HIPAA Privacy and Security
1996
Year
Updated 2013 HITECH
18
PHI Identifiers
From name to biometrics
60
Days
Breach notification deadline
eighteen identifiers, one rule
The 18 PHI Identifiers
Combined with health information, any one of these makes the data PHI. Removing one identifier alone does NOT de-identify — Safe Harbor requires removing all 18.
01
Name
02
Address
03
Dates
04
Phone
05
Fax
06
07
SSN
08
Med Record #
09
Health Plan #
10
Account #
11
License #
12
Vehicle ID
13
Device ID
14
URL
15
IP Address
16
Biometric
17
Full-face Photo
18
Other Unique
de-identification methods
Safe Harbor — remove all 18 identifiers. Expert Determination — qualified statistician verifies very small re-identification risk. Either method makes the data no longer PHI.
Two Rules + Breach Notification
privacy rule · 2003
Use and disclosure of PHI
Standards for who can see PHI and under what conditions. Minimum necessary applies.
security rule · 2005
Safeguarding ePHI
Administrative, physical, and technical safeguards for electronic PHI.
breach notification (HITECH 2009)
- › Notify affected individuals within 60 days of discovery
- › Notify HHS within 60 days for breaches of 500+ individuals
- › Media notification for breaches of 500+ in a single state
- › Smaller breaches reported to HHS annually
Exam Traps
HIPAA does not gag the employer
It restricts the group HEALTH PLAN. The employer-as-employer is not a covered entity. Asking why someone was absent is not by itself a HIPAA violation.
"Minimum necessary" applies INSIDE HR too
Even within HR, only the minimum PHI required for the task can be accessed. Need-to-know controls.
Business Associate Agreements are required
Any vendor handling PHI on behalf of a covered entity needs a BAA. No BAA = the covered entity is liable for the vendor's breach.
State law can be stricter
HIPAA preempts LESS-stringent state law. More-stringent state privacy laws survive preemption. The strictest applicable rule controls.
Plan, not employer
HIPAA covers the group health plan. Not the employer-as-employer. The firewall matters.
BAA before access
No vendor touches PHI without a Business Associate Agreement signed first. Skipping the BAA is the breach.
Patient files (PHI) belong to the office. The office is a HIPAA covered entity.
Friendly, but does not work at the office. Asking how the patient is doing is not a HIPAA matter.
Without permission, no files cross the boundary. That is the firewall HIPAA enforces.
If the office hires a billing vendor, the office gets a Business Associate Agreement signed first. Now the vendor is bound by the same rules.
Ready to test your PHR knowledge?
1,700+ practice questions written by certified professionals.
Start Practicing PHR