HIPAA Privacy Rule Essentials

Protected Health Information (PHI)

PHI is individually identifiable health information that is transmitted or maintained in any form (electronic, paper, or oral) by a covered entity or business associate. There are 18 identifiers that make health information individually identifiable:

  1. Names
  2. Geographic data smaller than a state
  3. Dates (except year) related to an individual
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers and serial numbers
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers
  17. Full-face photographs
  18. Any other unique identifying number or code

Covered Entities and Business Associates

TypeDescriptionExamples
Health PlansEntities that provide or pay the cost of healthcareHealth insurance companies, HMOs, Medicare, Medicaid
Healthcare ClearinghousesEntities that process health information between nonstandard and standard formatsBilling services, repricing companies
Healthcare ProvidersProviders who transmit health information electronicallyHospitals, physicians, pharmacies, labs
Business AssociatesPersons or entities performing functions on behalf of a covered entity involving PHIBilling companies, EHR vendors, attorneys, accountants

Minimum Necessary Standard

Covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request. Exceptions to the minimum necessary standard include:

  • Disclosures to or requests by a healthcare provider for treatment purposes
  • Disclosures to the individual who is the subject of the information
  • Uses or disclosures made pursuant to a valid authorization
  • Disclosures to HHS for compliance investigations
  • Uses or disclosures required by law

Patient Rights Under the Privacy Rule

RightDetailsTimeframe
Right of AccessPatients can inspect and obtain a copy of their PHI in a designated record set30 days (one 30-day extension permitted)
Right to AmendPatients can request amendments to their PHI; denial allowed if information is accurate60 days (one 30-day extension permitted)
Right to Accounting of DisclosuresPatients can receive a list of disclosures made in the prior 6 years (excludes TPO, patient-authorized, and others)60 days (one 30-day extension permitted)
Right to Request RestrictionsPatients can ask to restrict uses/disclosures; covered entity generally not required to agreeNo specific timeframe
Right to Confidential CommunicationsPatients can request PHI be sent by alternative means or to alternative locationsMust accommodate reasonable requests
Right to Notice of Privacy PracticesPatients must receive a description of how their PHI may be used and disclosedAt first service delivery

Treatment, Payment, and Operations (TPO)

PHI may be used or disclosed without patient authorization for:

  • Treatment: Provision, coordination, or management of healthcare (e.g., sharing records between consulting physicians)
  • Payment: Activities related to obtaining reimbursement (e.g., claims processing, eligibility determinations, utilization review)
  • Healthcare Operations: Administrative and quality activities (e.g., quality assessment, training programs, compliance activities, business planning)

When Authorization Is Required

A valid authorization must be obtained for uses and disclosures not otherwise permitted or required. Required elements include:

  • Description of the information to be used or disclosed
  • Name or class of persons authorized to make the disclosure
  • Name or class of persons to whom the disclosure may be made
  • Purpose of the use or disclosure
  • Expiration date or event
  • Signature and date of the individual
  • Right to revoke the authorization in writing

Authorizations are always required for: psychotherapy notes, marketing communications, and sale of PHI.

Permitted Disclosures Without Authorization (Beyond TPO)

  • As required by law (e.g., court orders, subpoenas)
  • Public health activities (e.g., reporting communicable diseases)
  • Victims of abuse, neglect, or domestic violence
  • Health oversight activities (e.g., audits, investigations)
  • Judicial and administrative proceedings
  • Law enforcement purposes (under specific conditions)
  • Decedents - to coroners, medical examiners, funeral directors
  • Organ and tissue donation
  • Research with IRB or Privacy Board waiver of authorization
  • To avert a serious threat to health or safety
  • Workers compensation

Breach Notification Requirements

Breach SizeNotification RequirementTimeframe
Fewer than 500 individualsNotify affected individuals and log for annual report to HHSWithin 60 days of discovery; annual log submitted to HHS
500 or more individualsNotify affected individuals, HHS, and prominent media outlet in the stateWithin 60 days of discovery - without unreasonable delay

A breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. Exceptions include unintentional acquisition by workforce members acting in good faith, inadvertent disclosures between authorized persons, and situations where the recipient could not reasonably retain the information.

Notice of Privacy Practices (NPP)

  • Must be provided to patients at first service delivery
  • Must describe uses and disclosures of PHI, patient rights, and the entity's legal duties
  • Must be posted in a clear and prominent location at the facility
  • Must be available on the covered entity's website if one exists
  • A good-faith effort must be made to obtain a written acknowledgment of receipt

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.