HIPAA: Resources
The following resources can help patients understand their rights and help providers become and stay compliant with HIPAA (Health Insurance Portability and Accountability Act) rules. .
General information
Get the latest news and updates.
- Health Information Privacy — U.S. Department of Health and Human Services (HHS) Office for Civil Rights
Privacy Rule
Find information about protecting health information.
- Summary of the HIPAA Privacy Rule — HHS
- HIPAA Privacy Rule and Public Health (PDF) — CDC (Centers for Disease Control and Prevention) and HHS, 2003
Anyone with a privacy question for HHS should email ocrprivacy@os.dhhs.gov or call 866-627-7748.
Security Rule
Find information about ensuring the confidentiality of electronic protected health information.
- Summary of the HIPAA Security Rule — HHS
- The Security Rule — HHS
- Security Rule Guidance Material — HHS
- NIST Computer Security Resource Center — National Institute of Standards and Technology
HIPAA guidance material
Read documents and other guidance related to HIPAA.
Guidance for patients
- File a Complaint with DHS—Wisconsin Medicaid HIPAA Privacy Complaint, F-13152
- File a Complaint with the federal Office for Civil Rights (OCR)
Guidance for providers
- Breach Notification for Unsecured Protected Health Information, Interim Final Rule (PDF) (2009)
- Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule — HHS
- HIPAA Guidance Materials for small providers, small health plans, and small businesses —HHS
- HIPAA for Professionals—HHS
- HIPAA Privacy Rule Accounting of Disclosures Under the Health Information Technology for Economic and Clinical Health Act, Proposed Rule (PDF) (2011)
- HITECH Privacy Regulation (PDF) — Begins on page 144
- HITECH Act Enforcement Interim Final Rule — HHS (2009)
- HIPAA COW (HIPAA Collaborative of Wisconsin)
- Joint Guidance on Application of HIPAA and FERPA to Student Health Records (PDF) — HHS and U.S. Department of Education (2019 update)
- Model Business Associate Agreement—DHS contract detailing how business associates must comply with HIPAA requirements
- Notice of Proposed Rulemaking to Implement HITECH Act Modifications — HHS
Training Resources
- HIPAA 101—HIPAA Collaborative of Wisconsin
- Health IT Privacy and Security Resources for Providers—The Office of the National Coordinator for Health Information Technology
Wisconsin-specific laws
Mental health/SUD/DD
- Confidentiality of treatment records—Wis. Admin. Code ch. DHS 92
- Patient Rights & Resolutions of Grievances—Wis. Admin. Code ch. DHS 94
- State Alcohol, Drug Abuse, Developmental Disabilities, and Mental Health Act—Wis. Stat. § 51.30
- Uses and disclosures of protected health information—Wis. Stat. § 146.816
Medicaid
- General Medicaid Administration—Wis. Admin. Code ch. DHS 108
- Information about Medicaid assistance beneficiaries—Wis. Stat. § 49.475
Providers
- Communicable Diseases – Restrictions on Use of HIV Tests—Wis. Stat. § 252.15
- Miscellaneous Health Provisions (health care records)—Wis. Stat. § 146.81-84
- Uses and disclosures of protected health information—Wis. Stat. § 146.816
Long-term care/family care
- Family Care (Confidentiality and Exchange of Information)—Wis. Admin. Code ch. DHS 10
- Long-Term Care (Confidentiality – Exchange of Information)—Wis. Stat. ch. 46
Additional resources
Refer to these other HIPAA and privacy resources.
- Identity Theft Protection—Department of Agriculture, Trade and Consumer Protection
- Privacy and Security—Federal Trade Commission