HIPAA
About HIPAA (Health Insurance Portability and Accountability Act)
HIPAA compliance encompasses regulations for protecting consumer healthcare information, including privacy, security, breach notification, and enforcement rules. Covered entities, such as physician and dental practices, pharmacies, and electronic health record (EHR) firms, along with their business associates, are required to implement policies to ensure compliance accountability through risk analysis, limit access to Protected Health Information (PHI), conduct workforce training, and safeguard PHI. Since its implementation in 1996, HIPAA has transformed how organizations handle PHI to prevent data theft and ensure sensitive healthcare information is only disclosed to appropriate parties. Non-compliance with HIPAA regulations can result in penalties per day and per violation, with fines potentially reaching up to $50,000 per day for each violation until the violation is resolved.
HIPAA PRIVACY
The HIPAA Privacy Rule establishes federal safeguards to protect private protected health information and grants patients various rights about their health information. At the same time, allowing the disclosure of protected health information necessary for patient care and other crucial purposes.
The HIPAA Privacy Rule:
- Spells out administrative responsibilities
- Discusses written agreements between covered entities and business associates
- Discusses the need and implementation of privacy policies and procedures
- Describes employer responsibilities to train workforce members and implement requirements regarding their use and disclosure of PHI
The Privacy Rule has a broad scope, covering all healthcare providers, regardless of their use of electronic health records. It encompasses all mediums, including electronic, paper, and oral. It grants patients the right to access their protected health information and information on how their records are utilized or shared.
HIPAA SECURITY
The HIPAA Security Rule mandates that covered entities, business associates, and subcontractors implement safeguards to protect electronically protected health information (ePHI) that is created, received, transmitted, or maintained. It outlines a set of administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Failure to follow the established policies and procedures for safeguarding ePHI is the most common reason for violations of the HIPAA Security Rule.
The HIPAA Security Rule:
- Establishes a national set of security standards for ePHI.
- Protects health information held or transmitted in electronic form
- Requires administrative, physical, and technical safeguards to secure ePHI
- Supports the Privacy Rule requirement to safeguard PHI in all forms reasonably










