HIPAA Privacy Rule
Introduction
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 includes privacy and security provisions that protect individually identifiable health information. The HIPAA Privacy Rule (45 CFR Parts 160 and 164) establishes national standards for the protection of protected health information (PHI) . The rule governs how covered entities and business associates may use and disclose PHI.
Protected Health Information
Protected health information is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium. PHI includes demographic information, medical history, test results, insurance information, and any other information that identifies the individual or could reasonably be used to identify the individual.
De-identified health information —information from which identifiers have been removed —is not PHI and is not subject to the Privacy Rule.
Covered Entities and Business Associates
The Privacy Rule applies to covered entities: healthcare providers who conduct electronic transactions, health plans, and healthcare clearinghouses. The rule also applies to business associates —persons or entities that perform functions or services involving PHI for a covered entity.
Covered entities must enter into written business associate agreements that require business associates to safeguard PHI and to report breaches.
Permitted Uses and Disclosures
The Privacy Rule permits uses and disclosures of PHI for treatment, payment, and healthcare operations without patient authorization. Treatment includes the provision of healthcare and related services. Payment includes activities to obtain reimbursement for healthcare. Healthcare operations include quality assessment, licensing, and business management.
Uses and disclosures for other purposes generally require the individual’s written authorization. Authorizations must specify the information to be disclosed, the purpose of the disclosure, and the expiration date.
Enforcement
The Department of Health and Human Services Office for Civil Rights (OCR) enforces the Privacy Rule. Penalties for violations are tiered based on the level of culpability, ranging from $100 to $50,000 per violation, with a maximum annual penalty of $1.5 million.
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, the Secretary of HHS, and, in certain cases, the media of breaches of unsecured PHI. Notification must be made without unreasonable delay and within 60 days of discovery.
Conclusion
The HIPAA Privacy Rule establishes national standards for protecting the privacy of health information. The rule governs the use and disclosure of PHI by covered entities and business associates, requires patient authorization for most non-treatment uses, and provides enforcement mechanisms for violations.