersey,Cincinnati Bengals Protoast MVP Team Logo Toaster

What Information is Protected

Protected Health Information. The Privacy Rule protects all "individually identifiable health information" held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information "protected health information (PHI)."12

“Individually identifiable health information” is information, including demographic data, that relates to:

and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual.13 Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number).

The Privacy Rule excludes from protected health information employment records that a covered entity maintains in its capacity as an employer and education and certain other records subject to, or defined in, the Family Educational Rights and Privacy Act, 20 U.S.C. §1232g.

De-Identified Health Information. There are no restrictions on the use or disclosure of de-identified health information.14 De-identified health information neither identifies nor provides a reasonable basis to identify an individual. There are two ways to de-identify information; either: (1) a formal determination by a qualified statistician; or (2) the removal of specified identifiers of the individual and of the individual’s relatives, household members, and employers is required, and is adequate only if the covered entity has no actual knowledge that the remaining information could be used to identify the individual.15


ePrescribing solution certified by Surescripts

Integrates with Practice Management Systems and EMR/EHR Systems

Sample Tracking Solution

A real time end-to-end Sample Management Solution that tracks and monitors sample activities

Patient Eligibility and Formulary Solution

Providers may request patient eligibility and formulary information with one click

Meds in the Office Solution

Physician can now keep track of all medications that are administered to
patients in the office

Appointment Scheduling Solution

Designed specifically to address the limitations and complexities found in traditional medical scheduling software

Patient Medication History Solution

Providers may request patient medication history information during office visit