HIPAA-Health Insurance Portability & Accountability Act

The United States passed legislation in 1996 in an effort to ensure the privacy and safeguarding of all individuals’ medical data. In August of the same year, President Bill Clinton, signed in to law the Health Insurance Portability and Accountability Act (HIPAA) . In 2013, the law was updated to include mobile devices.

The Health Insurance Portability & Accountability Act (HIPAA) is a Federal Act requiring that medical records and any individually identifiable health data that is used, or disclosed, by a provider in any form, electronically, on paper, or orally, are kept properly confidential. This Act gives the patient, significant new rights to understand and control how your health information is used. HIPAA provides substantial penalties for any entity that use personal health information for unintended parties or misuse.

OneTapCare Platform Security:

Data in transit is encrypted using 128-bit SSL and utilizing hashing techniques for protection of sensitive data. We additionally utilize AES encryption at the database layer to ensure that all sensitive data at rest is secured. End-to-end video feed security is ensured with AES-128 encryption and by design leverages Cryptographic Security Kernel, or CSK. The CSK offers a secure random number generator conforming to NIST SP 800-90 regulations, message authentication, and secure encryption and decryption. The primary use of the CSK is to provide cryptographic functionality to the SDK. The SDK takes advantage of the CSK library to create master keys, which can then be used to create a secure session key. Our technology is housed at a SSAE 16 SOC I Type II, PCI, HIPAA and HITECH-compliant data center.

The Health Insurance Portability & Accountability Act (HIPAA) contains the following Titles:

HIPAA Title I – HIPAA Health Insurance Reform

Provides protection for maintaining health insurance coverage for any individual changing or losing their job. It also prohibits group plans from denying persons with preexisting conditions and diseases access to coverage and bars them from setting lifetime coverage limits.(1)

HIPAA Title II – HIPAA Administrative Simplification

Title II states that the US Department of Health and Human Services must establish a national standard for electronic healthcare transaction processing. All healthcare organizations must also implement security measures for health data access and comply with privacy laws.(1)

Title III: HIPAA Tax Related Health Provisions

Title III provides for certain deductions for medical insurance, and makes other changes to health insurance law.

Title IV: Application and Enforcement of Group Health Plan Requirements

Title IV specifies conditions for group health plans regarding coverage of persons with pre-existing conditions, and modifies continuation of coverage requirements.

Title V: Revenue Offsets

Title V includes provisions related to company-owned life insurance, treatment of individuals who lose U.S. Citizenship for income tax purposes and repeals the financial institution rule to interest allocation rules.
For people working in healthcare IT, HIPAA compliance means adhering to the requirements of Title II, known as the provisions of Administrative Simplification.

The HIPAA Enforcement Rule states guidelines for investigating compliance violations of HIPAA. The HIPAA Omnibus Rule, established in 2013, implements modifications to HIPAA concerning any associate of a covered entity.

HIPAA Compliance

Regulations such as HIPAA require transparency first and foremost. Any activity revolving around regulated data systems may be audited. Therefore, there must be checks and balances and policies in place within the organizational structure to guarantee that electronic protected health information (EPHI) is:

  • Not accessible to anyone except those who have a verified business need for it
  • Carefully monitored during such access
  • Encrypted while in storage and during transfer on any unprotected network, and only move to authorized locations

The above requirements reflect four primary practices central to HIPAA compliance as outlined below. Within these are many other facets imperative to data security, such as data loss protection, secure backup of data, process and technical controls, network configuration and the human element necessary for everything to work efficiently.

Secure electronic PHI by implementing the appropriate technical and non-technical safeguards.
In this day and age, electronic data storage and transmission is commonplace in nearly every industry — and that means consumer identities are more vulnerable to hackers and cybercriminals. This is especially true in the healthcare space, which is why electronic PHI storage and transmission is so heavily regulated.

WHO MUST COMPLY WITH HIPAA?

HIPAA rules apply to all business associates and covered entities. This includes, organizations, individuals and also agencies as they are considered covered entities. The requirements put forth by HIPAA must be followed by these entities to provide respect and rights to protect their private health information.

If a covered entity partners with another company or entity to establish or maintain healthcare needs for their business, this other business associate must have a written contract stating that all business conducted with the business associate will follow HIPAA guidelines and rules as indicated in the contract. Although, the business associate has the contract in place, they are still directly liable for compliance of certain provisions of the HIPAA rules. Examples of the entities are as follows:

  • Chiropractors
  • Clinics
  • Dentists
  • Doctors
  • Nursing Homes
  • Pharmacies
  • Psychologists

If you have any questions regarding HIPAA, please email us at info@staging or a healthcare legal advisor.