PROTECTED MEDICAL INFORMATION—HIPAA AT WORK
On June 5, 1981, five young men in Los Angeles were diagnosed with a rare form of pneumonia, probably Pneumocystis carinii, an opportunistic organism that can be very serious in immunocompromised patients. Over the next few years, it became increasingly clear that these young men were dying from a disorder of their immune system acquired by unknown means. The immune deficiency caused them to be susceptible to infectious organisms that might not be as pathogenic or lethal in immune competent individuals.
Evaluation of these cases, at first called AIDS (acquired immune deficiency syndrome) then later HIV (Human immunodeficiency Virus) revealed most patients were young males, most were men-who-had-sex-with-men, or they were IV drug abusers. This started a firestorm among the general public who were not understanding or sympathetic to the plight of these people. That set off a wave of discrimination of all shapes and sizes affecting these patients who were shunned, isolated, segregated, and treated badly because of their lifestyle behavior.
This response plus reaction to the advent of electronic medical records and health information stored online, prompted the development of a mechanism by which the privacy of HIV patients could be protected. And the private health-related information of the general public could be secured where no one but authorized individuals could access it. Congress was thus motivated to pass the Kennedy-Kassebaum Act, a very comprehensive and complicated law that included HIPAA, the Health Information Portability and Accountability Act of 1996. The main purpose of HIPAA was, and is, to protect sensitive, personal health information, to keep it private and confidential, and establish standards for the management, transmission, and storing of private health information. It also imposed penalties on those who failed to comply with confidentiality regulations.
Strict rules were established to prevent unauthorized access or misuse of sensitive information. This included establishing a system of confidentiality that limited and controlled the disclosure of health information. In other words, an individual’s personal, private health information was no one else’s business. Without written permission, no one had open access to your information except those who had been authorized to do so. What is private to you is private to everyone. Rules for securing that information were set, too.
Another feature of the law was the “portability” aspect. People changing health insurance coverage at the time of a job change were guaranteed to still be insurable by the new insurer despite the presence of pre-existing conditions which might normally cause the person to be uninsurable. Under HIPAA, denial of coverage was prohibited.
The HIPAA law was divided into five sections called TITLES. Each TITLE had a purpose unto not only itself, but also to the entirety of the law.
TITLE I: Established rules protecting individuals from losing health insurance during job changes or after a job loss. The new employer’s plan could not deny coverage for a pre-existing condition that was present during the prior insurance coverage. HIPAA mandated insurers renew individual policies as long as they are offered or provide alternatives regardless of the individuals health condition. Health insurance was now “portable” between jobs. If the person had HIV covered by old insurance, it had to be covered by the new insurance, too.
TITLE II: Established National Provider Identification Numbers (NPI) for practitioners, employers, and health insurance plans. NPI number replaced all but the DEA, state license and Tax ID numbers, and simplified the system by establishing national standards for electronic health transactions. Title II also established policies and procedures for maintaining privacy and security.
TITLE III: Established guidelines for pre-tax medical spending accounts, and introduced changes to health insurance laws and deductions for medical insurance
TITLE IV: Offered guidelines for group healthcare plans and modified health coverage provisions (whatever that means).
TITLE V: Regulated company-owned life insurance policies, and provided guidance for treating non-US citizens.
These “provisions” are all active when they involve a “covered entity.” Any individual working in a health care environment of any sort—hospital, office, clinic, lab, etc.—was bound by all the provisions in HIPAA. That includes healthcare clearing houses, billing companies, employer-sponsored healthcare plans, and vendors of electronic medical records, medical equipment, and supplies, and insurance companies.
Federal standards for electronic medical records were established, too. This provision protected confidentiality, integrity, and availability of health information. The cyber world is susceptible to hacks and misuse of data, and medical data is private domain that demands privacy and confidentiality. HIPAA addresses privacy concerns, and protects it effectively.
The arrival of HIPAA fundamentally changed the way medical records are handled and medical information is stored, used, and disseminated. With this law, any bit of private medical information was placed under lock and key, and if you weren’t authorized to access it, if you tried, there were costly, harsh penalties. HIPAA may possibly have been the event that changed the doctor-patient relationship, and the doctor-institution, patient-institution, and doctor-doctor relationships more than any other. If you knew something, you were not allowed to share it without patient consent.
Privacy, security, and confidentiality were the key points in HIPAA, as well as portability of health care coverage. Penalties for violations made physicians quite wary, and were the fear factor for practitioners. Doctors feared talking to one another especially about a difficult case.
The bottom line for HIPAA lies in its strict privacy and confidentiality provisions that are secure but accessible to the individuals themselves. It protects sensitive data be it written, spoken, or electronic. Sensitive private health information is safe from misuse and unauthorized access. And employees changing jobs and health insurance are guaranteed to not be denied coverage by the new insurer regardless of pre-existing conditions. Mis-application of the law is punishable by heavy fines.
The doctor must be careful what he says and to whom. Old habits are hard to break but must be so private information is not conveyed to someone when it should not. A patient’s trust is gained by careful compliance with the intent and purpose of the law, and it seems physicians have taken HIPAA seriously.
At first, I was totally turned off by this very restrictive law, but time has shown it to be a wise document which has been effectively implemented. It is very protective for those folks at whom discrimination is often imposed. And there is a lot more information and detail about HIPAA that space and time won’t allow us to share. A revisit now and then, especially if new provisions are added, is in order.
References: www.google.com/US Dept of Health and Human Services. “Your rights under HIPAA
www.google.com/health-information-privacy
NCBI Bookshelf. Nat Library of Med/NIH/health-insurance-portability-and-accountability-act-HIPAA-compliance



