Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, you'll learn what HIPAA is, the role it plays in healthcare, and who is mandated to follow its requirements, along with relevant real-world examples.
The federal law known as HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Congress passed this landmark law to provide the following:
HIPAA gives the U.S. Department of Health and Human Services the responsibility of adopting rules to help individuals and companies keep important personal health information private.
HIPAA protects against unauthorized disclosure of any protected health information (PHI) that pertains to healthcare patients. It establishes a national set of security standards for protecting health information held or transferred in electronic form (ePHI). In addition to privacy and security, administrative provisions were included to improve system efficiency, including:
Pro Tip #1: HIPAA compliance is highly dependent on the size, function, administration, and type of entity or business associate. Therefore, this training module is not intended to be a complete or comprehensive guide to HIPAA compliance.
Entities and business associates regulated by the Privacy and Security Rules are obligated to comply with all federal and state requirements and should not rely on this training alone as a source of legal information or advice. To ensure compliance, covered entities and business associates should regularly perform risk assessments to track access to PHI, periodically evaluate security effectiveness, and re-evaluate potential risks.
HIPAA law applies directly to two particular groups: Covered Entities and Business Associates.
Covered Entities are health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically in connection with a covered transaction. (Note: Simply holding PHI does not by itself make an entity a covered entity.)
Pro Tip #2: HIPAA applies to employers only to the extent that they operate in one or more of these three groups. If a company offers healthcare services on-site (such as an on-site clinic), the employer would be considered a covered entity and required to follow HIPAA rules.
A business associate is any company or individual with access to Protected Health Information (PHI) or ePHI. Examples include IT vendors, laboratories, call centers, court reporters, cloud providers, and legal services.
Business associates are required to maintain a risk assessment, training, policies, and procedures. They must also safeguard PHI at all times, notify covered entities of any data breaches, and execute a Business Associate Agreement (BAA).
If a business associate violates HIPAA, they are not only in violation of their contract with the covered entity, but also in violation of federal HIPAA law itself and will be held accountable for penalties under both. Furthermore, if a business associate uses subcontractors, contractual agreements (BAAs) are required to hold those subcontractors to the exact same standards.