Healthcare Glossary

HIPAA

Compliance
Also called: Health Insurance Portability and Accountability Act, HIPAA privacy

HIPAA is the Health Insurance Portability and Accountability Act of 1996. It has two main pieces: portability (limiting pre-existing condition exclusions when workers change jobs, largely superseded by the ACA) and administrative simplification, which includes the Privacy Rule, Security Rule, and Breach Notification Rule that govern how protected health information (PHI) is used, shared, and safeguarded.

The Privacy Rule (effective 2003) sets national standards for who can access PHI and under what circumstances. Providers, health plans, and their business associates can use PHI for treatment, payment, and healthcare operations without specific patient consent, but must get authorization for most other uses. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI. The Breach Notification Rule requires notice to affected individuals, HHS, and (for large breaches) the media when unsecured PHI is compromised. Enforcement is by the HHS Office for Civil Rights, with penalties reaching seven figures for major violations. Business Associate Agreements (BAAs) are required whenever a covered entity shares PHI with a vendor performing services on its behalf.

The takeaway: if you handle any PHI as part of running a benefits program, you need BAAs in place with every vendor that touches the data. Missing BAAs are one of the most common HIPAA violations found in audits and one of the most preventable.