6.4 HIPAA Portability & Privacy

Key Takeaways

  • HIPAA portability credits prior 'creditable coverage' dollar-for-dollar against a pre-existing exclusion, lost only after a 63-day gap without coverage
  • The ACA (2014, §2704) eliminated all pre-existing condition exclusions, superseding HIPAA's PECE limits — but HIPAA's special enrollment rights remain live
  • The HIPAA Privacy Rule protects Protected Health Information (PHI) with a minimum-necessary standard that exempts treatment disclosures
  • The HITECH breach notification rule requires individual notice within 60 days of discovery, with HHS and media notice for breaches affecting 500+ individuals
Last updated: August 2026

HIPAA: Portability and Privacy

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) has two main pillars relevant to A&H licensing: (1) portability — protecting continuity of coverage when workers change jobs, and (2) privacy/security — protecting the confidentiality of individually identifiable health information. The portability rules have been largely superseded by the ACA's elimination of pre-existing condition exclusions (2014), but remain exam-relevant because they define terms (creditable coverage, special enrollment) still used in group plans.

HIPAA Portability Rules

Pre-2014, group health plans could impose pre-existing condition exclusion (PECE) periods — typically 12 months (18 months for late enrollees) — for conditions for which medical advice, diagnosis, care, or treatment was recommended or received in the prior 6 months (the look-back period).

HIPAA portability limited PECEs through:

  • Creditable coverage: prior coverage (group, individual, COBRA, Medicaid, Medicare, CHIP, TRICARE, church plan, public health plan, Indian Health Service) counts dollar-for-dollar against a PECE — each day of creditable coverage offsets one day of exclusion.
  • 63-day gap rule: creditable coverage is only lost if the individual has a gap of 63 days or more without coverage (shorter in some states). Brief lapses do not erase credit.
  • Certificate of creditable coverage: the prior plan must issue a certificate showing coverage dates when an individual leaves the plan; if the certificate is not received, the individual can prove creditable coverage by other means.
  • Special enrollment rights: loss of other coverage (e.g., spouse loses job), marriage, birth, adoption, or placement for adoption trigger a special enrollment opportunity outside open enrollment — the same trigger used by the ACA Marketplace.
  • Pre-existing exclusion limits: PECE could not exceed 12 months for regular enrollees, 18 months for late enrollees, and was prohibited entirely for pregnancy, newborns, and adopted children under age 18.

The ACA's Elimination of Pre-Existing Exclusions

Starting in 2014, the ACA (§2704) prohibited all pre-existing condition exclusions in group and individual health plans. This effectively superseded HIPAA's PECE limits — there are now no PECEs to offset. However, the portability framework (creditable coverage, 63-day gap, special enrollment) remains relevant for:

  • Special enrollment in group plans (still a live HIPAA right, applied daily).
  • Creditable coverage for Medicare Part D (determines the late-enrollment penalty).
  • Drug coverage credit for Part D purposes (the annual "creditable coverage" notice plans must send).

Distinguish: HIPAA portability made exclusions shorter; the ACA eliminated them. HIPAA did not guarantee issue in the individual market (that came with the ACA).

HIPAA Privacy Rule

The HIPAA Privacy Rule (45 CFR Parts 160 and 164) protects Protected Health Information (PHI) — individually identifiable health information held or transmitted by a covered entity (health plans, health care clearinghouses, and most health care providers) or their business associates.

Key Privacy Rule concepts:

  • PHI: health information that identifies the individual or could reasonably identify them; includes name, address, DOB, SSN, medical record number, and any of 18 HIPAA-specified identifiers.
  • Minimum necessary: when PHI is used or disclosed for treatment, payment, or health care operations (TPO), the disclosure must be limited to the minimum necessary to accomplish the purpose — except for treatment, which is exempt (full clinical sharing for care is allowed).
  • Notice of Privacy Practices (NPP): every covered entity must provide an NPP describing uses and disclosures of PHI, patient rights, and the entity's legal duties; health plans must provide NPP at enrollment and upon request.
  • Authorization: most uses beyond TPO require written patient authorization (marketing, sale of PHI, psychotherapy notes).
  • Patient rights: right to access, amend, accounting of disclosures, restriction requests, confidential communications.

HIPAA Security Rule

The HIPAA Security Rule (45 CFR §164.302–318) protects electronic PHI (ePHI) — PHI in electronic form. It requires:

  • Administrative safeguards — risk analysis, workforce training, sanction policies, access management.
  • Physical safeguards — facility access controls, workstation security, device and media controls.
  • Technical safeguards — access control, audit controls, integrity, transmission security (encryption).
  • Breach Notification Rule (HITECH Act 2009): breaches of unsecured PHI must be notified to affected individuals within 60 days, to HHS, and (for breaches affecting 500+ individuals) to media; small breaches (under 500) are logged and reported annually.

Common Exam Confusions

  • Portability ≠ Privacy: portability is about coverage continuity; privacy is about information protection. They are distinct HIPAA titles tested on the same exam.
  • HIPAA vs ACA: HIPAA limited exclusions; ACA eliminated them. HIPAA did not guarantee issue; ACA did.
  • Covered entity vs business associate: plans/providers are covered entities; vendors handling PHI on their behalf are business associates (with a Business Associate Agreement, BAA, required).
  • Minimum necessary ≠ treatment exception: treatment disclosures are exempt from minimum-necessary limits — clinicians may share full clinical records for care purposes.

Penalties and Enforcement

HIPAA violations carry tiered civil penalties (adjusted annually for inflation) enforced by the HHS Office for Civil Rights (OCR): a four-tier structure based on culpability, from "did not know" (lowest) to "willful neglect not corrected" (highest). Criminal penalties apply for knowingly obtaining or disclosing PHI — up to 1 year imprisonment for simple violations and up to 10 years where the motive is personal gain, harm, or commercial advantage. State attorneys general also have authority to bring civil actions on behalf of residents. For the A&H exam, remember that OCR enforces the Privacy and Security Rules, while HIPAA portability complaints (special enrollment, certificate of creditable coverage) flow through the DOL and state insurance departments for ERISA and insured plans respectively.

Test Your Knowledge

Under HIPAA portability, creditable coverage is lost if the individual has a gap without coverage of:

A
B
C
D
Test Your Knowledge

Starting in 2014, what did the ACA do to pre-existing condition exclusions in group and individual plans?

A
B
C
D
Test Your Knowledge

Which of the following is the minimum necessary standard under the HIPAA Privacy Rule?

A
B
C
D
Test Your Knowledge

Under the HIPAA breach notification rule, breaches of unsecured PHI must be reported to affected individuals within:

A
B
C
D