Atlas · Plate XVIII · Ethics and Professional Responsibility · 03
HIPAA and confidentiality
HIPAA protects identifiable health information. Offices give a Notice of Privacy Practices, use the minimum necessary information, and may share it for treatment, payment and operations without separate authorization. Patients can get copies of their records, generally within 30 days, and a breach must be reported to them within 60 days of discovery.
High-yield facts · 6
- HIPAA Privacy Rule compliance began in 2003; it protects individually identifiable protected health information (PHI).S56
- Covered entities must give a Notice of Privacy Practices and use the minimum necessary information.S56
- PHI can be shared for treatment, payment and health care operations without separate authorization.S56
- Patients have the right to see and get a copy of their records, generally within 30 days of a request.S56
- Breach notification: affected individuals must be told without unreasonable delay and no later than 60 days after discovery.S56
- The Security Rule covers electronic PHI (administrative, physical and technical safeguards).S56
Facts are written in our own words; each tag links to its source. Values marked "sources vary" differ between references, so check the one your program uses.