The HIPAA Privacy Rule focuses on the right of an individual to control the use of his or her personal/protected health information (PHI). Examples - messages left on answering machines, video conference recordings or paper-to-paper faxes.

The HIPAA Security Rule focuses on administrative, technical and physical safeguards specifically as they relate to Electronic PHI (ePHI). Examples - ePHI can be found in medical records, billing records, insurance/benefit enrollment and payment, claims payment, and case management records which can be stored on a computer, transmitted over the internet, and then downloaded onto a drive.

hippa mascot3

words

HIPAA Privacy Rule

  • This rule was passed in 2003 and is focused on protecting the rights of an individual and their ability to control and access their own Personal/Protected Health Information (PHI).
  • Covers any individually identifiable health information that is disclosed in any format whether electronically, on paper or verbally.
  • Lays out 18 identifiers that specify the information as PHI.
  • Outlines how medical organizations can use the data for necessary functions such as treatment, operations, and payment.
  • Patients should have access to the same information about themselves that their doctors do, and they should get some level of authority over where that information goes and who has access to it.

HIPAA Security Rule

  • Only falls under the protection of ePHI. ePHI is the electronic version of all things that are considered PHI. 
  • Ensures the confidentiality, integrity, and availability of all ePHI that is created, received, maintained, or transmitted.
  • Identify and protect against reasonably anticipated threats to the security or integrity of the information.
  • Protect against impermissible uses or disclosures of ePHI that are reasonably anticipated.
  • Government Agencies, Covered Entities (Health Plans, Doctors, Dentists, Clinics, Pharmacies), and Business Associates are required to implement physical, technical and administrative safeguards.

chart

 

If you would like general information about HIPAA, click to view the HIPAA page. Or, if you would like information regarding Travis County’s HIPAA Policies, or to report a suspected privacy concern, contact the Travis County Compliance and Privacy Officer