Introduction:
The Health Insurance Portability and Accountability Act of 1996 (HIPAA), also known as “Kennedy-Kassebaum”, passed congress rapidly and with great bipartisan support in 1996. Many aspects of the legislation have been implemented in the ensuing years; the deadline for full implementation of the privacy and confidentiality requirements was April 14, 2003. Health care providers and organizations have strict guidelines that must be followed to remain within the law. While this module and most of our attention now is focused on the provisions of the legislation that deal with privacy, confidentiality, and security of patient records, HIPAA also contains other requirements that have an impact on employers, insurance companies, and purchasers of health insurance coverage.
HIPAA was designed to address public concerns about managed care, insurance availability, and insurance affordability. For example, HIPAA prohibits insurance companies from denying coverage because of:
preexisting conditions,
a family member’s health status, or
whether or not an individual has been covered under a group policy and is seeking a personal health insurance policy.
Further, HIPAA ensures immediate coverage without regard to pre-existing conditions for individuals who change jobs and insurance carriers. HIPAA also established a pilot program for medical savings accounts (MSAs) that allows individuals to create a “health insurance individual account” to purchase health services and retain unspent funds rather than paying monthly premiums. Further, to encourage the purchase of long-term care insurance, HIPAA allows employers to deduct premiums and most benefits are tax-free to the beneficiary. Additionally, to facilitate purchase of health insurance by self- employed persons, the law allows 80% of the annual premiums to be tax- deductible by 2006. While many health policy analysts agree that these provisions have little impact on reducing the number of uninsured, they do, however, think these efforts are worthwhile. At this time, however, attention to HIPAA is riveted on implementing and paying for the privacy, confidentiality, and security aspects of the legislation (DiBenedetto, 2003).
In 1996, HIPAA was viewed as a way to reduce administrative costs, provide better access to health information, reduce fraud, and guaranty privacy of health information. However, the American Hospital Association estimates that it may cost between $4 billion and $22 billion to implement the tenets of the law. A search of the literature failed to produce specifics regarding cost; however, according to Gue and Upham (2004), the majority of costs are associated with developing and implementing software that integrates providers, payers, and governmental agencies.
As part of the HIPAA rule promulgation, the Centers for Medicare and Medicaid Services CMS mandated standardization of transaction and code sets (TSC) to reduce duplication, confusion, and non-compliance. CMS standards rely on use of ICD-9 codes for disease classification, CPT codes for procedures, and national drug codes (NDC) for medications. CMS admits that problems with these coding sets exist; new ICD-10-CM and ICD-10-PCS are thought to reduce the ambiguity and facilitate full implementation of electronic processing. The industry is working toward integrating HIPAA fully, it is just taking longer than they hoped to get the electronic interfaces coordinated (Gue and Upham 2004).
HIPAA is just the beginning of the ultimate conversion of healthcare information into an electronic health record (EHR). The Bush administration projects it will cost $100 million a year for 10 years primarily to fund demonstration projects and trial programs aimed at achieving four major goals:
establish routine use of EHRs in clinical practice,
connect health care workers in information exchange for clinical decision making,
enhance patients’ ability to choose providers based on quality, and
integrate public health surveillance systems into an interoperable network to support new research and better care (Scott 2004, p. 34).