What is HIPAA?

Video 2 of 27
5 min 20 sec
English
English

In this lesson, you'll learn what HIPAA is, the role it plays in healthcare, and who is mandated to follow its requirements, along with relevant real-world examples.

What is HIPAA?

The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following:

  • Portability of insurance
  • Protection and privacy of healthcare information
  • Standardization and efficiency in healthcare data
  • Prevention of discrimination and fraud

What is HIPAA's Role in Healthcare?

HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals and companies keep important personal health information private.

HIPAA protects against unauthorized disclosure of any protected health information (PHI) that pertains to healthcare patients. It establishes a national set of security standards for protecting health information held or transferred in electronic form (ePHI). In addition to privacy and security, administrative provisions were included to improve system efficiency, including:

  • Specific transaction standards and code sets
  • National standard unique identifiers
  • Data security and electronic signatures

Pro Tip #1: HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance.

Legal Compliance Disclaimer

Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all federal and state requirements and should not rely on this training alone as a source of legal information or advice. To ensure compliance, covered entities and business associates should regularly perform risk assessments to track access to PHI, periodically evaluate security effectiveness, and re-evaluate potential risks.

Who is Mandated to Follow HIPAA's Requirements?

HIPAA law applies directly to two particular groups: Covered Entities and Business Associates.

What is a Covered Entity?

Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. (Note: Simply holding PHI does not by itself make an entity a covered entity.)

  • Healthcare Providers: Any provider of medical or health services, or any organization or person who transmits health information electronically in the normal course of business (e.g., physicians, nurses, dentists, hospitals, pharmacies, ambulance companies, social workers).
  • Health Plans: Any individual or group plan that provides or pays the cost of healthcare, such as an insurance company, Medicare, or Medicaid.
  • Healthcare Clearinghouses: A public or private entity that transforms healthcare transactions from one format into a required format (e.g., an outside billing service).

Pro Tip #2: HIPAA applies to employers only to the extent that they operate in one or more of these three groups. If a company offers healthcare services on-site (such as an on-site clinic), the employer would be considered a covered entity and required to follow HIPAA rules.

What is a Business Associate?

A business associate is any company or individual with access to Protected Health Information (PHI) or ePHI. Examples include IT vendors, laboratories, call centers, court reporters, cloud providers, and legal services.

Business associates are required to maintain a risk assessment, training, policies, and procedures. They must also safeguard PHI at all times, notify covered entities of any data breaches, and execute a Business Associate Agreement (BAA).

Contractual & Regulatory Violations

If a business associate violates HIPAA, they are not only in violation of their contract with the covered entity, but also in violation of federal HIPAA law itself and will be held accountable for penalties under both. Furthermore, if a business associate uses subcontractors, contractual agreements (BAAs) are required to hold those subcontractors to the exact same standards.

Related Q&A

What does HIPAA stand for?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996 (or simply the HIPAA Act). It is a United States privacy law with the intention to protect patient medical information and ensure confidential communication between patients and medical professionals.

What is HIPAA?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal U.S. law designed to provide privacy standards to protect sensitive patient health information provided to health insurers, billing companies, doctors, hospitals and other health care providers. The act is meant to ensure this sensitive information is not disclosed without the patient's consent or knowledge.