Related Experiment Videos
HIPAA privacy standards raise complex implementation issues.
1Latham & Watkins, San Francisco, California, USA.
Summary
Healthcare organizations must implement new processes and information systems to comply with the Health Insurance Portability and Accountability Act (HIPAA) privacy standards, which define data use, individual rights, and administrative safeguards.
Area of Science:
- Health Informatics
- Healthcare Compliance
- Information Privacy
Background:
- The Health Insurance Portability and Accountability Act (HIPAA) of 1996 mandated the protection of electronic personal health information.
- Proposed privacy standards were issued by HHS in November 1999, with finalization imminent.
Purpose of the Study:
- To outline the key objectives of the HIPAA privacy standards.
- To inform healthcare organizations about necessary preparations for compliance.
Main Methods:
- The study reviews the proposed HIPAA privacy standards.
- It identifies essential administrative safeguards required for compliance.
Main Results:
- The standards aim to define protected health information (PHI) use and disclosure.
- They establish individual rights concerning PHI.
- Mandatory administrative safeguards include privacy officers, training, complaint systems, and sanctions.
Conclusions:
- Healthcare organizations must proactively implement new systems and processes.
- Compliance with HIPAA privacy standards is crucial for protecting patient data.