What is HIPAA?
Background
The Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (HIPAA) has had a significant impact on the health care industry. HIPAA applies to “covered entities” and, indirectly, to their “business associates.” As a health care clearinghouse, EHR Data Services ® is a covered entity under HIPAA. EHR Data Services also acts as a business associate on behalf of its customers. EHR Data Services has spent a considerable amount of time and resources to develop programs and systems to ensure compliance with the key HIPAA standards and requirements.
Standards for Electronic Transactions
Standards adopted under HIPAA require covered entities to transmit and receive certain electronic transactions in standard formats (the Transactions Rule). As a submitter of health care claims on behalf of its customers, Transactions Rule compliance is a core part of EHR Data Services’s business. The information needed to generate HIPAA compliant transactions is fully integrated into EHR Data Services®, and the Transactions Rule requirements are embedded in the fabric of the EHR Data Services' workflow, from patient scheduling through payment posting. Using the integrated data, claims are formatted, and then submitted and processed in HIPAA standard formats.
Privacy Rule
Privacy standards adopted under HIPAA (the Privacy Rule) require that covered entities use or disclose Protected Health Information (PHI) only as permitted or required by the Privacy Rule. EHR Data Services has implemented policies and procedures designed to ensure compliance with the Privacy Rule requirements by EHR Data Services’s workforce. In addition, EHR Data Services helps enable customers to comply with the Privacy Rule. For instance, EHR Data Services functionality includes privacy notice tracking, the ability to view, log, and update disclosures of PHI, and gives customers the ability to assign differing levels of user access to PHI.
Security Rule
Security standards adopted under HIPAA (the Security Rule) require that covered entities implement appropriate physical, administrative, and technical measures to ensure the confidentiality, integrity and availability of PHI in electronic form (ePHI).
EHR Data Services has performed a risk analysis under the Security Rule, and has prepared a risk management plan in which it has identified the measures in place to ensure that it maintains the confidentiality, integrity, and availability of ePHI. |