The Health Insurance Portability and Accountability Act of 1996 (HIPAA), was the result of efforts by congressional healthcare reform proponents to reform healthcare. The goals and objectives of this legislation are to streamline industry inefficiencies, reduce paperwork, make it easier to detect and prosecute fraud and abuse and enable workers of all professions to change jobs, even if they (or family members) had pre-existing medical conditions.

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes

•  Name

•  Dates (except year)

•  Zip code of more than 3 digits, telephone and fax numbers, email

•  Social security numbers

•  Medical record numbers

•  Health plan numbers

•  License numbers

•  Photographs

Information shared with other healthcare providers or clearinghouses

•  Nursing and physician notes

•  Billing and other treatment records

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it.

•  Access to PHI,

•  Correction for errors and completeness, and

•  Knowledge of others who use PHI

Safeguarding of PHI means that the persons that hold PHI must

•  Be accountable for own use and disclosure

•  Have a legal recourse to combat violations

How Aspir'e implements HIPAA

• No access to third party email providers

• Zoning of office area and successive swipe card based access controls

• Control on magnetic media (floppy disc, CD, pen drive etc.) in restricted areas

• Locking of confidential documents, mandatory shredding of confidential documents

• Server logging and exception reporting, Periodic audits

• Threat nature

• Source of threat

• Means of potential threat (break in, physical intrusion, computer hack, virus)

• Specific kind of data at risk (patient identification, financials, medical)

 

SECURITY

Physical and electronic access restrictions to work area and network Firewall protection for internal network from the world wide web Enterprise-wide multiple virus protection systems 128-bit SSL and data encryption on all web based applications.

Each user has unique login, power-on and screensaver passwords Controlled media usage/movement through inventory logs and physical checks

User accounts to access shared resources like fax machines and photocopiers Random screening of emails for attachments with PHI

All documentation is kept on our proprietary electronic Document Management System, which is protected by stringent rules of user access, logins and passwords.

 

TRANSACTION STANDARDS

Our systems and processes completely support the usage of the new transaction and code sets under the HIPAA standards provided your third-party or proprietary software supports the same. If you are utilizing the services of a clearinghouse in transmitting claims, we can continue, without altering the arrangement. We currently work with several clearinghouses across the USA, for the transmission of claims and patient bills.

The following transaction sets, are available as part of the standard application:

Information on disclosures can be retrieved at any time. All access to the software is based on logins and passwords, linked to a system of user-groups and rights, ensuring conformance to our 'minimum necessary' policy. Data is backed up daily and an offsite backup maintained as part of our Disaster Recovery Policy.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

•  To assure physical data center security, the manager must

•  Lock data center

•  Manage access list

•  Track data center access with closed circuit TV cameras to monitor both internal and external building activities

•  Protect access to data center with 24 x 7 onsite security

•  Protect backup data

•  Test recovery procedure

Network security

•  Secure networking - firewall protection, encrypted data transfer only

•  Network access monitoring and report auditing

Data security

•  Individual authentication - individual logins and passwords

•  Role Based Access Control

•  Audit trails - all access to all data fields tracked and recorded

•  Data discipline - Limited ability to download data

 

About Us | Site Map | Privacy Policy | Contact Us | ©2006 Aspir'e Solutions
Home | Services | Benefits | Testimonials |Careers |Contact