Get certified in HIPAA for just $29.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
You may be asking yourself, so what is HIPAA? The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following. Portability of insurance. Protection and privacy of healthcare information. Standardization and efficiency in health care data. And prevention of discrimination and fraud. HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals keep their personal health information private. HIPAA protects from unauthorized disclosure of any protected health information that pertains to the patient. It establishes a national set of security standards for protecting certain health information that is held or transferred in electronic form. In addition to privacy and security, administrative provisions were also included in HIPAA to improve the efficiency and effectiveness of the health care system. These include specific transaction standards and code sets. National standard and unique identifiers, and Data Security and electronic signatures. HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance. Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all of their federal and state requirements and should not rely on this training alone as a source of legal information or advice. In addition to ensure compliance with HIPAA, covered entities and business associates should regularly perform a risk assessment to track access to protected your health information and periodically evaluate the effectiveness of security measures put in place. They should also regularly re-evaluate potential risks to protected health information. Who is mandated to follow HIPAA requirements? HIPAA applies to 2 groups: Covered Entities and Business Associates. Covered Entities are health plans, health care clearinghouses, and health care providers that transmit protected health information (or PHI) electronically in connection with a covered transaction. As a side note, simply holding protected health information does not by itself make someone a covered entity. So what is a Health Care Provider? Well, it’s any provider of medical or other health services, or any organization or person who transmits any health information in electronic form. This includes organizations and individuals that provide bills or are paid in connection with services in the normal course of business. Some common examples include: physicians, dentists, optometrists, nurses, mental health providers, radiology centers, chiropractors, psychologists, pharmacies, durable medical equipment providers, hospitals, ambulance companies, home health workers, and social workers. A Health Plan is any individual or group plan that provides or pays the cost of healthcare such as an insurance company, Medicare, or Medicaid. A Health Care Clearinghouse is a public or private entity that transforms healthcare transactions from one form to another into a required format. An example of this would be an outside billing service that ensures all information transferred between a doctor’s office and an insurance company complies with HIPAA. HIPAA applies to employers only to the extent that they somehow operate in one or more of these three groups. The same standards apply to covered entities in both the public and private sectors. If a company offers health care and treatment to employees on-site, such as an on-site clinic, the employer would be a covered entity and be required to follow HIPAA requirements. So what is a Business Associate? A business associate is any company or individual with access to Protected Health Information, or ePHI. A Business Associate is required to have a risk assessment, training, policies and procedures just like a covered entity. Some examples of a business associate are IT vendors, laboratories, call centers, court reporters, cloud providers, legal services, suppliers and manufacturers with access to PHI or ePHI. Business associates are required to protect PHI at all times just like a covered entity. They are required to notify covered entities of any potential and active data breaches. Business associates must comply with HIPAA requirements by signing a contractual agreement with the covered entity. This is called a Business Associate Agreement or BAA. A BAA states that the business associate will only use the protected health information for proper purposes and will safeguard it from misuse. A Business Associate must also comply with all security requirements of the HIPAA regulations that will ensure administrative, physical and technical safeguards are in place to protect PHI. If a business associate violates HIPAA, they are not only in violation of the contract with the covered entity, but in violation with HIPAA itself. They will be held accountable for the penalties for both types of violations. If a business associate uses subcontractors, the HIPAA law requires contractual agreements between them. The subcontractor is held to the same HIPAA requirements in the use of PHI. Thank you for taking the time today to educate yourself on just what is HIPAA.
In this lesson, you'll learn what HIPAA is, the role it plays in healthcare, and who is mandated to follow its requirements, along with relevant real-world examples.
The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following:
HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals and companies keep important personal health information private.
HIPAA protects against unauthorized disclosure of any protected health information (PHI) that pertains to healthcare patients. It establishes a national set of security standards for protecting health information held or transferred in electronic form (ePHI). In addition to privacy and security, administrative provisions were included to improve system efficiency, including:
Pro Tip #1: HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance.
Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all federal and state requirements and should not rely on this training alone as a source of legal information or advice. To ensure compliance, covered entities and business associates should regularly perform risk assessments to track access to PHI, periodically evaluate security effectiveness, and re-evaluate potential risks.
HIPAA law applies directly to two particular groups: Covered Entities and Business Associates.
Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. (Note: Simply holding PHI does not by itself make an entity a covered entity.)
Pro Tip #2: HIPAA applies to employers only to the extent that they operate in one or more of these three groups. If a company offers healthcare services on-site (such as an on-site clinic), the employer would be considered a covered entity and required to follow HIPAA rules.
A business associate is any company or individual with access to Protected Health Information (PHI) or ePHI. Examples include IT vendors, laboratories, call centers, court reporters, cloud providers, and legal services.
Business associates are required to maintain a risk assessment, training, policies, and procedures. They must also safeguard PHI at all times, notify covered entities of any data breaches, and execute a Business Associate Agreement (BAA).
If a business associate violates HIPAA, they are not only in violation of their contract with the covered entity, but also in violation of federal HIPAA law itself and will be held accountable for penalties under both. Furthermore, if a business associate uses subcontractors, contractual agreements (BAAs) are required to hold those subcontractors to the exact same standards.
HIPAA stands for the Health Insurance Portability and Accountability Act of 1996 (or simply the HIPAA Act). It is a United States privacy law with the intention to protect patient medical information and ensure confidential communication between patients and medical professionals.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal U.S. law designed to provide privacy standards to protect sensitive patient health information provided to health insurers, billing companies, doctors, hospitals and other health care providers. The act is meant to ensure this sensitive information is not disclosed without the patient's consent or knowledge.