2003•Defense Counsel JournalRequires access

The HIPAA Privacy Rule: An Overview of Compliance Initiatives and Requirements; the Privacy Rule Contains a Maze of Mandates and Exceptions Requiring That Entities Covered by HIPAA Need the Best of Health Care Counsel

Nancy A. Lawson, Jennifer M. Orr, Doedy Sheehan Klar

Open publisher page 3 citations

Abstract

The Privacy Project The Privacy Rule contains a maze of mandates and exceptions requiring that entities covered by HIPAA need the best of health care counsel THE Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub.L. No. 104-191) was created and enacted in response to the health care industry's request for standardization, as a remedy for increasingly frequent health care privacy breaches, and as an effort to halt steady increases in health care costs. It received bi-partisan Congressional and industry-wide approval and was signed into law on August 21, 1996. HIPAA's enactment was without much fanfare. Most attention focused on the fact that HIPAA (1) amended the Employees Retirement Income Security Act (ERISA) to limit health plans' ability to use preexisting condition coverage exclusions and (2) barred discrimination by health plans in a variety of areas. A. Privacy Rule More important for defense counsel, Title II of HIPAA, denominated Simplification, required Congress to pass privacy, security and electronic health care transaction standards to regulate the use of health information transmitted electronically, which, by regulation, now has been expanded to encompass health information in any form or medium. In a nutshell, the HIPAA standards, when fully implemented, are expected to and will: * simplify the administration of health insurance claims and the costs associated with those claims by encouraging the promulgation of national standards; * give patients more control over and access to their medical information; * protect individually identifiable health information from real or potential threats of disclosure through the setting and enforcing of standards; and * improve efficiency in health care delivery by standardizing electronic data interchange (EDI). Title II stated that if by December 1999, Congress failed to pass meaningful health privacy legislation, with the input of the U.S. Department of Health and Human Services (HHS), then HHS was required to assume the responsibility. HHS's recommendations regarding federal privacy legislation were submitted to Congress in 1997, but Congress ultimately failed to act. As a result, HHS published the Standards for Privacy of Individually Identifiable Health Information, known as the Privacy Rule, in December 2000.1 In March 2002, after receiving, reviewing and responding to more than 60,000 public comments on the rule, HHS issued proposed modifications. These changes were intended to alleviate problems with the original rule that unintentionally impeded patient access to health care, while still maintaining the requirements for the privacy of individually identifiable health information. Primarily, the changes included: (1) eliminating the patient consent requirement, (2) modifying the definition of marketing, (3) providing allowances for incidental uses and disclosures of protected health information, and (4) allowing additional time for compliance with the cumbersome business associate provisions. Finally, in mid-August 2002, after an additional comment period, HHS issued its final version of the Privacy Rule and thereby finalized the groundbreaking and controversial federal privacy regulations. For all intents and purposes, the proposed changes in the March 27, 2002, amendment were adopted. Covered entities are required to comply with the Privacy Rule's requirements on or before April 14, 2003, with the exception that small health plans are given an additional year to comply. Small health plans, by statute, are those with fewer than 50 participants and/or plans with annual receipts of $5 million or less. B. Transactions and Code Sets Rule The Privacy Rule represents only one portion of HIPAA Administrative Simplification. In fact, well before the Privacy Rule was finalized, HIPAA-covered entities and their business associates already were implementing the Standards for Electronic Transactions, known as the Transactions and Code Sets Rule, as compliance with that rule originally was required on or before October 16, 2002, except for small health plans. …

About this research paper

What this paper is about

The Privacy Project The Privacy Rule contains a maze of mandates and exceptions requiring that entities covered by HIPAA need the best of health care counsel THE Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub.L. No. 104-191) was created and enacted in response to the health care industry's request for standardization, as a remedy for increasingly frequent health care privacy breaches, and as an effort to halt steady increases in health care costs. It received bi-partisan Congressional and industry-wide approval and was signed into law on August 21, 1996. HIPAA's enactment was without much fanfare. Most attention focused on the fact that HIPAA (1) amended the Employees Retirement Income Security Act (ERISA) to limit health plans' ability to use preexisting condition coverage exclusions and (2) barred discrimination by health plans in a variety of areas. A. Privacy Rule More important for defense counsel, Title II of HIPAA, denominated Simplification, required Congress to pass privacy, security and electronic health care transaction standards to regulate the use of health information transmitted electronically, which, by regulation, now has been expanded to encompass health information in any form or medium. In a nutshell, the HIPAA standards, when fully implemented, are expected to and will: * simplify the administration of health insurance claims and the costs associated with those claims by encouraging the promulgation of national standards; * give patients more control over and access to their medical information; * protect individually identifiable health information from real or potential threats of disclosure through the setting and enforcing of standards; and * improve efficiency in health care delivery by standardizing electronic data interchange (EDI). Title II stated that if by December 1999, Congress failed to pass meaningful health privacy legislation, with the input of the U.S. Department of Health and Human Services (HHS), then HHS was required to assume the responsibility. HHS's recommendations regarding federal privacy legislation were submitted to Congress in 1997, but Congress ultimately failed to act. As a result, HHS published the Standards for Privacy of Individually Identifiable Health Information, known as the Privacy Rule, in December 2000.1 In March 2002, after receiving, reviewing and responding to more than 60,000 public comments on the rule, HHS issued proposed modifications. These changes were intended to alleviate problems with the original rule that unintentionally impeded patient access to health care, while still maintaining the requirements for the privacy of individually identifiable health information. Primarily, the changes included: (1) eliminating the patient consent requirement, (2) modifying the definition of marketing, (3) providing allowances for incidental uses and disclosures of protected health information, and (4) allowing additional time for compliance with the cumbersome business associate provisions. Finally, in mid-August 2002, after an additional comment period, HHS issued its final version of the Privacy Rule and thereby finalized the groundbreaking and controversial federal privacy regulations. For all intents and purposes, the proposed changes in the March 27, 2002, amendment were adopted. Covered entities are required to comply with the Privacy Rule's requirements on or before April 14, 2003, with the exception that small health plans are given an additional year to comply. Small health plans, by statute, are those with fewer than 50 participants and/or plans with annual receipts of $5 million or less. B. Transactions and Code Sets Rule The Privacy Rule represents only one portion of HIPAA Administrative Simplification. In fact, well before the Privacy Rule was finalized, HIPAA-covered entities and their business associates already were implementing the Standards for Electronic Transactions, known as the Transactions and Code Sets Rule, as compliance with that rule originally was required on or before October 16, 2002, except for small health plans. …

Why it matters

OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The Privacy Project The Privacy Rule contains a maze of mandates and exceptions requiring that entities covered by HIPAA need the best of health care counsel THE Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub.L. No. 104-191) was created and enacted in response to the health care industry's request for standardization, as a remedy for increasingly frequent health care privacy breaches, and as an effort to halt steady increases in health care costs. It received bi-partisan Congressional and industry-wide approval and was signed into law on August 21, 1996. HIPAA's enactment was without much fanfare. Most attention focused on the fact that HIPAA (1) amended the Employees Retirement Income Security Act (ERISA) to limit health plans' ability to use preexisting condition coverage exclusions and (2) barred discrimination by health plans in a variety of areas. A. Privacy Rule More important for defense counsel, Title II of HIPAA, denominated Simplification, required Congress to pass privacy, security and electronic health care transaction standards to regulate the use of health information transmitted electronically, which, by regulation, now has been expanded to encompass health information in any form or medium. In a nutshell, the HIPAA standards, when fully implemented, are expected to and will: * simplify the administration of health insurance claims and the costs associated with those claims by encouraging the promulgation of national standards; * give patients more control over and access to their medical information; * protect individually identifiable health information from real or potential threats of disclosure through the setting and enforcing of standards; and * improve efficiency in health care delivery by standardizing electronic data interchange (EDI). Title II stated that if by December 1999, Congress failed to pass meaningful health privacy legislation, with the input of the U.S. Department of Health and Human Services (HHS), then HHS was required to assume the responsibility. HHS's recommendations regarding federal privacy legislation were submitted to Congress in 1997, but Congress ultimately failed to act. As a result, HHS published the Standards for Privacy of Individually Identifiable Health Information, known as the Privacy Rule, in December 2000.1 In March 2002, after receiving, reviewing and responding to more than 60,000 public comments on the rule, HHS issued proposed modifications. These changes were intended to alleviate problems with the original rule that unintentionally impeded patient access to health care, while still maintaining the requirements for the privacy of individually identifiable health information. Primarily, the changes included: (1) eliminating the patient consent requirement, (2) modifying the definition of marketing, (3) providing allowances for incidental uses and disclosures of protected health information, and (4) allowing additional time for compliance with the cumbersome business associate provisions. Finally, in mid-August 2002, after an additional comment period, HHS issued its final version of the Privacy Rule and thereby finalized the groundbreaking and controversial federal privacy regulations. For all intents and purposes, the proposed changes in the March 27, 2002, amendment were adopted. Covered entities are required to comply with the Privacy Rule's requirements on or before April 14, 2003, with the exception that small health plans are given an additional year to comply. Small health plans, by statute, are those with fewer than 50 participants and/or plans with annual receipts of $5 million or less. B. Transactions and Code Sets Rule The Privacy Rule represents only one portion of HIPAA Administrative Simplification. In fact, well before the Privacy Rule was finalized, HIPAA-covered entities and their business associates already were implementing the Standards for Electronic Transactions, known as the Transactions and Code Sets Rule, as compliance with that rule originally was required on or before October 16, 2002, except for small health plans. …

Key concepts: Health Insurance Portability and Accountability Act, Protected health information, Business, Health care, Privacy law, Internet privacy, Information privacy, Privacy policy

Related papers

Back to paper searchBrowse research topicsOriginal source
The HIPAA Privacy Rule: An Overview of Compliance Initiatives and Requirements; the Privacy Rule Contains a Maze of Mandates and Exceptions Requiring That Entities Covered by HIPAA Need the Best of Health Care Counsel — Research Paper | ScholarLens