What You Should Know About HIPAA and HIPAA Compliance

HIPAA stands for Health Insurance Portability andwith protected health information and consist of
Accountability Act. It is a federal law enacted in 1996healthcare providers, health insurance providers, and
as an attempt at incremental health care reform andemployer sponsored group health plans. Anyone
experts consider it to be the most significant healthoutside of those categories is considered a business
care legislation since Medicare in 1965.associate. Business associates include medical billing
HIPAA's intent is to reform the healthcare industrycompanies, medical storage, marketing organizations,
by reducing costs, simplifying administrative processessoftware companies, medical device manufacturers,
and burdens, and improving privacy and security ofetc.
patient's information.While the DHHS (Department of Health and Human
There are two separate and distinct laws that fallServices) regulates covered entities, business
under the HIPAA umbrella: HIPAA Privacy and HIPAAassociates are regulated by the covered entities they
Security. HIPAA Privacy relates to the protection andwork with through a business associate agreement
privacy of individuals' protected health information(alternatively called business associate contract).
(PHI) while HIPAA security relates to the protectionHIPAA compliance involves two main components:
and privacy of individuals' protected health informationone being HIPAA training of employees and the other
in electronic form (ePHI). HIPAA Privacy is what mostimplementing processes, procedures, and forms
of us think about when we hear the term HIPAA (related to HIPAA.
HIPAA Awareness Training, Notice of PrivacyWhile alot of regulations in HIPAA may seem like
Practices, Authorization forms, etc )whereas HIPAAcommon sense, think of them as just providing some
Security tends to be more the focus of anlevel of standardization so an individual and the
organization's IT department because it deals withorganizations involved in their care can know what to
encryption, electronic security, disaster recovery, etc.expect of each other.
Do you have to worry about HIPAA? There are twoHIPAA compliance does not have to be a
main classifications under HIPAA: Covered Entities andcomplicated process and once setup, can be relatively
Business Associates. Covered Entities are thoselittle effort to maintain.
types of organizations/individuals that deal directly