1/22
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
HIPAA
Health Insurance Portability and Accountability Act
Four Components of HIPAA
standardized electronic data transactions, data security standards, privacy protections, and standard national identifiers

Privacy (HIPAA Definition)
the state of being concealed or secret
Confidentiality (HIPAA Definition)
containing private information, such as a patient’s medical record
Authorization (HIPAA)
a written document granting permission to use or disclose PHI for specific purposes
Disclosure vs. Use
disclosure is sharing PHI outside an entity; Use is handling PHI within an entity
Protected Health Information (PHI)
individually identifiable health data created or received by a covered entity
Examples of PHI
name, SSN, address, medical records, medical diagnoses, account numbers, and photos
Covered Entities (CE)
health plans, health care clearinghouses, and health care providers conducting electronic transactions
TPO
Treatment, Payment, and Health Care Operations (uses of PHI not requiring authorization)
Notice of Privacy Practice (NPP)
notice given to patients explaining how their PHI will be used and disclosed
Patient rights under HIPAA
rights to NPP, timely access/copies, amendment, restriction, disclosure accounting, and authorization revocation
HIPAA Privacy Rule Effective Date
April 14, 2003
Request for Amendment
patient’s written request to alter health records; CE can accept or deny
Accounting of Disclosures Timeline
a covered entity must respond to a written request within 60 days
Minimum Necessary Standard
requirement to disclose only the minimum amount of PHI needed to perform a job
Exceptions to Minimum Necessary Standard
treatment, disclosures to the patient, authorized disclosures, and disclosures required by law
Business Associate (BA)
a non-workforce person or entity performing functions involving PHI on behalf of a CE
Examples of Business Associates
third-party claims processors, CPA firms, medical transcriptionists, and pharmacy benefit managers
Incidental Disclosure
a secondary, unpreventable PHI disclosure occurring as a by-product of permitted use
HITECH Act (2009)
legislation adding privacy/security rules, breach reporting requirements, and increased non-compliance penalties

HITECH Breach Notification (>500 individuals)
requires reporting to affected individuals, the government, and prominent media outlets
Conflict Between State Law and HIPAA
follow whichever law provides greater privacy rights or protection to the patient