HIPAA

HIPAA (the Health Insurance Portability and Accountability Act of 1996) is the US federal law whose Privacy, Security and Breach Notification Rules govern how health plans, healthcare providers, clearinghouses and their business associates may use, disclose and protect individually identifiable health information.

Also called: Health Insurance Portability and Accountability Act, HIPAA compliance

HIPAA applies to “covered entities”, health plans, healthcare clearinghouses, and providers that transmit health information electronically, and, since the 2009 HITECH Act, directly to their “business associates”: any outside organization that creates, receives, maintains or transmits protected health information on a covered entity’s behalf. A service that answers a clinic’s phone and takes down a patient’s name and symptoms is handling PHI and is a business associate.

The Privacy Rule limits uses and disclosures of PHI to what is permitted or authorized and gives patients rights over their records. The Security Rule requires administrative, physical and technical safeguards for electronic PHI, chosen through a documented risk analysis rather than a fixed checklist. The Breach Notification Rule sets out who must be told, and when, if PHI is exposed.

There is no government HIPAA certification for a product or vendor. The Department of Health and Human Services’ Office for Civil Rights enforces the rules; whether a particular arrangement satisfies them is a question for the covered entity and its advisers, and the business associate agreement is where the obligations are written down.