HIPAA Compliance - Understanding the Basics

The Health Insurance Portability and Accountabilityimplementation specifications. Required
Act (HIPAA) has changed the healthcarespecifications must be adopted and administered
information security landscape in the U.S.as dictated by the rule.
Compliance has become a critical issue for allAddressable specifications are more flexible. Yet
organizations that come in contact with healthaccording to the rules for both required and
information. Here is a summary the HIPAA basics.addressable specifications, how organizations
HIPAA, also known as the Kennedy-Kassebaumsatisfy individual security requirements and which
Act, was signed into law by the U.S. Congress intechnology they choose are left to the business
1996 to establish health insurance reform anddecisions of each entity.
healthcare administrative simplification for variousHealthcare organizations face fines for
healthcare entities including: health plans, healthcarenoncompliance with HIPAA regulations. Penalties
clearinghouses such as billing services andinclude the following: general fines of up to
community health information systems, and$25,000 per incident, as well as up to $50,000,
healthcare providers that transmit healthcare dataimprisonment for not more than one year, or
in a way that is regulated by HIPAA.both for wrongful disclosure of individually
Governed by HHS, HIPAA Title I supports theidentifiable health information.
continuation of health insurance coverage forHIPAA Fines are Real
workers and their families when they change orIn July 2008, HHS announced a formal action
lose their jobs. Title II defines numerous offensesagainst Providence Health & Services. HHS
relating to healthcare and healthcare-relatedrequired Providence to pay $100,000 and
information and sets civil and criminal penalties forimplement a detailed Corrective Action Plan to
agencies that fail to abide by HIPAA standards.ensure that it will appropriately safeguard
The most significant provisions of Title II for ITidentifiable electronic patient information against
organizations are its Administrative Simplificationtheft or loss.
rules. Per the requirements of Title II, HHS hasThis case emphasizes that there is a renewed
established five rules regarding Administrativeinterest in HIPAA and sends a clear message that
Simplification:HHS has the authority and intent to take
- Privacy Ruleenforcement action. This has been a debate of
- Transactions and Code Sets Rulesorts ever since the passage of HIPAA. These
- Security Rulematters are frequently resolved on a consultative
- Unique Identifiers Rulebasis with HHS Office of Civil Rights (OCR).They
- Enforcement Ruleprefer to work with the healthcare organization to
Various security standards apply to each of theseresolve problems. The HHS Office of Inspector
rules, particularly for the Security Rule, whichGeneral (OIG), however, has been critical of HHS'
establishes three main security objectives:lack of enforcement activity in the past.
Administrative Safeguards, Physical Safeguards,Providence is an example that shows HHS can
and Technical Safeguards. Each safeguard areaand will act for HIPAA violations.
includes both required and addressable