Overview of the Privacy Rule
The HIPAA Privacy Rule, established under the Health Insurance Portability and Accountability Act of 1996, sets national standards for the protection of individually identifiable health information. It applies to covered entities and their business associates and governs how protected health information may be used and disclosed.
Covered Entities
The Privacy Rule applies to three categories of covered entities: health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with certain transactions. Business associates, who perform functions involving PHI on behalf of covered entities, are also bound by HIPAA requirements through business associate agreements.
Defining Protected Health Information
Protected health information, or PHI, includes any individually identifiable health information transmitted or maintained in any form, including electronic, paper, or oral communication. PHI includes 18 specific identifiers such as names, dates, geographic subdivisions smaller than a state, and medical record numbers.
Permitted Uses and Disclosures
Covered entities may use and disclose PHI without patient authorization for treatment, payment, and healthcare operations, commonly referred to as TPO. Other permitted disclosures without authorization include public health activities, reporting of abuse or neglect, judicial proceedings, and law enforcement purposes under specific conditions. All other uses and disclosures generally require written patient authorization.
The Minimum Necessary Standard
Covered entities must make reasonable efforts to limit PHI use, disclosure, and requests to the minimum necessary to accomplish the intended purpose, except for treatment purposes and certain other exceptions.
Individual Rights Under the Privacy Rule
- Right to access and obtain a copy of their health records
- Right to request amendment of their health information
- Right to receive an accounting of certain disclosures
- Right to request restrictions on uses and disclosures
- Right to receive a Notice of Privacy Practices
Enforcement and Penalties
The Office for Civil Rights enforces the Privacy Rule and can impose civil monetary penalties ranging from a few hundred dollars to over a million dollars per violation category per year, depending on the level of culpability. Criminal penalties may apply in cases of knowing violations or violations committed for personal gain.
Conclusion
Understanding the Privacy Rule is essential for HIM professionals responsible for release of information, patient rights requests, and organizational privacy compliance programs.