7.2 HIPAA Privacy, Security, and Code-Set Rules for Coders
Key Takeaways
- Protected health information is individually identifiable health information in any form—electronic, paper, or oral—held or transmitted by a covered entity or business associate, including coding charts, queries, and claims.
- The minimum necessary standard requires reasonable efforts to limit uses, disclosures, and requests of PHI, with important exceptions such as treatment disclosures between providers and data required for HIPAA standard transactions.
- A remote or vendor coder who is not hospital workforce is a business associate; the hospital must have a business associate agreement, and the vendor is directly subject to Security Rule safeguards for electronic PHI.
- HIPAA medical code sets include ICD-10-CM for diagnoses, CPT and HCPCS Level II for outpatient procedures and supplies, and ICD-10-PCS only for hospital inpatient procedures.
- HHS Office for Civil Rights enforces civil HIPAA rules and the Department of Justice handles criminal cases; civil dollar amounts are inflation-adjusted in 45 CFR §102.3, so this section does not quote a stale schedule.
Why HIPAA is a coding rule, not only an IT policy
Facility coding is a HIPAA activity. The chart, the query, the encoder worksheet, and the 837 claim all contain protected health information (PHI). A COC candidate who can pick a CPT code but cannot say when a vendor coder needs a business associate agreement (BAA), or which code set HIPAA adopted for outpatient procedures, is not ready for the Compliance domain or for a real HOPD/ASC department.
The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 directed the Department of Health and Human Services (HHS) to adopt standards for electronic exchange, privacy, and security of health information. The Privacy Rule (45 CFR Parts 160 and 164, Subparts A and E) limits uses and disclosures of PHI. The Security Rule (Part 164, Subpart C) protects electronic PHI (ePHI). The Transactions and Code Sets rules (45 CFR Part 162) tell covered entities which electronic formats and medical code sets to use. The HHS Office for Civil Rights (OCR) administers Privacy and Security enforcement. CMS administers the transaction and code-set standards.
Who is covered, and what is PHI
Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a transaction for which HHS adopted a standard (claims, eligibility, remittance, and related 837/835/270-271 work). A hospital that submits electronic outpatient claims is a covered entity. So is the Medicare program as a health plan.
PHI is individually identifiable health information held or transmitted by a covered entity or business associate, in any medium. It relates to the individual's past, present, or future physical or mental health, the provision of health care, or payment for that care, and it identifies the person or could reasonably be used to identify the person. A complete HOPD record, an itemized bill, and a coder's email that attaches an operative report with a name and medical record number are all PHI. Employment records the hospital keeps as employer, and certain education records under FERPA, are outside PHI.
De-identified information is not PHI. The Privacy Rule allows two methods: expert statistical determination, or the safe harbor that removes specified identifiers of the individual and of relatives, employers, and household members (names, full street address, dates more precise than year, telephone and email, Social Security and medical record numbers, account and health-plan numbers, device and vehicle identifiers, URLs and IP addresses, biometric identifiers, full-face photos, and comparable unique codes), with no actual knowledge that the remainder can identify the person. Quality reports that still contain medical record numbers are not de-identified.
Treatment, payment, operations, and minimum necessary
A covered entity may use or disclose PHI without a patient authorization for treatment, payment, and health care operations (TPO).
- Treatment is the provision, coordination, or management of care, including consultation and referral. Disclosures for treatment between providers are exempt from the minimum necessary standard. That is why the emergency department can send the operative note to the on-call surgeon without a minimum-necessary debate.
- Payment includes the provider's activities to obtain reimbursement. Building the UB-04 or CMS-1500, answering a MAC additional documentation request, and posting the remittance are payment uses.
- Health care operations include quality assessment, credentialing, medical review, audits, fraud-and-abuse detection, and certain administrative activities. Internal coding quality review sits here.
Minimum necessary is the Privacy Rule's working limit for most other uses, disclosures, and requests: make reasonable efforts to use or share only what the purpose requires. Role-based access is the Security Rule's cousin of the same idea. HHS is explicit that the rule does not forbid using an entire medical record when the entity has documented that the whole record is reasonably necessary for a defined purpose. A same-day-surgery coder who needs the history, operative report, implant log, and pathology to assign CPT, ICD-10-CM, and device HCPCS is not violating minimum necessary by opening those sections. A registration clerk who can open every behavioral-health note without a job need is.
Minimum necessary also does not apply to uses or disclosures required to comply with the HIPAA transaction standards, including required and situationally required data elements on the 837. You do not strip diagnosis codes off a claim to “minimize” PHI. It does not apply to disclosures the individual authorizes in writing, or to disclosures required by law.
Business associates and remote coders
A business associate is a person or organization, other than a member of the covered entity's workforce, that performs functions involving PHI on the covered entity's behalf, or that provides listed services (including consulting) that involve PHI. Claims processing, billing, and coding vendors are classic examples. HHS also lists independent medical transcriptionists, cloud providers that store ePHI, and IT contractors who need access to systems that contain ePHI. A janitorial crew with only incidental contact is not a business associate if reasonable safeguards are in place.
Workforce members—employees, volunteers, trainees, and others under the hospital's direct control—are not business associates. They are trained and sanctioned under the hospital's Privacy and Security policies. A coder employed by the hospital is workforce. A coder employed by a national coding company, working from home on hospital charts, is a business associate (or a workforce member of a business associate).
The Privacy Rule requires a BAA that, among other 45 CFR §164.504(e) elements, describes permitted uses and disclosures, bars the vendor from using PHI in a way the hospital could not, and requires the vendor to apply appropriate safeguards. The Security Rule requires the BAA to bind the associate to Security Rule obligations and to report security incidents, including breaches of unsecured PHI. Subcontractors who create, receive, maintain, or transmit ePHI for the vendor are themselves business associates and need downstream BAAs. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for many Security Rule and certain Privacy Rule provisions. OCR can investigate the vendor without routing every case through the hospital.
A BAA is not required for a treatment disclosure to another provider (hospital to specialist, hospital lab to reference lab). A BAA is not required when the hospital submits a claim to a health plan; each is acting as a covered entity on its own behalf. Those exceptions do not rescue a missing BAA with a coding contractor.
Facility scenario: weekend overflow coding
The HOPD falls behind on colonoscopy operative reports. Leadership wants to email encrypted PDFs to a freelancer who used to work in the department and now codes from another state. The freelancer is not on the hospital payroll this year. Correct sequence: execute a BAA first; provision a unique user ID into the encoder or EHR with the minimum access needed for outpatient surgery coding; require encryption in transit and at rest; forbid PHI on personal Gmail, WhatsApp, or an unencrypted laptop; and make sure the vendor knows it must notify the hospital of a security incident. Skipping the BAA because “they already know our patients” is a Privacy and Security failure, not a productivity hack.
Security Rule at the coder's workstation
The Security Rule applies to ePHI only—PHI in electronic media—not to paper charts or hallway conversations (those remain Privacy Rule issues). Regulated entities, including business associates, must ensure the confidentiality, integrity, and availability of ePHI; protect against reasonably anticipated threats and impermissible uses; and ensure workforce compliance. Implementation is scalable: size, complexity, technical capability, cost, and risk all matter. The Rule does not name a single brand of VPN. It does require a risk analysis, information access management that matches minimum necessary, and administrative, physical, and technical safeguards. Unique user IDs, automatic logoff, encryption where reasonable and appropriate, and a ban on shared “coding” passwords are the day-to-day translation for a remote coding team.
OCR has proposed updates to strengthen Security Rule cybersecurity; until a final rule says otherwise, the current Security Rule summarized by HHS is the exam-relevant baseline. Do not treat a proposed rule as already in force.
Transaction and code-set rules the COC exam actually tests
HIPAA required national electronic standards. Institutional, professional, and dental claims use ASC X12N 837 Version 5010. HOPD facility claims travel as 837I (the electronic UB-04). Independent ASC facility claims travel as 837P (the electronic CMS-1500), which is why the same ABN modifiers appear in different places on the two forms. Retail pharmacy uses NCPDP standards, which you will rarely touch as a facility outpatient coder.
HHS and CMS publish the adopted medical data code sets (45 CFR §162.1002 and the CMS Administrative Simplification code-set table):
| Activity | Adopted standard | Outpatient facility use |
|---|---|---|
| Diagnosis coding | ICD-10-CM, including the Official Guidelines for Coding and Reporting | First-listed and secondary diagnoses on HOPD and ASC claims |
| Hospital inpatient procedures | ICD-10-PCS | Not the procedure code set on HOPD/ASC facility claims |
| Outpatient and physician procedures | CPT (HCPCS Level I) | Endoscopy, surgery, radiology, medicine, ED visits as applicable |
| Supplies, drugs, and items not in CPT | HCPCS Level II | Devices, drugs, G-codes, many Medicare-specific services |
| Dental procedures | CDT | Only if the outpatient department is billing dental services |
Using ICD-10-PCS as the HOPD procedure code, or inventing a local “facility CPT,” is a code-set error as well as a billing error. Covered entities must use the code set valid at the time the care is furnished. That is why the COC exam expects current-year CPT, ICD-10-CM, and HCPCS books rather than a memorized 2015 crosswalk.
Enforcement without a stale fine table
OCR may impose civil money penalties for HIPAA violations. Amounts vary with culpability (from lack of knowledge through willful neglect) and are subject to a calendar-year cap for identical violations. HHS adjusts civil amounts for inflation; the current figures live in 45 CFR §102.3, not in a study-guide guess. This section therefore does not quote a civil dollar schedule that may already be out of date. Criminal penalties also exist for knowing improper obtaining or disclosure of individually identifiable health information; the Department of Justice prosecutes those cases. Business associates, not only hospitals, can face civil and criminal liability. For the exam and the job: protect the chart, limit access, contract your vendors, use the adopted code sets, and do not treat a missing BAA as a paperwork nicety.
A hospital outpatient department hires a remote coding company to code same-day surgery records. The company's employees are not hospital workforce. Before the hospital transmits operative reports that include patient identifiers, what does the HIPAA Privacy Rule require?
Which HIPAA-adopted code set is the standard for hospital inpatient procedure coding and should not be used as the procedure code set on a typical HOPD or independent ASC facility claim?
How does the HIPAA Privacy Rule's minimum necessary standard apply to facility coding?