Compliance with Access, Use, and Disclosure of PHI Glossary

Compliance Glossary for the RHIA Exam

Regulatory compliance is a critical domain for RHIA professionals. This glossary defines essential terms related to healthcare privacy, security, legal requirements, accreditation, and the regulatory frameworks that govern health information management in the United States.

Abuse (Healthcare)
Practices that are inconsistent with accepted fiscal, business, or medical practices and result in unnecessary costs, improper payment, or payment for services not medically necessary. Unlike fraud, abuse does not require intent to deceive.
Accreditation
A voluntary process by which an organization is evaluated against established standards by an external body. In healthcare, accrediting organizations include The Joint Commission, CARF, and DNV GL.
Advance Directive
A legal document in which a person specifies actions to be taken regarding their health if they become unable to make decisions. Common forms include living wills and durable power of attorney for healthcare.
Amendment (HIPAA)
A patient's right under HIPAA to request that a covered entity modify protected health information in a designated record set. The covered entity may accept or deny the request with written justification.
Authorization (HIPAA)
A detailed document signed by the patient that gives covered entities permission to use or disclose protected health information for purposes other than treatment, payment, or healthcare operations.
Breach Notification Rule
A HIPAA requirement that covered entities and business associates notify affected individuals, the HHS Secretary, and in some cases the media, following a breach of unsecured protected health information.
Business Associate
A person or entity that performs certain functions or activities on behalf of a covered entity that involve the use or disclosure of protected health information. Business associates must comply with HIPAA requirements through a business associate agreement.
Centers for Medicare and Medicaid Services (CMS)
The federal agency within HHS that administers the Medicare program, works with state governments to administer Medicaid, and oversees the Health Insurance Marketplace. CMS sets conditions of participation for healthcare facilities.
Conditions of Participation (CoP)
Federal regulations that healthcare organizations must meet to participate in Medicare and Medicaid programs. CoPs address various aspects of patient care, governance, and record-keeping.
Consent
The process by which a patient agrees to receive treatment or to allow the use or disclosure of health information. Informed consent requires that the patient understands the nature, risks, and benefits of a proposed action.
Corporate Compliance Program
An internal system of policies, procedures, and controls designed to prevent, detect, and correct violations of laws and regulations. The OIG recommends seven elements for an effective compliance program.
Covered Entity
Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically. Covered entities must comply with HIPAA Privacy, Security, and Breach Notification Rules.
De-identification
The process of removing or altering data so that it can no longer be used to identify an individual. HIPAA provides two methods for de-identification - the Expert Determination method and the Safe Harbor method.
Designated Record Set
A group of records maintained by or for a covered entity that includes medical records, billing records, enrollment records, and any other records used to make decisions about individuals.
Electronic Health Record (EHR)
A digital version of a patient's health record that is maintained over time and may include data from multiple providers and facilities. EHRs must meet certification criteria established by the Office of the National Coordinator for Health IT.
e-Discovery
The process of identifying, collecting, and producing electronically stored information in response to a legal request or litigation. Healthcare organizations must have policies for preserving and producing electronic health records.
False Claims Act
A federal law that imposes liability on persons and organizations who defraud government programs, including Medicare and Medicaid. The Act includes qui tam provisions that allow whistleblowers to file lawsuits on behalf of the government.
Fraud (Healthcare)
An intentional deception or misrepresentation made with the knowledge that the deception could result in unauthorized benefit. Examples include billing for services not rendered and upcoding.
Health Insurance Portability and Accountability Act (HIPAA)
A 1996 federal law that established national standards for the protection of health information. HIPAA includes the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule.
HITECH Act
The Health Information Technology for Economic and Clinical Health Act of 2009, which strengthened HIPAA enforcement, expanded breach notification requirements, and promoted the adoption of electronic health records through meaningful use incentives.
Informed Consent
A legal and ethical requirement that healthcare providers explain a proposed treatment, including its risks, benefits, and alternatives, and obtain the patient's voluntary agreement before proceeding.
Institutional Review Board (IRB)
A committee that reviews and approves research involving human subjects to ensure ethical standards are met and participants' rights are protected. IRBs evaluate whether the use of health information in research complies with privacy regulations.
Minimum Necessary Standard
A HIPAA requirement that covered entities limit the use, disclosure, and request of protected health information to the minimum amount needed to accomplish the intended purpose. This standard does not apply to treatment disclosures.
Notice of Privacy Practices (NPP)
A document that a covered entity must provide to patients describing how their protected health information may be used and disclosed, and informing them of their rights under HIPAA.
Office for Civil Rights (OCR)
The division within the U.S. Department of Health and Human Services responsible for enforcing HIPAA Privacy and Security Rules. OCR investigates complaints and conducts compliance audits.
Office of Inspector General (OIG)
An independent office within HHS that protects the integrity of HHS programs and the well-being of beneficiaries. The OIG publishes compliance guidance, the Work Plan, and the List of Excluded Individuals and Entities.
Patient Rights
Legal entitlements that protect patients in healthcare settings, including the right to access records, request amendments, receive an accounting of disclosures, and file complaints regarding privacy violations.
Protected Health Information (PHI)
Individually identifiable health information that is transmitted or maintained by a covered entity in any form - electronic, paper, or oral. PHI includes 18 specific identifiers defined by HIPAA.
Qui Tam
A provision of the False Claims Act that allows private citizens (whistleblowers) to file lawsuits on behalf of the government against entities that have defrauded government programs. Successful qui tam plaintiffs receive a percentage of recovered funds.
Release of Information (ROI)
The process of disclosing patient health information to authorized requestors in compliance with applicable laws and regulations. ROI policies ensure that disclosures meet HIPAA requirements and state privacy laws.
Safe Harbor Method
One of two HIPAA-approved methods for de-identifying protected health information. It requires the removal of 18 specified identifiers and confirmation that the remaining information cannot be used to identify an individual.
Security Rule (HIPAA)
The HIPAA rule that establishes national standards for protecting electronic protected health information. It requires covered entities to implement administrative, physical, and technical safeguards.
Stark Law
A federal law that prohibits physicians from referring Medicare or Medicaid patients for designated health services to entities with which the physician or an immediate family member has a financial relationship, unless an exception applies.
Subpoena
A legal order compelling an individual to appear in court or produce documents. A subpoena duces tecum specifically requests the production of documents such as medical records.
Treatment, Payment, and Healthcare Operations (TPO)
Under HIPAA, the three purposes for which a covered entity may use or disclose protected health information without patient authorization. These categories encompass most routine uses of health information.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.