Complying with the Health Insurance Portability and Accountability Act. Privacy standards
- PMID: 11760704
Complying with the Health Insurance Portability and Accountability Act. Privacy standards
Abstract
The Privacy Rule: Limits the use and disclosure of PHI to purposes of treatment, payment, or routine health care operations. Requires covered entities to provide advance notice to the public of its policy governing disclosure of PHI. Requires entities covered by the Standard to secure general client consent to use and to disclose PHI for treatment, payment, or routine health care operations and to obtain specific client authorization to use or to disclose PHI for all other purposes unless the disclosure is specifically permitted without consent or authorization (e.g., a covered entity may disclose PHI to a health care oversight agency such as the Office of the Inspector General without first obtaining client authorization). In certain situations, a covered entity need only obtain client agreement to disclose PHI which may be oral or inferred from the circumstances surrounding the disclosure. For example, a covered entity could disclose PHI to a relative caring for the individual who is the subject of the health information. Expects covered entities to take measures to protect PHI from both inadvertent and deliberate misuse and disclosure. Requires, except in certain circumstances, the amount of PHI disclosed on any occasion to be limited to the minimum necessary to achieve the purpose of the disclosure. Gives individuals more control of their health information by permitting them to review and amend health information pertaining to themselves and to demand an accounting of persons to whom their health information has been disclosed. Establishes terms under which a covered entity may disclose PHI to a business associate. Permits states to maintain state laws that are more stringent than the Privacy Rule. The statute provides for significant civil and criminal penalties for failure to comply with the Standards. Violations are punishable by fines as much as $250,000 and 10 years imprisonment. The HHS, Office of Civil Rights is charged with enforcing the Standards. The HHS is expected to issue a single Enforcement Rule applicable to all three of the HIPAA Administrative Simplification Standards. Many worksite records will not be protected under the HIPAA Privacy Rule because employers are not covered entities and few occupational health professionals meet the criteria of being considered a covered entity. Nevertheless, occupational health professionals need to be knowledgeable about the application of HIPAA in the occupational health care setting. Furthermore, given that the Rule does not preempt state privacy laws that are more stringent than the Standards, occupational health professionals should monitor legislative activity related to privacy in the states in which they practice. To date, Oregon, Texas, and New Jersey have broadened HIPAA's definitions to create more covered entities and services.
Similar articles
-
Roadmap to HIPAA: keeping occupational health nurses on track.AAOHN J. 2004 Apr;52(4):169-77; quiz 178-9. AAOHN J. 2004. PMID: 15119817 Review.
-
Final HIPAA security regulations: a review.Manag Care Q. 2003 Summer;11(3):15-27. Manag Care Q. 2003. PMID: 14983648
-
Assembling the HIPAA privacy puzzle.Healthc Financ Manage. 2003 Jan;57(1):46-52. Healthc Financ Manage. 2003. PMID: 12553232
-
HIPAA privacy: the compliance challenges ahead.J Health Law. 2002 Winter;35(1):45-82. J Health Law. 2002. PMID: 11974522
-
HIPAA privacy regulations.Semin Speech Lang. 2006 May;27(2):89-100. doi: 10.1055/s-2006-939941. Semin Speech Lang. 2006. PMID: 16673257 Review.
Cited by
-
Research Electronic Data Capture (REDCap) in an outpatient oncology surgery setting to securely email, collect, and manage survey data.J Adv Nurs. 2024 Jun;80(6):2592-2597. doi: 10.1111/jan.15983. Epub 2023 Dec 2. J Adv Nurs. 2024. PMID: 38041582 Free PMC article.
-
THE GAP BETWEEN RESEARCH AND CLINICAL PRACTICE FOR INJURY PREVENTION IN ELITE SPORT: A CLINICAL COMMENTARY.Int J Sports Phys Ther. 2020 Dec;15(6):1229-1234. doi: 10.26603/ijspt20201229. Int J Sports Phys Ther. 2020. PMID: 33344038 Free PMC article.
-
Medical record information disclosure laws and policies among selected countries; a comparative study.J Res Med Sci. 2010 May;15(3):140-9. J Res Med Sci. 2010. PMID: 21526073 Free PMC article.
MeSH terms
LinkOut - more resources
Full Text Sources