• Home
  • About Us
  • Services
    • Financial Improvement
    • Denial Management / Revenue Cycle
    • Physician Advisor Services
    • Clinical Operations / Improvement
    • Quality Improvement Programs
    • Accreditation
    • Human Resources / Interim Staffing
    • Training
  • Case Studies
  • FAQ
  • News
    • News and Events
    • Newsletter Sign Up
    • Read Newsletters
    • View our Blog
  • Careers
  • Library
  • Contact Us
  • Login
    • PRS
    • PM
 

Connect

Recent Posts

  • Exchange Development Could Advance As State’s Flexibility Increases
  • Hospitals May Be Pressured to Change
  • Exploring Medicaid Managed Care Expansion
  • BHM Appoints New Business Division Leader Kathleen Schoenauer
  • 7 Lessons Learned from the Swine Flu

Archives

  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • June 2011
  • May 2011
  • January 2011
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • April 2008
  • March 2008

Categories

  • Accreditation
  • Clinical Operations Improvement
  • Compliance
  • financial
  • Gues Post
  • Health Care Reform
  • Health Insurance
  • Healthcare Fraud and Abuse
  • Healthcare Prevention
  • Learning Series
  • News and Events
  • Quality Improvement Programs
  • Services
  • Uncategorized

Post navigation

← RAC Learning Series Part Four – Demystifying the Query (Audit) Process
HIPAA Security Explored →

Ten HIPAA Questions Answered

Posted on January 18, 2012 by Kathleen Rand

In this blog, we will review ten questions about the Health Insurance Portability and Accountability Act, or HIPAA. The legislation can seem overwhelming; sometimes breaking it down can make it much easier to digest.

Of course to ensure that your organization is prepared to overcome any compliance roadblock, please consult BHM regarding our HIPAA Compliance analysis: click here for more information

HIPAA security lock image

HIPAA ensures a 'lock' on privacy.

1. What is HIPAA?

The Health Insurance Portability and Accountability Act, or HIPAA, was passed by the federal government in 1996. The original intention of HIPAA

was to help guarantee the continuation of health insurance coverage when an individual left his or her job. Additionally, HIPAA was expanded to include a number of provisions in order to simplify and lower the costs of processing health information. A number of these provisions deal with the standardization of electronic transactions, particularly regarding security and privacy issues.

2. What is the HIPAA Security Rule?

HIPAA requires the implementation of security standards to help protect health information. Yet, it does not spell out any specific security requirements. HIPAA simply necessitates administrative, technical and physical safeguards to make sure that the integrity of health information remains confidential. These requirements have been defined and published in the HIPAA Security Rule by the Department of Health and Human Services.

4. What type of information is protected by HIPAA?

Health information is defined as any information, whether spoken or recorded in any form, that is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or healthcare clearinghouse. This information can be related to the past, present or future physical or mental health condition of an individual, the delivery of health care to an individual, or the past, present or future payment for the provision of healthcare to an individual.

5. Who must comply with the HIPAA Security Rule?

Any Health Plan, Health Care Clearinghouse or a Health Care Provider who transmits health information in electronic form must comply with the HIPAA Security Rule. A Health Plan is defined as an individual or group plan that provides or pays the cost of medical care. A Health Care Clearinghouse is defined as a public or private entity, including a billing service, re-pricing company, community health management information system or community health information system that does either of the following functions: (1) Processes health information received from another entity in a nonstandard format; or (2) Receives a standard transaction from another entity and processes health information into nonstandard format for the receiving entity. A Health Care Provider is defined as a provider of services, a provider of medical or health services and any other person or organization who delivers, bills or is paid for health care in the normal course of business.

6. What are the repercussions of non-compliance with HIPAA?

Failure to comply with HIPAA requirements could result in significant financial loss through civil penalties, not to mention damage to an organization’s reputation. HIPAA states that civil penalties up to $100 per day per person can be issued for non-compliance. While this does not seem like a large sum, it can quickly add up. For instance, if student health information was exposed for 1000 students over the course of 30 days, the fines could reach $3,000,000.

7. May a physician or hospital “fax” a patient’s medical information to other physicians or to an insurer?

Yes. The Privacy Rules do not prohibit a “covered entity” from faxing protected health information. A physician should be sure, however, to comply with the Privacy Rules’ requirements for disclosures generally. For example, the physician should check whether the “minimum necessary” rule applies and, if it does, limit the information in the fax to the minimum necessary information.

Also, a physician should be sure to have appropriate security safeguards in place that are administrative, technical, and physical in nature. For example, the physician should use policies and procedures that require office staff to verify the recipient’s fax number and use a cover sheet that does not include protected health information.

8. What is the “minimum necessary” standard?

HIPAA requires a physician to make reasonable efforts to limit the amount of protected health information that the physician uses or discloses to the minimum amount that is necessary to accomplish the purpose of the use or disclosure.

Importantly, this requirement does not apply when a physician discloses information to another provider for treatment purposes or when a physician requests information from another provider for treatment purposes. Accordingly, the minimum necessary standard should not interfere with a physician’s ability to provide appropriate treatment to patients.

9. May a physician discuss information about a patient’s treatment with other physicians using e-mail or fax?

Yes. Physicians may use any method of communication — including e-mail, oral conversations, written letters, or other methods (including sending facsimiles) — so long as the physician uses “reasonable and appropriate safeguards” to protect the communication. HIPAA does not prohibit a covered entity from emailing or faxing protected health information to a physician.

If a covered entity refers to the Privacy Rules as the reason the individual will not fax information to a physician, the physician may direct the covered entity to the Department of Health and Human Services’ Frequently Asked Questions at: http://www.hhs.gov/ocr/privacy/hipaa/faq/index.html. The physician may also assure the individual that appropriate safeguards are in place to receive the fax securely.

10. If a patient’s family members call to ask how their loved one is doing, what can the treating physician disclose?

HIPAA allows a physician to share a patient’s information with the patient’s family member or friend if the information is limited to what is directly relevant to that person’s involvement in the patient’s care. For example, a physician may tell a person living with the patient that the patient needs plenty of rest and lots of fluids or that the patient needs to take a prescribed medication twice daily with food. The physician should not share more information than the person needs to assist with the patient’s care.

A physician should not share a patient’s information with the patient’s family or friends if the patient has asked the physician not to, or if the physician believes, in his/her professional judgment, a disclosure would be inappropriate.

 

 

 

 

This entry was posted in Compliance and tagged BHM Healthcare Solutions, compliance healthcare, HIPAA, HIPAA Security, Privacy Rules. Bookmark the permalink.

Post navigation

← RAC Learning Series Part Four – Demystifying the Query (Audit) Process
HIPAA Security Explored →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

*

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


BHM Healthcare Solutions
Healthcare Management and Consulting Firm Improving Financial &
Operational Performance of Health Care Enterprises
Suite 102, 1033 Corporate Square Drive St. Louis, MO 63132
888-831-1171 Office, 888-818-2425 Fax
email: results@bhmpc.com

 


Copyright © 2011 BHM. All rights reserved
  • Home
  • |
  • About Us
  • |
  • Services
  • |
  • BHM Staff
  • |
  • Case Studies
  • |
  • Contact Us
  • |
  • FAQ
  • |
  • Newsletter
  • |
  • Careers
  • |
  • Privacy Policy & Terms of Use