Offline Notepad View raw

Shared snapshot

HIPPA

Basics for providers: Privacy, Security, Breach Notification

Health Insurance Portability & Accountability (HIPPA)

PHI

3 KEY GROUPS

  1. HEALTH CARE CLEARING HOUSE
  1. BUSINESS ASSOCIATES - covered idea

-A Business Associate is any third party that:

Creates, receives, maintains, or transmits PHI on behalf of a covered entity,

Or provides services involving PHI access.

Examples include:

Billing companies

Cloud storage or data hosting providers

IT support services

Medical transcriptionists

Law firms, auditors, or accountants handling PHI

Claims processing companies

Consultants analyzing healthcare data

COVERED ENTITY

3 RULES in healthcare

  1. PRIVACY RULE :

PHI (Privacy Health Informartion)

THE 18 IDENTIFIERS OF PHI Names All geographic subdivisions smaller than a state (e.g., street address, city, county, precinct, zip code) All elements of dates (except year) for dates directly related to an individual Telephone numbers Fax numbers Email addresses Social Security numbers Medical record numbers Health plan beneficiary numbers Account numbers Certificate/license numbers Vehicle identifiers and serial numbers Device identifiers and serial numbers Web URLs IP addresses Biometric identifiers (including finger and voice prints) Full-face photographs and any comparable images Any other unique identifying number, characteristic, or code

Requirements:

INCIDENTAL DISCLOSURES

  1. SECURITY RULE

(3 TYPES OF SAFEGUARDS) Administrative safeguards Physical safeguards Technical safeguards

  1. BREACH NOTIFICATION RULE:

⚠️ Types of HIPAA Breaches- RESCUE PLAN WHEN THINGS GO WRONG

  1. 🧾 Unintentional Breach

An accidental disclosure of PHI — not malicious, but still a violation if safeguards weren’t followed.

🔹 Examples:

Sending a patient’s lab results to the wrong email address.

Leaving printed records in a public area by mistake.

Accidentally sharing PHI with an unauthorized staff member.

🔹 Prevention:

Double-check recipients before sending emails or faxes.

Train staff on privacy procedures.

Implement “minimum necessary” access.

  1. 🏢 Physical Breach

Occurs when paper files, devices, or physical media containing PHI are lost, stolen, or improperly handled.

🔹 Examples:

Theft of laptops, USB drives, or printed records.

Improper disposal of documents (not shredding).

Unauthorized entry into secure medical record storage areas.

🔹 Prevention:

Lock storage areas and workstations.

Use privacy screens and physical barriers.

Securely dispose of or wipe old devices and documents.

  1. 💻 Cyber Breach

Involves electronic PHI (ePHI) being accessed or stolen through cyberattacks or system vulnerabilities.

🔹 Examples:

Phishing or ransomware attacks.

Hacking into servers, email, or cloud systems.

Weak passwords or unencrypted data transmission.

🔹 Prevention:

Use strong passwords and multi-factor authentication.

Encrypt data in storage and transit.

Conduct regular security audits and software updates.

Train staff on identifying phishing emails.

  1. 🗣️ Verbal Breach

Occurs when PHI is spoken or overheard without proper authorization.

🔹 Examples:

Discussing a patient’s condition in a hallway or elevator.

Calling out patient names and diagnoses in a waiting area.

Sharing PHI verbally with unauthorized individuals.

🔹 Prevention:

Speak quietly in private areas.

Avoid using full names or identifiers in public spaces.

Train staff on discretion and verbal privacy etiquette.


Who must Conplky with HIPAA rules? HIPAA applies to two main groups:

  1. Covered Entities
  2. Business Associates

Who enforces HIPAA rules?