Introduction to HIPAA Flashcards
A general introduction and overview of the federal HIPAA regulations
<b> HIPAA </b> stands for
<b>H</b>ealth <b>I</b>nsurance <b>P</b>ortability and <b>A</b>ccountability <b>A</b>ct
HIPAA’s intent is to…
…reform the healthcare industry by reducing costs, simplifying administrative processes and burdens, and improving the privacy and security of individuals’ health information.
<b>PHI</b> stands for
<b>P</b>rotected <b>H</b>ealth <b>I</b>nformation (<b>PHI</b>)
<b>PHI</b> definition
<b>PHI</b> is any identifiable health information relating to the past, present, or future health condition of the individual regardless of the form in which it is maintained (electronic, paper, oral format, etc).
<b>ePHI</b>
<i>Electronic</i> Protected Health Information, a subset of PHI
The two organization types that are regulated under HIPAA:
<ol>
<li>Covered Entities</li>
<li>Business Associates</li>
</ol>
Covered Entities definition
the source of of PHI; generate it. they have a direct relationship with individuals with PHI.
Covered Entities are ___ and required to be ____.
<i>directly regulated</i>, <i>HIPAA compliant (protecting PHI)</i>
Healthcare Clearinghouses are…
…covered entities that process nonstandard health information they receive from another entity into a standard format, or vice versa.
Business Associates are ____ and required to be ____.
<i>directly regulated</i>, <i>HIPAA compliant (protecting PHI)</i>
Business Associates definition
All third party vendors and business partners that create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity or another business associate.
Chain of Trust
formed by business associate contracts, where a covered entity shares PHI with contracted business associates, with 1 contract per link.
Business Associate contract
legal HIPAA document where the Business Associate legally attests to being HIPAA compliant, to either the Covered Entity or another Business Associate.
This enables sharing PHI from the attestee to the attester, wherein the attester becomes legally liable to fines and penalties.
Two main parts of HIPAA
<ol>
<li>HIPAA privacy</li>
<li>HIPAA security</li>
</ol>
HIPAA privacy
protections for PHI from a people standpoint