15.3 HIPAA Privacy/Security, Cybersecurity & Internal Coding Audits

Key Takeaways

  • HIPAA Safe Harbor de-identification requires removal of 18 identifier categories; those categories are not the definition of PHI. Coding and billing may occur as payment or healthcare operations without individual authorization, subject to applicable minimum-necessary rules and exceptions.
  • A covered entity needs a Business Associate Agreement with a vendor or contractor that performs a business-associate function involving PHI, unless another HIPAA status or exception applies; remote location alone does not determine business-associate status.
  • The HIPAA Security Rule requires risk-based administrative, physical, and technical safeguards; specific controls such as encryption, MFA, VDI, privacy screens, and tamper-evident logs are selected and documented through the organization’s risk analysis.
  • Internal coding audit programs use prospective and retrospective review with risk-based sampling and organization-defined accuracy targets, followed by proportionate education and re-audit.
Last updated: August 2026

HIPAA Privacy/Security, Cybersecurity & Internal Coding Audits

AHIMA CCS Exam Focus: Ensuring data security, patient privacy, and rigorous coding quality is a central mandate for certified coding professionals. On the Certified Coding Specialist (CCS) exam, candidates are evaluated on HIPAA Privacy Rule provisions (including the 18 HIPAA Safe Harbor identifier categories, the Minimum Necessary standard, and TPO exceptions), HIPAA Security Rule safeguard pillars (administrative, physical, and technical controls), cybersecurity protocols for remote/offshore coding, the design of prospective versus retrospective audit programs, risk-based sampling methodologies, and mathematical formulas for calculating DRG and code-level accuracy against an organization-defined accuracy target.


1. HIPAA Privacy Rule & Protected Health Information (PHI) in HIM

The Health Insurance Portability and Accountability Act (HIPAA) establishes federal privacy and security requirements for protected health information. The HITECH Act strengthened this framework through breach-notification requirements, direct accountability for business associates and subcontractors, expanded enforcement and penalties, and incentives supporting adoption and meaningful use of certified electronic health record technology.

                             HIPAA Safe Harbor: 18 Identifier Categories
  ┌─────────────────────────────────────────┬─────────────────────────────────────────┐
  │ 1. Names of patients and relatives     │ 10. Account numbers                     │
  │ 2. Geography smaller than a state*     │ 11. Certificate / license numbers       │
  │ 3. Date elements except year*          │ 12. Vehicle identifiers / serial numbers│
  │ 4. Telephone numbers                   │ 13. Device identifiers & serial numbers │
  │ 5. Fax numbers                         │ 14. Web Universal Resource Locators(URLs│
  │ 6. Electronic mail addresses           │ 15. Internet Protocol (IP) addresses    │
  │ 7. Social Security numbers             │ 16. Biometric identifiers (fingerprints)│
  │ 8. Medical Record Numbers (MRNs)       │ 17. Full-face photographic images       │
  │ 9. Health plan beneficiary numbers     │ 18. Other unique number/trait/code      │
  └─────────────────────────────────────────┴─────────────────────────────────────────┘

*Safe Harbor has detailed exceptions for certain three-digit ZIP codes and for ages over 89. These categories are a de-identification test, not an exhaustive definition of when information is PHI.

The "Minimum Necessary" Standard in Coding Operations

Under 45 CFR § 164.502(b), covered entities must make reasonable efforts to limit the use, disclosure, or request of PHI to the "minimum necessary to accomplish the intended purpose of the use, disclosure, or request." The standard has defined exceptions, including disclosures to or requests by a healthcare provider for treatment; payment and healthcare-operations work generally remains subject to minimum-necessary policies.

  • Application to Inpatient/Outpatient Coders: Medical coders need role-appropriate access to the portions of the encounter record reasonably necessary for accurate coding, which may include physician progress notes, consultation reports, operative summaries, pathology results, discharge summaries, nursing flowsheets, and medication administration records. However, coders must not access unrelated past encounters, records of family members, or charts of high-profile patients without an active, assigned clinical coding or auditing business need.
  • Role-Based Access Control (RBAC): HIM leadership must configure EHR security profiles so that coding staff receive access tailored to their specific job function, preventing unrestricted browsing of non-relevant health system databases.

Treatment, Payment, and Health Care Operations (TPO) Exceptions

HIPAA permits covered entities to use and disclose PHI without obtaining individual patient authorization under the statutory Treatment, Payment, and Health Care Operations (TPO) exceptions:

  • Payment: Activities undertaken by healthcare providers to obtain reimbursement for health services. Medical coding, Clinical Documentation Improvement (CDI), billing claim generation (837I/837P), electronic claims transmission, and payer utilization review fall squarely under the Payment exception.
  • Health Care Operations: Activities related to covered entity operations, including internal coding quality audits, peer review, professional credentialing, compliance training, and accreditation surveys. Internal coding audits are legally conducted under Operations without patient authorization.

Business Associate Agreements (BAAs)

A Business Associate (BA) is any external individual or organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity for a function regulated by HIPAA. Common HIM Business Associates include third-party coding staffing agencies, offshore coding vendors, independent coding audit firms, cloud-based encoder software hosts, and transcription vendors.

  • Mandatory BAA Provisions: Under the HIPAA Omnibus Final Rule, Business Associates are directly liable for compliance with the HIPAA Security Rule. A compliant Business Associate Agreement (BAA) must explicitly establish:
    1. The permitted and required uses and disclosures of PHI.
    2. The requirement to implement administrative, physical, and technical safeguards.
    3. Mandatory reporting of security incidents and breaches of unsecured PHI to the covered entity without unreasonable delay (and no later than 60 days under federal law).
    4. Binding downstream subcontractors to the exact same privacy and security obligations.
    5. Authorization for the covered entity to terminate the contract if the BA violates a material term.
    6. Return or secure destruction of PHI at termination when feasible; when infeasible, continued protections and limits on further use or disclosure.

2. HIPAA Security Rule & Remote Coding Cybersecurity

While the Privacy Rule focuses on who can access PHI across all mediums (paper, verbal, electronic), the HIPAA Security Rule (45 CFR Part 160 and Part 164, Subparts A and C) establishes federal standards specifically safeguarding Electronic Protected Health Information (ePHI) across three structural safeguard pillars:

                         HIPAA Security Rule: Three Pillars
                                       │
         ┌─────────────────────────────┼─────────────────────────────┐
         ▼                             ▼                             ▼
Administrative Safeguards      Physical Safeguards           Technical Safeguards
• Formal risk analysis         • Facility access controls    • Unique user identification
• Security management process  • Workstation use policies    • Emergency 'break-glass' access
• Workforce security & training• Device & media controls    • Automatic session logoff
• Contingency / DR planning    • Visual privacy controls     • Transmission security
• Sanction policies for breach • Secure physical disposal    • Audit controls/activity review

Technical Safeguards in Modern HIM

The Security Rule is risk-based and technology-neutral. It requires access-control, audit-control, integrity, authentication, and transmission-security capabilities, while many implementation specifications—including encryption—are addressable, meaning the entity must assess reasonableness and appropriateness, implement the safeguard when reasonable, or document an equivalent measure or why it is not reasonable.

  • Access control: Assign unique user identification and authorize access according to role and minimum necessary use. Automatic logoff, emergency access, and multi-factor authentication can be appropriate controls based on risk; HIPAA does not prescribe one universal MFA configuration.
  • Audit and integrity controls: Record and examine activity in systems containing ePHI and protect information from improper alteration or destruction. Tamper-evident logging and SIEM monitoring are useful implementations, not named universal technologies in the regulation.
  • Transmission and storage protection: Encryption, secure VPNs, and contemporary TLS/AES configurations can reduce risk, but HIPAA does not mandate TLS 1.3 or AES-256 by name. Select and document safeguards through the entity's risk analysis and security-management process.

Remote and Offshore Coding Security Protocols

For home-based or offshore coding, an organization should select remote-work safeguards from its risk analysis and document them in policy. Common controls include:

  • Virtual Desktop Infrastructure (VDI): Coders connect to a virtualized hospital desktop session hosted in the secure hospital data center. No patient data or medical records are ever stored, downloaded, or cached on the remote computer's local hard drive.
  • Data Loss Prevention (DLP) Policies: VDI environments disable local clipboard copying, local file saving, external USB storage drive connectivity, and local document printing.
  • Physical Home Workstation Security: Remote coding agreements mandate a dedicated, private home office space with closed doors, clean-desk standards (no written notes with patient identifiers), and reasonable visual-privacy controls to prevent unauthorized viewing. Privacy screens may be appropriate based on the workspace risk assessment but are not universally mandated by HIPAA.

3. Internal Coding Audit Programs: Design, Methodology & Sampling

A comprehensive Internal Coding Audit Program is an indispensable component of hospital compliance and revenue cycle integrity. Audits serve to prevent allegations of healthcare fraud under the False Claims Act, ensure adherence to official coding guidelines, identify physician documentation deficiencies, prevent payer claim denials, and guide targeted coder education.

                           Coding Audit Program Architecture
                                         │
         ┌───────────────────────────────┴───────────────────────────────┐
         ▼                                                               ▼
Prospective (Pre-Bill) Audits                                   Retrospective (Post-Bill) Audits
• Audited AFTER coding, BEFORE claim drop                       • Audited AFTER claim drop & payment
• Prevents submission of incorrect/false claims                 • Allows unhurried, large statistical sampling
• Catches overcoding and undercoding immediately                • Measures actual billing accuracy
• Disadvantage: Increases DNFB & delays A/R cash flow           • Disadvantage: Requires formal rebilling/refunds

Prospective vs. Retrospective Audits

Audit DimensionProspective (Pre-Bill) AuditRetrospective (Post-Bill) Audit
TimingCompleted after code assignment but prior to claim transmission (837I/837P)Completed after claim submission and final payer adjudication/remittance (835)
Primary GoalPrevent billing errors, fraudulent claims, and immediate claim denialsMeasure ongoing compliance baseline, evaluate longitudinal trends, sample large volumes
Cash Flow ImpactTemporarily holds claims, increasing Discharged Not Final Billed (DNFB) and A/R daysZero impact on initial billing turnaround and hospital cash flow
Error RemediationCodes corrected directly on the claim prior to billing; zero payer notification neededRequires applicable claim adjustments, rebilling, and overpayment review or repayment under the controlling payer rules and deadlines
Best ApplicationHigh-risk DRGs, newly hired coders, new regulatory updates, vendor onboardingRoutine quarterly compliance benchmarking, annual physician documentation profiling

Sampling Strategies: Random vs. Focused Risk-Based Sampling

To optimize audit resources, HIM departments deploy a hybrid sampling methodology:

  1. Statistically Valid Random Sampling: A randomized selection of inpatient and outpatient records across all service lines to calculate an unbiased, baseline departmental coding accuracy rate.
  2. Focused (Risk-Based) Sampling: Targeted selection of records with high regulatory, financial, or clinical vulnerability. High-yield focused audit targets include:
    • High-Weight / High-Dollar MS-DRGs: Major surgical procedures, organ transplants, ECMO, mechanical ventilation greater than 96 consecutive hours (5A1955Z), tracheostomy, and extensive burn cases.
    • Single CC/MCC Inpatient Cases: Records where an MS-DRG is elevated to a higher payment tier by a single secondary diagnosis (e.g., Sepsis, Acute Kidney Injury, Encephalopathy, Severe Protein-Calorie Malnutrition). These cases represent prime targets for payer clinical validation denials.
    • Hospital-Acquired Conditions (HACs) & Present on Admission (POA) Inconsistencies: Cases with hospital-acquired catheter-associated UTIs, surgical site infections, or stage 3/4 pressure injuries with POA = N (No) or POA = U (Undetermined).
    • Post-Acute Care Transfer (PACT) Cases: Inpatient discharges assigned MS-DRGs subject to transfer penalty rules where the patient was transferred to home health, skilled nursing, or hospice.
    • Unlisted Surgical Codes: CPT or ICD-10-PCS claims utilizing unlisted/unspecified procedure codes (0YZ..., 47999, etc.).
    • Provider Query Compliance: Reviewing query forms to identify non-compliant, leading questions or financial prompts.

4. Industry Accuracy Benchmarks, Formulas & Closing the Audit Loop

Organizations should define and document their own coding-accuracy targets, sampling rules, error weights, and corrective-action thresholds. A 95% target is common in some departments and contracts, but it is not a universal AHIMA-mandated national threshold.

                                Coding Accuracy Formulas
  ┌─────────────────────────────────────────────────────────────────────────────────┐
  │ 1. Code-Level Accuracy Rate (%)                                                │
  │    (Total Correct Codes Assigned / Total Codes Evaluated) x 100                 │
  ├─────────────────────────────────────────────────────────────────────────────────┤
  │ 2. DRG / Narrative Accuracy Rate (%)                                            │
  │    (Total Correct DRGs Assigned / Total Inpatient Cases Audited) x 100          │
  ├─────────────────────────────────────────────────────────────────────────────────┤
  │ 3. Financial Variance & Net Reimbursement Impact                                │
  │    Gross Overpayments - Gross Underpayments = Net Financial Reimbursement Delta│
  └─────────────────────────────────────────────────────────────────────────────────┘

Calculating Coding Accuracy

Auditors compute accuracy at two distinct operational tiers:

  1. Code-Level Accuracy Rate (%):

    • Evaluates the precision of every individual diagnosis and procedure code assigned.
    • Formula: Code-Level Accuracy Rate (%)=Total Correct Codes AssignedTotal Codes Evaluated×100\text{Code-Level Accuracy Rate (\%)} = \frac{\text{Total Correct Codes Assigned}}{\text{Total Codes Evaluated}} \times 100
    • Where $\text{Total Codes Evaluated} = \text{Correct Codes} + \text{Incorrect/Changed Codes} + \text{Missed/Omitted Codes (False Negatives)}$.
  2. DRG Accuracy Rate (%):

    • Evaluates whether the assigned codes resulted in the correct final MS-DRG or APR-DRG assignment.
    • Formula: DRG Accuracy Rate (%)=Total Correct DRGs AssignedTotal Inpatient Records Audited×100\text{DRG Accuracy Rate (\%)} = \frac{\text{Total Correct DRGs Assigned}}{\text{Total Inpatient Records Audited}} \times 100
    • Note: A case may have a minor secondary diagnosis code error that does not alter the final MS-DRG (e.g., if multiple other valid MCCs exist), resulting in an incorrect code-level score but a 100% correct DRG score.

Step-by-Step Mathematical Example

An auditor reviews 50 inpatient charts. Across these 50 charts, the coder assigned 300 total diagnosis and procedure codes. The audit reveals:

  • 270 codes were completely correct.
  • 15 codes were incorrect (wrong code selected).
  • 15 valid codes were missed and omitted by the coder.
  • 46 of the 50 charts had the correct final MS-DRG assigned; 4 charts had an incorrect MS-DRG resulting from missed or incorrect principal diagnoses/MCCs.

Total Codes Evaluated=270 (Correct)+15 (Incorrect)+15 (Missed)=300\text{Total Codes Evaluated} = 270 \text{ (Correct)} + 15 \text{ (Incorrect)} + 15 \text{ (Missed)} = 300 Code-Level Accuracy Rate=270300×100=90.0%(below an illustrative organizational 95% target)\text{Code-Level Accuracy Rate} = \frac{270}{300} \times 100 = 90.0\% \quad (\text{below an illustrative organizational 95\% target}) DRG Accuracy Rate=4650×100=92.0%(below an illustrative organizational 95% target)\text{DRG Accuracy Rate} = \frac{46}{50} \times 100 = 92.0\% \quad (\text{below an illustrative organizational 95\% target})

Closing the Audit Feedback Loop: RCA & Corrective Action Plans

An audit program fails if results are merely archived without actionable remediation. Closing the loop requires a systematic four-phase process:

graph LR
    A["Phase 1: Audit Execution<br/>(Prospective/Retrospective Scoring)"] --> B["Phase 2: Root Cause Analysis<br/>(Guideline, Encoder, or Documentation Gap)"]
    B --> C["Phase 3: Corrective Action Plan<br/>(Targeted Education & 100% Pre-Bill Queue)"]
    C --> D["Phase 4: Re-Auditing & CQI<br/>(Demonstrated Sustained Accuracy at Local Target)"]
  1. Root Cause Analysis (RCA): Categorize each identified error by underlying etiology: (a) Coding guideline misunderstanding, (b) Encoder logic trap or software misdirection, (c) Incomplete provider documentation requiring a query, or (d) Clerical / typographical oversight.
  2. Individual & Departmental Education: Deliver one-on-one coder mentoring and formal inservice training targeting identified vulnerability trends (e.g., sepsis sequencing, acute myocardial infarction timing rules, root operation differentiation in PCS).
  3. Corrective Action Plan (CAP) & Intensive Pre-Bill Monitoring: When performance falls below the organization's documented threshold, a proportionate corrective action plan may include targeted education, focused pre-bill review, and re-audit. The review percentage, duration, and release criteria should follow local policy rather than an assumed universal rule.
  4. Continuous Quality Improvement (CQI): Trend aggregate audit metrics quarterly to identify systemic documentation opportunities, guiding Clinical Documentation Improvement (CDI) specialist focus areas and physician educational programs.
Test Your Knowledge

A hospital has adopted a 95.0% code-level accuracy target in its written audit policy. An audit evaluates 250 codes: 230 correct, 12 incorrect, and 8 missed. What is the code-level accuracy, and how does it compare with that local target?

A
B
C
D
Test Your Knowledge

Under the HIPAA Privacy Rule, which of the following activities performed by a hospital Health Information Management (HIM) department is legally permitted WITHOUT obtaining explicit written authorization from the patient?

A
B
C
D
Test Your Knowledge

A hospital coding audit team is designing a focused, risk-based sampling plan for their upcoming quarterly inpatient coding audit. Which of the following case categories represents the HIGHEST regulatory and financial compliance risk for focused auditing?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams