HIPAA Privacy Rule Flashcards
HIPAA acronym
Health Insurance Portability and Accountability Act
Privacy Rule was passed in what year?
2003
Security Rule was passed in what year?
2005
The privacy rule establishes the ______
minimum
(NOTE: if state and federal are diff, follow the most stringent one)
What is privacy?
Freedom from unauthorized intrusion
What is confidentiality?
requires HC providers to protect heath records from unauthorized use
(NOTE: may be written or verbal)
What title # of HIPAA pertains to privacy and security?
Title II
What forms of info does the Privacy rule cover?
oral, written, and electronic
What forms of info does the Security rule cover?
Only electronic info
PHI acronym
Protected health info
What does HIPAA lack?
a private right of action
(NOTE: means that a pt can’t sue for HIPAA violation, only an attorney or general gov)
Purpose of HITECH (2009) (2)
- Strengthens privacy and security of PHI (i.e. use of EHRs)
- increased penalties
What is health info per HIPAA?
Any info (whether oral or recorded in any form) that is created or received by a health care provider, health plan, employer, life insurer, school
AND relates to the past, present, or future phys/mental health of an individual
What happens if health info is not dated?
Applies to the future
(no end date)
What 6 things does HIPAA provide the patient the right of?
- access
- request amendment
- accounting of disclosure
- request confidential communications
- request restrictions
- complain of privacy rule violations
Who does HIPAA apply to? (2)
- Covered entities (+ workforces)
- Business associates (+ workforce and subcontractors)
What is covered under HIPAA?
PHI (and any “HIPAA identifiers” that point to a certain pt)
What is NOT covered under HIPAA? (2)
- De-identifiied info
- personnel and edu records
Three HIPAA CEs:
- Healthcare provider
- Health plan
- Healthcare clearinghouse
CE: Healthcare provider description
doctor
CE: Health plan description
insurance plan
CE: Healthcare Clearinghouse description
3rd party billing vendor
Should HIPAA be politicalized?
No
An example of an organization that would need a business associate agreement is…
a) housekeeping service
b) Hospital where dr refers patients for surgery
c) Healthcare organization’s employees
d) Billing service that the healthcare organization uses
d) Billing service that the healthcare organization uses
HIPAA Applicability: What is a Business Associate (BA)?
Any person or org that provides services around PHI or its disclosure
(ex: 3rd party vendors, consultants, etc)
What is a Business associate agreement (BAA)? Does it apply to subcontractors?
Legally protects info handled by BA that complies with HIPAA
Yes
Components of a BAA (3):
- written
- specifies permitted/prohibited uses
- assurances of safeguards to prevent unauthorized use
What law added more BA categories?
HITECH
If a health care facility accepts cash or provides free services, like a clinic that provides physical exams, administers vaccines, and gives well baby check-ups regulated by HIPAA?
No; free services are not CE
Are wearable devices that collect PHI covered by HIPAA?
No
Are artificial intelligence (AI) programs that analyze patient data considered BAs?
No
What was added to the 2024 HIPAA update?
- strengthened reproductive privacy
- reward, similar to qui tam
- increased care coordination for SUD records
What is a workforce?
Any individual working under the CE’s direct control
(paid employees, volunteers, trainers, interns, outsourced vendors)
What are the three components for determining PHI?
- identifies a person or a reasonable basis to believe a person could be identified
- relates to one’s health condition
- is held or transmitted by a CE or its BA