last updated 10/31/02
  Does It Apply to Us?
   
 

The short answer is that if you are in the health care industry and have access to patient data, the HIPAA Privacy Rule probably applies to you. For a complimentary consultation, email the firm at info@jkhipa.com or call Kazu Sano at (415) 773-2861.

The longer answer is that the HIPAA Privacy Rule applies to (1) health care providers who transmit any health information in electronic form in connection with a transaction for which the Department of Health & Human Services has adopted a standard; (2) health plans; and (3) health care clearinghouses.

Health Care Providers. You are a covered health care provider if you are a provider and you transmit health information in electronic form in connection with any one of the following transactions: (1) health claims (or other equivalent encounter information) and attachments to those claims; (2) enrollment and dis-enrollment in a health plan; (3) eligibility for a health plan; (4) health care payment and remittance advice; (5) health plan premium payments; (6) first report of injury; (7) health claim status; or (8) referral certification and authorization.

You are a covered health care provider even if you use a third-party billing service (so that technically the billing service engages in the electronic transactions instead of you).

Health Plans. You are a covered health plan if you are an individual or group plan that provides or pays the cost of medical care. This includes group health plans, health insurance issuers, any arrangement established or maintained for the purpose of offering or providing health benefits to the employees of two or more employers, and HMOs.

Health Care Clearinghouses. You are a covered health care clearinghouse if you are an organization (including billing services and re-pricing companies) that (1) takes health information received in non-standard format or containing non-standard data content and processes it into standard data elements or a standard transaction; or (2) receives a standard transaction and processes it into non-standard format or data content.