HIPAA Privacy Rule Deep Dive

HIPAA Privacy Rule Deep Dive

The HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) establishes national standards for the protection of individually identifiable health information. For RHIA candidates, a detailed understanding of the Privacy Rule is essential - it is one of the most heavily tested topics on the exam.

Scope and Applicability

The Privacy Rule applies to covered entities and their business associates. Covered entities include:

  • Health plans (insurance companies, HMOs, Medicare, Medicaid)
  • Healthcare clearinghouses (entities that process health information into standard formats)
  • Healthcare providers who transmit any health information electronically in connection with a HIPAA-covered transaction

A business associate is a person or organization that performs functions or activities on behalf of a covered entity that involve the use or disclosure of PHI. Examples include billing companies, transcription services, cloud storage vendors, and consultants. Business associate agreements (BAAs) are required contracts that establish the permitted uses and disclosures of PHI by the business associate.

Protected Health Information (PHI)

PHI is individually identifiable health information that is created or received by a covered entity and relates to the past, present, or future physical or mental health condition of an individual, the provision of healthcare, or payment for healthcare. PHI can exist in any form - electronic, paper, or oral.

The Privacy Rule identifies 18 identifiers that make health information individually identifiable:

  • Names
  • Geographic data smaller than a state
  • Dates (except year) related to an individual
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

Uses and Disclosures of PHI

The Privacy Rule distinguishes between uses and disclosures that require patient authorization and those that are permitted without authorization:

Permitted without authorization (key categories):

  • Treatment, payment, and healthcare operations (TPO): PHI may be used and disclosed for these core functions without patient authorization.
  • Public health activities: Reporting communicable diseases, vital events, adverse drug reactions, and FDA-regulated product issues.
  • Victims of abuse, neglect, or domestic violence: Disclosures to government authorities as required by law.
  • Health oversight activities: Audits, investigations, inspections, and licensure activities.
  • Judicial and administrative proceedings: In response to a court order or, with certain conditions, a subpoena.
  • Law enforcement purposes: Under specific circumstances, such as court orders, grand jury subpoenas, or to identify or locate a suspect.
  • Decedents: To coroners, medical examiners, and funeral directors.
  • Workers' compensation: As authorized by and necessary to comply with workers' compensation laws.

Patient Rights Under the Privacy Rule

RightDescriptionKey Details
Right to accessPatients may inspect and obtain a copy of their PHI in the designated record setMust respond within 30 days (one 30-day extension permitted). Reasonable cost-based fees allowed. Electronic copy must be provided if maintained electronically and patient requests it.
Right to amendPatients may request amendments to their PHIOrganization may deny if the record is accurate, was not created by the organization, or is not part of the designated record set. Must respond within 60 days.
Right to accounting of disclosuresPatients may request a list of disclosures of their PHICovers disclosures made in the six years prior to the request. Excludes disclosures for TPO, to the individual, for national security, and to correctional institutions.
Right to request restrictionsPatients may ask that uses or disclosures for TPO be restrictedOrganization is not required to agree to the restriction, except when the disclosure is to a health plan and the patient paid out of pocket in full.
Right to confidential communicationsPatients may request PHI be communicated by alternative means or at alternative locationsMust accommodate reasonable requests (e.g., calling a cell phone instead of a home phone).
Right to noticePatients must receive a Notice of Privacy Practices (NPP)NPP must describe uses and disclosures, patient rights, and the organization's legal duties. Must be provided at first service delivery.

Minimum Necessary Standard

The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI used, disclosed, or requested to the minimum amount needed to accomplish the intended purpose. This standard does not apply to disclosures to or requests by a healthcare provider for treatment, disclosures to the individual, uses or disclosures authorized by the individual, disclosures to HHS for enforcement, uses or disclosures required by law, and uses or disclosures required for HIPAA compliance.

De-identification

The Privacy Rule provides two methods for de-identifying PHI so that it is no longer subject to HIPAA protections:

  • Expert determination (statistical method): A qualified statistical or scientific expert determines that the risk of identifying an individual is very small.
  • Safe harbor method: All 18 identifiers are removed, and the covered entity has no actual knowledge that the remaining information could identify an individual.

Enforcement and Penalties

The Office for Civil Rights (OCR) within HHS enforces the Privacy Rule. Penalties are tiered based on the level of culpability, ranging from $100 per violation for unknowing violations up to $50,000 or more per violation for willful neglect. Annual caps apply at each tier. Criminal penalties (handled by the Department of Justice) can include fines and imprisonment for knowingly obtaining or disclosing PHI.

Exam Preparation Tips

For the RHIA exam, memorize the 18 PHI identifiers and the two de-identification methods. Understand when authorization is and is not required. Know patient rights thoroughly, especially access timelines and the mandatory restriction for self-pay patients. Be clear on the minimum necessary standard and its exceptions. Scenario-based questions frequently test whether a particular disclosure requires authorization or falls under a permitted category.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.