HIPPA

The Basics

HIPAA contains provisions for both privacy and security. Privacy rules have been promulgated and compliance was required by most health plans by April

14, 2003; plans with less than $5 million in annual receipts had until April 14,

2004 to fully comply. These rules have gone through several iterations, some as recently as March 2003 and refinements continue. Security rules that detail further requirements for the health care industry and patients were issued in October 2004.

A key factor for all health care providers and organizations to keep in mind is that, while HIPAA rules are strict, if state law covering the same topic is more stringent, the state law must be followed (Herrin, 2003). Health providers are well advised not to overlook state law as they accommodate HIPAA. Providers and organizations must remain up-to-date with both HIPAA and state law changes.

The intent of HIPAA is to protect patients from unauthorized or inappropriate use and access to their health information. Further, the rules protect patients by giving them access to their health information so they know what has been documented about their health status. Proposed by-products of HIPAA are to improve quality of care, restore trust in the health care system, and improve the efficiency and effectiveness of information dissemination by building on existing legal frameworks. HIPAA also contains an administrative simplification section designed to improve the efficiency of health information coding to facilitate digital transfer of information between and among health care providers, payers, and health plans.

HIPAA creates safeguards so that only those people or entities having a real need to know health information will be able to access it (Calloway and Venegas 2002). The HIPAA rules complement other standards that protect patients’ rights. Compliance with privacy rules promises to be a cornerstone of future JCAHO and Medicare/Medicaid surveys. Remember, compliance is mandatory, not voluntary.

WHY HIPAA IS NEEDED

Health care professionals have long realized the need to protect patients from unauthorized use of their health information; at the same time, they want to have access to needed information when treating a patient. Widespread use of electronic data is facilitating the rapid transfer of information and the Institute of Medicine has urged the creation of standards so electronic records can be available (Follansbee, 2002).

Similarly, the public is greatly concerned about the privacy of their medical records. Prior to the electronic medical record, patient information was maintained in paper form and neatly locked away, accessible only to those who had authorized access. With computerized records information can be accessed, changed, distributed, and copied with far less regard for appropriate authorization (Follansbee, 2002).

Serious breaches of record confidentiality have occurred. An employee of the Hillsborough county health department was able to carry home a disk with the names of 4000 HIV positive patients. People have purchased used computers that contained prescription records of patients; Eli Lilly recently sent out an email with the names of patients taking Prozac; the University of Montana inadvertently placed the medical records of some 62 people on the internet. Consequently, patients, health care providers, and other health care entities are very concerned about confidentiality, restoring the public trust, and protecting themselves from lawsuits.

Yet, the ability of multiple providers to access a patient’s record can significantly improve the overall quality of care. Think about the chronically ill individual who receives care from more than one or two specialist providers. If each provider has access to the most recent treatment plan, it stands to reason that care will be more coordinated, efficient, and effective.


UNDERSTANDING HIPAA - WHAT IS INCLUDED IN THE LAW

HIPAA describes those affected by the law as “covered entities”. Included under this umbrella are health care providers, health plans, health care clearinghouses, and business associates.

Health care providers are defined as anyone who is paid for health care services or bills for services provided. The list is all inclusive: physicians, licensed health care providers, hospitals, outpatient physical therapists, social workers, certified nurse midwives, technicians administering X-rays done at home, home health agencies, pharmacists, providers of home dialysis supplies and equipment, nursing homes, nurses, and nurse administrators. This list means that any hospital or health facility worker who may see confidential patient information is included.

A health plan is any individual or group that pays for health care services. Included are health maintenance organizations (HMOs), insurance companies, Medicare/Medicaid, self-insured plans, employee group plans, federal plans such as CHAMPUS, military, veteran’s administration, and Indian health services.

Clearinghouses are those entities that receive health information from providers and health plans. They typically are responsible for standardizing the information to improve claims processing. Included in this group are third-party administrators, billing services, and re-pricing agencies

The business associates category covers a broad range of professionals and services. Included are attorneys, consultants, auditors, accountants, billing firms, data processing companies, and practice management firms. Nurses working as independent contractors, i.e., case managers, legal nurse consultants, and educators are included and subject to compliance with HIPAA law. A contract between the business associate and hiring agent must be in place before the associate can see any patient information.

Prev
Next