What Does HIPAA Mean?

HIPAA means the Health Insurance Portability and Accountability Act – an Act which led to the development of a Federal floor of privacy protections for individually identifiable health information. However, the Federal floor did not appear overnight. It took more than five years for regulations to be enacted – and even longer for them to be enforced.

The answer to the question what does HIPAA mean is often punctuated with references to the Privacy, Security, and Breach Notification Rules. But these were not the original purpose of the Health Insurance Portability and Accountability Act. The original purpose of HIPAA was to reform the health insurance industry in order to preserve insurance coverage when workers are between jobs and to prevent the denial of coverage due to a preexisting condition.

Due to the cost of the reforms, Congress added a second Title to HIPAA – one which had the intention of neutralizing the costs by reducing fraud and waste in the healthcare industry and by making the administration of healthcare transactions more efficient. The measures to reduce fraud and waste were effective immediately – saving Medicare and the insurance industry billions of dollars. The Administrative Simplification Regulations took longer to produce results.

The Administrative Simplification Regulations

At the time HIPAA was passed in 1996, different health plans, healthcare organizations, and billing companies used different transaction codes for processes such as eligibility checks, diagnoses, and treatment authorizations. The Secretary of Health and Human Services was tasked with standardizing the transaction codes as the first stage of making the administration of healthcare transactions more efficient – and this process took four years to complete.

In addition, the Secretary had been instructed to develop Security Standards for the Protection of Electronic Protected Health Information created, collected, maintained, and transmitted in healthcare transactions. The Secretary was also instructed to make recommendations for the privacy of individually identifiable health information – which were to be adopted as HIPAA regulations if Congress did not pass its own privacy legislation within three years.

Similar to the different transaction codes in use, there was a patchwork of state laws relating to the privacy and security of personal information throughout the country. When developing the privacy and security standards, the Secretary had to account for this patchwork of state laws and create a Federal floor of privacy protections while allowing states with more stringent laws to maintain their privacy and security regulations. Due to the balancing act required, the Final HIPAA Privacy Rule was published in August 2002, and the Final Security Rule in February 2003.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Why the Regulations Were Not Enforced until 2010

Although the Secretary of Health and Human Services published an Enforcement Rule in 2006, the focus of the Rule was to encourage voluntary compliance with the Privacy and Security Rules rather than apply the penalties authorized by HIPAA ten years earlier. As a result, the involvement of HHS’ Office for Civil Rights in the enforcement of HIPAA was limited to providing technical assistance when individuals complained about violations of their patients’ rights.

The situation changed with the passage of the HITECH Act in 2009 and the introduction of the Breach Notification Rule. This Rule reversed the “burden of proof” so that, rather than HHS’ Office for Civil Rights having to prove that an individual had suffered harm before a data breach was notifiable, the covered entity or business associate had to demonstrate a low likelihood of harm if not notifying HHS’ Office of Civil Rights and affected individuals of the data breach.

This change in the burden of proof significantly increased the number of data breach notifications from 2010 onwards, and – once investigations had been conducted into the data breaches – the number of penalties for violations of HIPAA. This had the impact of waking up many healthcare providers to the risk of enforcement action if they failed to comply with HIPAA – an impact that was also felt by business associates following the Omnibus Final Rule in 2013.

What Does HIPAA Mean to Healthcare Providers in 2024?

Other than changes to the transaction codes in order to respond to new processes, treatments, and medical devices – and annual increases in HIPAA violation penalties to account for inflation – the Administrative Simplification Regulations have remained mostly unchanged since 2013. However, the direction of HHS enforcement action has swung several times (from focusing on data breaches, to compliance audits, to the denial of patients’ rights) and it could soon change again.

Over the past few years, HHS Office for Civil Rights has proposed several Privacy Rule changes including attested uses and disclosures of reproductive health information, closer alignment between the Privacy Rule and SAMHSA’s Substance Use Confidentiality Regulations, and changes to patients’ rights to accommodate CMS’ Interoperability and Patient Access Final Rule. In addition, new Cybersecurity Performance Goals are being suggested, which may become a condition for participation in Medicare.

What this means for healthcare providers in 2024 is that HIPAA covered entities and business associates will have to keep on top of their HIPAA compliance efforts. Not only has HHS Office for Civil Rights indicated it will step up its enforcement actions in 2024, but State Attorney Generals have also expressed an interest in pursuing penalties for HIPAA violations. In 2023, sixteen state actions resulted in settlements for HIPAA violations totaling $105,930,000.

HIPAA covered entities and business associates who require help with keeping on top of their compliance efforts – or who need assistance with the provision of HIPAA training – should seek professional compliance advice.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/