7.2 HIPAA Privacy, Security Rules, and Breach Notification
Key Takeaways
- The Health Insurance Portability and Accountability Act (HIPAA) of 1996 protects individually identifiable Protected Health Information (PHI) across electronic, paper, and oral formats.
- PHI comprises 18 specific identifiers—including names, dates, SSNs, medical record numbers, and biometric data—when linked to health conditions or care provision.
- The HIPAA Privacy Rule enforces the Minimum Necessary Standard and restricts un-authorized PHI disclosures to Treatment, Payment, and Healthcare Operations (TPO).
- The HIPAA Security Rule mandates Administrative, Physical, and Technical safeguards to ensure the confidentiality and integrity of electronic PHI (ePHI).
- The Breach Notification Rule requires notifying affected individuals within 60 calendar days of breach discovery, with reporting to HHS and media for breaches affecting 500+ individuals.
7.2 HIPAA Privacy, Security Rules, and Breach Notification
Quick Summary: Enacted in 1996, the Health Insurance Portability and Accountability Act (HIPAA) establishes federal standards to protect sensitive Protected Health Information (PHI). Healthcare organizations must comply with the Privacy Rule (governing PHI use, disclosure, and patient rights), the Security Rule (requiring administrative, physical, and technical safeguards for ePHI), and the Breach Notification Rule. Disclosures without patient authorization are strictly limited to TPO (Treatment, Payment, Healthcare Operations) and statutory mandates. The HITECH Act and Omnibus Rule expanded enforcement directly to Business Associates.
Overview of HIPAA Legislative Framework
Passed by Congress in 1996, HIPAA was originally designed to improve health insurance portability for workers between jobs. However, Title II of HIPAA—known as Administrative Simplification—fundamentally transformed American healthcare by creating federal privacy, security, and transaction standards.
Key Legislative Updates
- HIPAA Privacy Rule (2003): Established first nationwide standard protecting paper, verbal, and electronic health information.
- HIPAA Security Rule (2005): Set specific safeguard requirements for electronic Protected Health Information (ePHI).
- HITECH Act (2009): Part of the ARRA stimulus package; increased civil monetary penalties, incentivized Electronic Health Record (EHR) adoption, and introduced the Breach Notification Rule.
- HIPAA Omnibus Rule (2013): Formally incorporated HITECH provisions, holding Business Associates directly liable for HIPAA violations and enhancing enforcement.
Protected Health Information (PHI) and the 18 Identifiers
Protected Health Information (PHI) is defined as individually identifiable health information that is transmitted or maintained in any medium (paper, electronic, verbal) by a covered entity or business associate, relating to an individual's past, present, or future physical or mental health, healthcare provision, or payment for care.
Protected Health Information (PHI)
│
┌──────────────────────────┴──────────────────────────┐
▼ ▼
Health Condition / Care Data Individually Identifiable Data
(Diagnosis, Rx, Lab Results, Billing) (Any of the 18 HIPAA Identifiers)
To be classified as PHI, health data must be linked to at least one of the 18 Specific HIPAA Identifiers:
- Names (patient, relative, employer)
- Geographic subdivisions smaller than a state (street address, city, county, ZIP code)
- All elements of dates directly related to an individual (birth date, admission date, discharge date, date of death, ages over 89)
- Telephone numbers
- Fax numbers
- Electronic mail (email) addresses
- Social Security Numbers (SSN)
- Medical Record Numbers (MRN)
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers (including license plate numbers)
- Device identifiers and serial numbers
- Web Universal Resource Locators (URLs)
- Internet Protocol (IP) address numbers
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographic images and comparable images
- Any other unique identifying number, characteristic, or code
Note: Information stripped of all 18 identifiers is considered de-identified data and is no longer subject to HIPAA restrictions.
The HIPAA Privacy Rule and Minimum Necessary Standard
The Privacy Rule regulates how covered entities (physicians, hospitals, clinics, pharmacies, health plans) use and disclose PHI. It also establishes fundamental patient rights:
- Right to Inspect and Copy: Patients can request copies of their medical and billing records.
- Right to Request Amendments: Patients can request corrections to erroneous record entries.
- Right to an Accounting of Disclosures: Patients can request a log of non-routine PHI disclosures made by the facility.
- Notice of Privacy Practices (NPP): Facilities must provide every patient with an NPP document explaining how their PHI is handled and obtain written acknowledgment of receipt.
The Minimum Necessary Standard
Under the Privacy Rule, healthcare workers must make reasonable efforts to limit the access, use, and disclosure of PHI to the minimum necessary required to accomplish the intended clinical or administrative purpose.
- Clinical Example: A billing specialist needs access to diagnostic codes and insurance account numbers, but does not need access to psychotherapy progress notes.
- Exception: The Minimum Necessary Standard does not apply to disclosures between healthcare providers for direct treatment purposes.
Permitted Disclosures: Treatment, Payment, and Operations (TPO)
Covered entities may use or disclose PHI without obtaining a specific signed patient authorization under three core scenarios collectively called TPO:
| Permitted TPO Category | Definition | Clinical Example |
|---|---|---|
| Treatment (T) | Provision, coordination, or management of healthcare and related services by one or more providers. | An MA faxes lab results to a consulting cardiologist or discusses a patient's prescription with a retail pharmacist. |
| Payment (P) | Activities undertaken to obtain premiums or reimbursement for healthcare services. | The billing department submits an itemized electronic claim form containing ICD-10 codes to a private insurer. |
| Healthcare Operations (O) | Administrative, financial, legal, and quality improvement activities necessary to run a clinic. | Using patient records for internal quality assurance audits, compliance reviews, or training student Medical Assistants. |
Mandatory Public Interest Exceptions (No Authorization Required)
- Reporting suspected child, elder, or vulnerable adult abuse or neglect.
- Reporting mandatory communicable diseases to local/state public health departments (e.g., TB, measles, syphilis).
- Complying with court orders or valid judicial warrants.
- Organ donation coordination and medical examiner investigations.
The HIPAA Security Rule: Safeguard Categories
While the Privacy Rule applies to all PHI, the Security Rule focuses specifically on protecting electronic PHI (ePHI). It mandates three categories of safeguards:
HIPAA Security Rule
│
┌─────────────────────────────────┼─────────────────────────────────┐
▼ ▼ ▼
Administrative Safeguards Physical Safeguards Technical Safeguards
• Security Management • Facility Access Controls • Access Controls (Passwords)
• Employee Training • Workstation Security • Encryption Standards
• Risk Assessment • Media & Device Controls • Audit Trail Logs
- Administrative Safeguards: Policies and procedures designed to manage security measures. Includes conducting regular risk assessments, designating a Security Officer, implementing employee sanction policies, and managing workforce access.
- Physical Safeguards: Physical measures protecting electronic systems and buildings from unauthorized access and environmental hazards. Includes workstation screen shields, locked server rooms, keycard entry, clean desk policies, and secure disposal of media.
- Technical Safeguards: Automated technology controls protecting data access. Includes unique user IDs and complex passwords, automatic logoff after inactivity, end-to-end data encryption (in transit and at rest), and immutable audit logs.
Business Associate Agreements (BAA)
A Business Associate (BA) is any vendor, contractor, or non-employee entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Examples include cloud storage providers, billing clearinghouses, electronic health record (EHR) vendors, and IT consultants.
Before sharing PHI, covered entities must execute a legally binding Business Associate Agreement (BAA). Under the HIPAA Omnibus Rule, BAs are directly subject to federal audits, Security Rule compliance, and civil monetary penalties.
Breach Notification Rule Requirements
A breach is defined as an impermissible acquisition, access, use, or disclosure of unencrypted PHI that compromises the security or privacy of the data.
Impermissible PHI Disclosure Discovered
│
Perform 4-Factor Risk Assessment
│
┌──────────────────────┴──────────────────────┐
▼ ▼
Low Probability of Compromise Breach Confirmed
(Document & Keep File) (Initiate Protocols)
│
┌───────────────────────────────┴───────────────────────────────┐
▼ ▼
Breach < 500 Individuals Breach ≥ 500 Individuals
• Notify individuals within 60 days • Notify individuals within 60 days
• Log & report to HHS within 60 • Report to HHS within 60 days
days of calendar year end • Issue press release to prominent
media outlets within 60 days
Notification Protocol
- Individual Notice: Covered entities must notify all affected individuals in writing via first-class mail (or secure email if consented) without unreasonable delay and no later than 60 calendar days following discovery of the breach.
- HHS Notification: For breaches affecting 500 or more individuals, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) must be notified at the same time as individuals (within 60 days). For breaches under 500 individuals, the entity must log them and report to HHS within 60 days of the calendar year end.
- Media Notification: If a breach affects 500 or more residents of a specific state or jurisdiction, the entity must issue a press release to prominent media outlets in that region within 60 calendar days.
Civil and Criminal Penalties for HIPAA Violations
Penalties are enforced by the HHS Office for Civil Rights (OCR) and the Department of Justice (DOJ).
| Penalty Category | Culpability Standard | Statutory Civil Fine / Penalty Range |
|---|---|---|
| Tier 1: Did Not Know | Violation occurred despite exercising reasonable diligence; lack of knowledge. | $137 to $68,928 per violation (Annual max: ~$1.9 million). |
| Tier 2: Reasonable Cause | Entity knew or should have known with reasonable diligence, but lacked willful neglect. | $1,379 to $68,928 per violation (Annual max: ~$1.9 million). |
| Tier 3: Willful Neglect (Corrected) | Intentional neglect, but corrected within 30 days of discovery. | $13,785 to $68,928 per violation (Annual max: ~$1.9 million). |
| Tier 4: Willful Neglect (Uncorrected) | Intentional neglect, not corrected within 30 days. | Minimum $68,928 up to maximum statutory limits. |
| Criminal Penalties | Knowingly obtaining or disclosing PHI; offenses committed under false pretenses or for commercial advantage/malicious harm. | Up to $250,000 fine and 1 to 10 years federal imprisonment. |
Which of the following is categorized as a Technical Safeguard under the HIPAA Security Rule?
Under HIPAA Privacy Rule guidelines, which scenario represents a PERMITTED disclosure of PHI without requiring a specific signed patient authorization?
A healthcare facility discovers a cybersecurity data breach affecting 750 patient records. According to the HIPAA Breach Notification Rule, what is the statutory deadline and requirement for reporting?