HIPAA: Then & Now

A story about HIPAA that starts with once upon a time, in the late 1990s, the U.S. healthcare system was in dire need of a change. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was created to address this need. The act aimed to improve the portability and accountability of health insurance coverage, guarantee coverage for employees with pre-existing conditions, and prevent โ€œjob lockโ€ โ€“ a scenario in which plan members stayed in a job to avoid losing health benefits.

HIPAA introduced several measures to ensure the continuity of coverage between jobs, including the creation of national standards to protect sensitive patient health information from being disclosed without the patientโ€™s consent or knowledge. The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The Privacy Rule standards address the use and disclosure of individualsโ€™ health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called โ€œcovered entitiesโ€. The Privacy Rule also contains standards for individualsโ€™ rights to understand and control how their health information is used.

The story of HIPAA is not just about the creation of a law, but also about the implementation and enforcement of that law. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. The Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.

The implementation of HIPAA has not been without its challenges. There have been concerns about the cost of implementing the Privacy and Security Rules, as well as understanding what is reasonable and appropriate for an organization, based on size. However, the benefits of HIPAA are clear. The act has helped to ensure that patientsโ€™ health information is protected, and that they have greater control over how their information is used. The act also required that Covered Entities and Business Associates must do to protect that information and comply with the HIPAA Security Standards and Implementation Specifications.

In 2009, the enforcement authority was delegated to the HHS Office for Civil Rights (OCR) by then U.S. Secretary of Health and Human Services, Kathleen Sebelius. Since then, OCR has settled or imposed a civil money penalty in 137 cases resulting in a total dollar amount of almost $137 million. OCR continues to investigate privacy and security complaints against numerous organizations and businesses, regardless of size.

But legislative changes are needed, especially with the advancements in health technology applications and data analytics. The regulations have not kept pace with technical safeguard requirements. From a compliance standpoint, there are times when it feels like you are trying to stick a round peg into a square hole. It takes experienced compliance officers, HIPAA consultants, and lawyers to understand what the regulations call for, now almost 30 years since HIPAA was enacted. At some point, Congress will need to tackle the issue of updating the HIPAA regulations. For now, keep those round pegs available.