The Health Insurance Portability and Accountability Act (HIPAA) was originally introduced in 1996 to protect health insurance coverage for employees who lost or changed jobs. Today, HIPAA also includes mandates and standards governing how healthcare providers and other covered organizations transmit and protect sensitive patient health information.
HIPAA rules benefit both patients and providers by establishing standards for the privacy, security and handling of protected health information (PHI). They help healthcare organizations securely and efficiently store and share patient data while protecting it from unauthorized use and access. Failure to comply can result in significant penalties and other negative consequences, making it important for organizations to understand how HIPAA works and the key areas it covers.
HIPAA rules require that:
The HIPAA Privacy Rule outlines standards to protect all individually identifiable health information handled by covered entities or their business associates. This protected health information (PHI) includes a wide range of sensitive data, such as social security numbers, credit card information, and medical history, including prescriptions, procedures, conditions, and diagnoses.
PHI has long been a target of identity theft, so establishing strong privacy rules governing its use, access, and security is one of the most important parts of protecting patient data. The Privacy Rule addresses this risk by:
The Privacy Rule also includes limiting the release of PHI to the minimum required for disclosure (aka the Minimum Necessary Rule). In other words, under the Privacy Rule, information isn’t disclosed beyond what is reasonably necessary to protect patient privacy.
To ensure patient records and information are kept private, the Privacy Rule outlines:
What is a covered entity?
Organizations subject to HIPAA rules are called covered entities.
Covered entities include any organization or third party that handles or manages protected patient data, for example:
Additionally, business associates of covered entities must comply with parts of HIPAA rules.
Business associates are third-party organizations that need and have access to health information when working with a covered entity. Business associates can include contractors and subcontractors, companies that help doctors bill and process claims, lawyers and accountants, IT specialists and companies that store or dispose of medical data.
When can covered entities use or disclose PHI?
A covered entity cannot use or disclose PHI unless permitted under the Privacy Rule or by written authorization from the subject of the information.
Covered entities must disclose PHI to the individual upon request or to HHS for compliance investigations or enforcement.
Permitted uses and disclosures
Covered entities may use or disclose PHI without prior patient authorization for their own treatment, payment and health care operations. They are always allowed to share PHI with the individual. The Privacy Rule also makes exceptions for disclosure in the public interest, such as when required by law or for public health.
The HIPAA Security Rule establishes standards for protecting the electronic PHI (ePHI) that a covered entity creates, uses, receives or maintains. While the Privacy Rule governs the privacy and confidentiality of all PHI, including oral, paper and electronic forms, the Security Rule focuses on guidelines for securing electronic data.
A key goal of the Security Rule is to protect individuals’ private health information while still allowing covered entities to adopt new technologies that improve the quality and efficiency of patient care.
The Security Rule considers flexibility, scalability and technological neutrality. This means there are no specific requirements for the types of technology covered entities must use. Instead, covered entities can use any security measures that allow them to implement the standards appropriately. It is up to the covered entity to decide which security measures and technologies are best for its organization.
Under the Security Rule, covered entities must:
The Security Rule covers three main areas of security: administrative, physical and technical.
Administrative safeguards
Administrative safeguards are administrative actions, policies and procedures that develop and manage security measures that protect ePHI.
Administrative safeguards make up more than half of the Security Rule regulations and lay the foundation for compliance.
Covered entities must implement the following administrative safeguards:
Physical safeguards
HIPAA physical safeguards are any physical measures, policies and procedures used to protect a covered entity’s electronic information systems from damage or unauthorized intrusion. This includes the protection of buildings and equipment.
In other words, HIPAA rules require covered entities to consider and apply safeguards to protect physical access to ePHI.
HIPAA physical safeguard requirements include:
Technical safeguards
Under the Security Rule, technical safeguards apply to the technology itself, as well as the policies and procedures that govern its use, protect its electronic protected health information and control access to it.
Technical safeguards include:
Together, these safeguards help covered entities provide comprehensive, standardized security for all ePHI they handle.
The HIPAA Breach Notification Rule requires covered entities and business associates to provide notification of a breach involving unsecured PHI. A breach is any impermissible use or disclosure of PHI under the Privacy and Security Rules.
If a potential breach occurs, the organization must conduct a risk assessment to determine the scope and impact of the incident and confirm whether it falls under the notification requirement.
The risk assessment should be based on the following factors:
A covered entity is required to make a notification unless it can demonstrate a low probability that PHI was compromised. Breach notifications include individual notice, media notice, and notice to the secretary.
Individual notice
Following a breach, the organization must notify all impacted individuals. The notice must include a description of the breach and the types of information involved, what steps individuals should take to protect themselves from potential harm and what the covered entity is doing to investigate and address the breach.
Media notice
Covered entities must also notify the media (typically through a press release to local or regional outlets) if the breach affects 500 or more residents of a state or jurisdiction. The notice must include the same information as the notice to individuals and must be issued promptly, no later than 60 days following the discovery of the breach.
Notice to the Secretary
Covered entities are required to notify the Secretary of Health and Human Services whenever a breach occurs. If the breach affects fewer than 500 individuals, the covered entity must notify the Secretary within 60 days of the end of the calendar year in which the breach was discovered.
If the breach affects 500 or more individuals, the covered entity must notify the Secretary within 60 days of the discovery of the breach.
The three rules of HIPAA are cornerstones of regulation that protect the healthcare industry and consumers from fraud, identity theft and violations of privacy.
Through privacy, security, and notification standards, HIPAA regulations:
Failure to comply with HIPAA regulations can lead to costly penalties and even criminal liability. Access control runs underneath all three rules and this is where the Delinea Platform succeeds by securing the privileged accounts that can reach ePHI.
Delinea's audit and compliance solution gathers the access evidence auditors ask for across HIPAA, SOC 2, SOX and ISO 27001.
You can grant least privilege access to servers, databases and cloud infrastructure based on roles, attributes or just-in-time approval and then record the sessions. That leaves you a reviewable account of who touched ePHI and what they did with it, which is the evidence a HIPAA audit turns on.