HIPAA Overview
HIPAA (the Health Insurance Portability and Accountability Act) is a federal law designed to protect sensitive health information from being disclosed without a patient's consent or knowledge. It sets standards for handling, storing, and sharing protected health information (PHI) to ensure the privacy and security of medical records.
Protected health information (PHI) includes any identifiable health information – such as medical records, diagnoses, treatment plans, and payment information or billing history – that is held or transmitted by a healthcare provider, health plan, or healthcare clearinghouse.
HIPAA rules
The law is broken down into three primary standards:
- The Privacy Rule: Sets national standards for who can access a patient’s health information and dictates how it can be used or disclosed or shared.
- The Security Rule: Focuses on safeguarding PHI.
- Portability: Ensures employees and their families can keep and transfer their health insurance coverage if they lose or change jobs.
Patients have rights to control their health information
Get it: Access to a health record is a powerful tool in staying healthy. It helps patients make better decisions with doctors and track progress. Patients have the right to see and get copies of their medical record and other health information. Typically, they can get copies the way they want them, such as by email. Patients may have to put the request in writing and pay for the cost of copying and mailing. In most cases, copies must be given within 30 days, and a request can’t be denied due to unpaid medical bills.
Check it: If a patient thinks something is wrong or missing from their file, they can ask their doctor to fix it. The doctor might not agree, but patients always have the right to have their disagreement added to their record. For example, if a patient and their doctor agree that the file has the wrong result for a test, the doctor can change it. Even if the doctor believes the test result is correct, a patient still has the right to have their disagreement noted in their file. In most cases, the file should be updated within 60 days.
Know who has seen it: By law, protected health information can be used and shared for specific reasons not directly related to someone's care, like making sure doctors give good care, making sure nursing homes are clean and safe, reporting when the flu is in the community, or reporting as required by state or federal law. In many of these cases, a patient can find out who has seen their health information.
Generally, someone's health information cannot be used for purposes not directly related to their care without their permission. For example, a doctor cannot give health information to an employer, or share it for things like marketing and advertising, without the patient's written authorization. A patient should have received a notice explaining how health information may be used on their first visit to a new healthcare provider or when they got new health insurance, but anyone can ask for another copy anytime.
Limit how information is shared: Patients have the right to decide who sees their information and can request limits on how it is used. They can ask that their health information not be shared with certain people, groups, or companies. If they go to a clinic, for example, they can ask the doctor not to share their medical records with other doctors or nurses at the clinic. Patients can ask for other kinds of restrictions, but providers do not always have to agree to do what a patient asks, particularly if it could affect their care. However, if a patient requests, a healthcare provider or pharmacy must not tell a patient’s health insurance company about a payment, item, or service if the information relates to care they received or drugs they take which the patient has paid for in full out of pocket.
Providers must restrict disclosures to a health plan if the disclosure is for payment or healthcare operations and the disclosure relates to a healthcare item or service which the patient has paid the provider in full out of pocket.
Request alternative confidential communications: Patients can make reasonable requests to be contacted at different places or in a different way. For example, they can ask to have a nurse call them on their cell phone or at their office instead of their home phone or to send mail in an envelope instead of on a postcard.
Know how information is used: Providers must give every new patient or patients that ask for it a Notice of Privacy Practices detailing how they use and share PHI. Additionally, existing patients must receive a Notice of Privacy Practice every three years or when there are significant changes. The notice explains how someone's health information may be shared for routine purposes such as treatment, healthcare operations, and billing. It details situations where data must be legally shared without a patient's permission such as for public health reporting, to law enforcement, or to prevent a serious threat to safety). It lists a patient's rights, including their ability to request copies of their records, request changes to incorrect information, and limit who can see information. And it explains exactly how to file a complaint if someone believes their privacy rights have been violated.
File a complaint: If someone thinks their rights are being denied or their health information is not being protected, they have the right to file a complaint with their provider, health insurer, or the U.S. Department of Health and Human Services (HHS).
The Own Your Rights printable one-pager also lists these rights.
Who must protect a patient’s health information?
Patients have rights under the HIPAA that providers are required to follow. These rules apply to covered entities and business associates, which include:
Healthcare providers
*if they transmit information in an electronic form
- Chiropractors
- Clinics
- Dentists
- Doctors
- Nursing Homes
- Pharmacies
- Psychologists
Health plans
- Employer-sponsored health plans
- Government programs that pay for healthcare, like Medicare, Medicaid, and military and veterans’ health programs
- Health insurance companies
- HMOs (health maintenance organizations)
Healthcare clearinghouses
- Consultants that perform utilization reviews for a hospital
- Independent medical transcriptionists who work with physician
- Organizations that process health information for other organizations
- Third-party administrators that help with claims processing
Provider responsibilities
HIPAA also includes rules for covered entities:
The Privacy Rule: Dictates how Protected Health Information (PHI) can be used and shared. Providers must:
- Protect patients’ PHI.
- Give patients a clear, written explanation of their privacy rights and how their PHI is used. That's called a Notice of Privacy Practices (NPP).
- Allow patients to access, get copies of, and request changes to their health records.
- Limit the use and disclosure of PHI to what is minimally necessary for treatment, payment, and healthcare operations.
- Have a privacy officer.
- Get written authorization before sharing PHI outside of their organization, for example, when sharing PHI on websites or social media or for marketing with some exceptions.
The Security Rule: Focuses on safeguarding Protected Health Information (PHI). Covered entities are responsible for:
- Ensuring safeguards are in place to control access to data, both physically and electronically.
- Conducting regular risk assessments and training the workforce on HIPAA compliance.
The Breach Notification Rule: If a data breach occurs, a covered entity must:
- Notify affected patients without unreasonable delay (typically within 60 days).
- Notify the U.S. Department of Health and Human Services.
- Within 60 days if the breach affects 500 or more people.
- Within 60 days after the end of the calendar year if the breach affects fewer than 500 people.
Patients have rights under the Privacy Rule that providers are required to follow. The Provider’s Responsibilities in Patient Rights for HIPAA explains these rights in plain language. This information is available to providers, as required by 2013 Wisconsin Act 238 (Wis. Stat. §146.816(4)).
More information
Find resources to help patients understand their rights and help providers become and stay compliant with HIPAA rules.