1. What is HIPAA?

The federal law known as “HIPAA” stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following: portability of insurance. protection and privacy of healthcare information. standardization and efficiency in health care data. prevention of discrimination and fraud. HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals keep their personal health information private. HIPAA protects from unauthorized disclosure of any protected health information that pertains to the patient. It establishes a national set of security standards for protecting certain health information that is held or transferred in electronic form. In addition to privacy and security, administrative provisions were also included in HIPAA to improve the efficiency and effectiveness of the health care system. These include: Specific transaction standards and code sets. National standard unique identifiers Data Security and electronic signatures. HIPAA compliance is highly dependent on the size, function, administration, and type of entity. Who is mandated to follow HIPAA requirements? A Health Plan is any individual or group plan that provides or pays the cost of healthcare such as an insurance company, Medicaid, or Medicare. So what is a Business Associate? A BAA states that the business associate will only use the protected health information for proper purposes and will safeguard it from misuse. A Business Associate must also comply with all security requirements of the HIPAA regulations that will ensure administrative, physical and technical safeguards to protect PHI. If a business associate violates HIPAA, they are not only in violation of the contract with the covered entity, but in violation with HIPAA itself. They will be held accountable for the penalties for both types of violations. If a business associate uses subcontractors, the HIPAA law requires contractual agreements between them. The subcontractor is held to the same HIPAA requirements in the use of PHI. Thank you for taking the time today to educate yourself on what is HIPAA!