What are HIPAA Covered Transactions?
HIPAA covered transactions are electronic communications between two parties for administrative or financial activities related to healthcare that use standards adopted by the Secretary for Health and Human Services in Part 162 of the HIPAA Administrative Simplification Regulations.
When Congress passed the Health Insurance Accountability and Portability Act (HIPAA) in 1996, its primary objective was to reform the health insurance industry. Because the cost of the reforms would increase insurance premiums, and because this would result in a reduction of federal tax revenue, a second Title was added to the Act.
Title II of HIPAA aimed to neutralize the cost of the reforms by reducing fraud and waste in the healthcare industry and simplifying the administration of healthcare transactions. However, at the time more than 400 proprietary formats were being used to communicate transaction data between healthcare providers and health plans.
Consequently, Congress instructed the Secretary for Health and Human Services (HHS) to adopt standards for healthcare transactions and the data elements used in them. The first set of standards for HIPAA covered transactions was published in 2000 and covered eight types of healthcare transaction:
- Health Care Claims or Equivalent Encounter Information.
- Eligibility for a Health Plan.
- Referral Certification and Authorization.
- Health Care Claim Status.
- Enrollment and Disenrollment in a Health Plan.
- Health Care Electronic Funds Transfers (EFT) and Remittance Advice.
- Health Plan Premium Payments.
- Coordination of Benefits.
Changes and Additions to the Standards
Changes to HIPAA covered transactions occur frequently. The original standards were updated in 2003, in 2009, and in 2012 to address technical issues and make minor changes to code sets. In 2015, the original ICD-9-CM code sets were replaced by ICD-10-PCS code sets to increase the level of specificity in the descriptions of procedures.
With regards to the data elements used in code sets, these also change frequently. For example, files used in the Medicaid National Correct Coding Initiative (NCCI) are usually replaced annually, the Healthcare Common Procedure Coding System (HCPCS) is updated quarterly, and the National Drug Code Directory is updated daily.
With regards to additions to the standards, code sets for Medicaid pharmacy subrogation transactions were added in January 2009 – increasing the total types of HIPAA covered transactions to nine – while HIPAA covered health plans have been required to comply with the HIPAA Operating Rules since January 2014.
The HIPAA Operating Rules require health plans to provide quicker, more complete responses to inquiries regarding individuals’ eligibility for benefits, claim statuses, fund transfers, and remittance advices. Due to the introduction of the HIPAA Operating Rules, the requirement to adopt Unique Health Plan Identifiers was rescinded in 2019.
The current standards, code sets, and data elements for HIPAA covered transactions can be found at 45 CFR Part 162.
How Compliance with the Standards is Enforced
Compliance with the standards for HIPAA covered transactions is enforced by HHS’ Centers for Medicare and Medicaid Services (CMS). CMS has the authority to investigate complaints and impose penalties when non-compliance leads to delayed eligibility checks and treatment authorizations or delayed payments.
CMS receives approximately 150 complaints about HIPAA covered transactions per year. When complaints are investigated and found to be justified, CMS has the same enforcement powers as HHS’ Office for Civil Rights inasmuch as the agency can impose corrective action plans or civil money penalties for compliance failures.
In addition to receiving complaints from external sources, CMS also monitors and enforces compliance with the Administrative Simplification Compliance Act. This Act requires all qualifying providers to submit Medicare claims via an online portal. Providers who fail to comply can be denied payment and excluded from Medicare.
CMS can also exclude healthcare providers from all federal healthcare programs via HHS’ Office of Inspector General. However, CMS can only exercise this enforcement option if the failure to comply with the standards for HIPAA covered transactions is attributable to fraud, theft, abuse, neglect, or unlawful activity.
Healthcare organizations can test their compliance with the standards for HIPAA covered transactions and file complaints via CMS’ ASETT portal.
Why it is Important to Know What HIPAA Covered Transactions Are
HIPAA covered transactions determine whether a healthcare provider qualifies as a “covered entity”. Being a covered entity not only means the healthcare provider has to comply with all applicable HIPAA standards, but also that any third party with whom the healthcare provider shares Protected Health Information (PHI) has to comply with HIPAA “where provided”.
- A healthcare provider that conducts – or subcontracts – electronic communications for which HHS has adopted standards qualifies as a covered entity.
- A third party that creates, receives, stores or transmits PHI for or on behalf of a covered entity – even if unrelated to healthcare transactions – qualifies as a business associate.
- A healthcare provider that does not qualify as a covered entity can still qualify as a business associate if it provides services for or on behalf of a covered entity that involve uses or disclosures of PHI.
Healthcare organizations unsure of their “HIPAA status” are advised to review the ways in which they conduct eligibility checks, seek treatment authorizations, or bill for treatments to determine whether any of the transactions qualify as HIPAA covered transactions. Even if one transaction qualifies, a healthcare provider will qualify as a HIPAA covered entity.
