7.4 HIPAA, ABNs, & Place of Service Rules

Key Takeaways

  • The HIPAA Privacy Rule protects PHI, while the Security Rule focuses specifically on safeguarding electronic PHI (ePHI).
  • The Minimum Necessary rule requires covered entities to use or disclose only the minimum PHI needed to accomplish the intended purpose.
  • An Advance Beneficiary Notice (ABN) must be signed by the patient before receiving a service that Medicare is expected to deny.
  • Place of Service (POS) codes are critical for accurate reimbursement, indicating whether a service occurred in an office (11), hospital (22), or via telehealth (10/02).
Last updated: July 2026

HIPAA, ABNs, & Place of Service Rules

Compliance in a medical practice extends far beyond diagnosis and procedure coding. It involves protecting sensitive patient data, properly notifying patients of their potential financial liability before services are rendered, and accurately reporting the physical or virtual location where services took place. Mastering these areas is essential for avoiding audits, penalties, and ensuring a smooth revenue cycle.

HIPAA: Privacy, Security, and Minimum Necessary

The Health Insurance Portability and Accountability Act (HIPAA) established national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge.

Privacy Rule vs. Security Rule

While often discussed together, the Privacy and Security rules have distinct focuses:

  • The Privacy Rule: Establishes national standards to protect individuals' medical records and other personal health information (PHI). It applies to health plans, healthcare clearinghouses, and healthcare providers (collectively known as Covered Entities). It gives patients significant rights over their health information, including the right to examine and obtain a copy of their records, and the right to request corrections. It broadly covers PHI in any form—written, oral, or electronic.
  • The Security Rule: Specifically protects health information that is held or transferred in electronic form (ePHI). It does not apply to paper records. It requires Covered Entities to implement three types of safeguards:
    • Administrative Safeguards: Policies and procedures to manage security (e.g., training staff, designating a security officer).
    • Physical Safeguards: Measures to protect electronic systems and related buildings/equipment from natural and environmental hazards and unauthorized intrusion (e.g., locked doors, computer screen privacy filters).
    • Technical Safeguards: Technology and policies to protect ePHI and control access to it (e.g., encryption, unique user IDs, auto-logoff mechanisms).

The Minimum Necessary Standard

A core concept of the Privacy Rule is the "Minimum Necessary" standard. It dictates that covered entities must make reasonable efforts to limit the use, disclosure of, and requests for PHI to the minimum necessary to accomplish the intended purpose.

  • Example: A medical billing clerk needs access to a patient's demographic information, diagnosis codes, and procedure codes to submit a claim. However, they do not need, and should not have access to, the full text of the physician's psychiatric progress notes or detailed surgical reports if it is not required for billing. The principle ensures that employees only see the data they absolutely need to do their jobs.

Advance Beneficiary Notice of Noncoverage (ABN)

An Advance Beneficiary Notice (ABN), officially Form CMS-R-131, is a written notice given to a Medicare beneficiary by a provider before receiving items or services that Medicare is expected to deny payment for. It is a critical financial and compliance tool.

  • Purpose: The primary purpose of an ABN is to transfer financial liability to the patient. If the provider believes Medicare will not pay because the service is not considered "reasonable and necessary" (e.g., an experimental treatment, a cosmetic procedure, or a screening test that exceeds frequency limits), they must issue an ABN. This allows the patient to make an informed decision about whether to proceed and pay out-of-pocket.
  • Execution Rules: The rules for ABNs are strict:
    • It must be given before the service is provided.
    • It cannot be a blanket ABN given to every patient for every service "just in case" Medicare denies it. It must be specific to the situation.
    • It must specify the exact item or service, the estimated cost, and the specific reason the provider believes Medicare will deny it.
    • The patient must read the form, choose an option (e.g., "I want the service and accept responsibility to pay"), and sign and date it.
    • If a valid ABN is not signed prior to the service, and Medicare subsequently denies the claim, the provider cannot bill the patient; the provider must write off the charge entirely.

Place of Service (POS) Codes

Place of Service (POS) codes are two-digit numbers placed on healthcare professional claims (CMS-1500 forms) to indicate the exact setting in which a service was provided. POS codes are not merely descriptive; they significantly impact reimbursement rates.

Generally, services performed in a "non-facility" setting (like a private physician's office) are reimbursed at a higher rate than those in a "facility" setting (like a hospital). This payment differential exists because in an office, the physician bears the overhead costs (rent, equipment, staff salaries), whereas in a hospital, the facility bears those costs, and the physician is only being paid for their professional time and expertise.

Key POS Codes to Know:

  • 11 - Office: Location, other than a hospital, skilled nursing facility, or military treatment facility, where the health professional routinely provides health examinations, diagnosis, and treatment. This triggers the higher non-facility payment rate.
  • 19 - Off Campus-Outpatient Hospital: A portion of an off-campus hospital provider-based department.
  • 21 - Inpatient Hospital: A facility, other than psychiatric, which primarily provides diagnostic, therapeutic, and rehabilitation services for inpatients.
  • 22 - On Campus-Outpatient Hospital: A portion of a hospital's main campus which provides diagnostic, therapeutic, and rehabilitation services to sick or injured persons who do not require hospitalization.

Telehealth POS Codes:

Due to the massive expansion of remote care, telehealth POS codes are now frequently used and heavily audited:

  • 02 - Telehealth Provided Other than in Patient's Home: The location where health services and health related services are provided or received, through telecommunication technology. The patient is located somewhere other than their home (e.g., a rural clinic connecting to a specialist).
  • 10 - Telehealth Provided in Patient's Home: The location where health services and health related services are provided or received, through telecommunication technology. The patient is located in their own home.

Using the incorrect POS code (e.g., billing POS 11 for a service that was actually performed in the hospital outpatient department, POS 22) constitutes an overpayment and a serious compliance violation.

Loading diagram...
Place of Service (POS) Impact
Test Your Knowledge

A physician orders a lab test that they know exceeds Medicare's frequency limits for that patient's condition. To legally bill the patient for the test when Medicare denies it, what must the physician do?

A
B
C
D
Test Your Knowledge

Under the HIPAA Privacy Rule, the principle that dictates an employee should only have access to the specific health information required to perform their job duties is known as:

A
B
C
D