1 / 7100%
Lauren,
Thank you for submission and I appreciate your willingness to approach the discussion of
healthcare and technology from the financial point of view. In any discussion, within health care,
it seems financial liability is often a central place of complaint and or debate. While most people
are agreed on receiving the best level of care few are agreed on who is financially responsible. It
has been my personal experience most people have some level of dissatisfaction with costs
associated with of health care however, few people understand where and why these costs are
perceived as high when compared to other nations. In your discussion thread you addressed the
topics of HIPPA, and rising costs tied to insurance. Within the U.S. health care system HIPPA
and the patient’s financial responsibility are two major components that drive health care policy.
Within HIPPA lies the patients’ rights, medical history, plans of care and projected quality of
life. Likewise, a patient’s finances, being private and the means by which to afford quality care
are intensely passionate parts of a patient’s life.
HIPAA (Health Insurance Portability and Accountability Act) is United States legislation that
provides data privacy and security provisions for safeguarding medical information. The law has
emerged into greater prominence in recent years with the many health data breaches caused by
cyber-attacks and ransomware attacks on health insurers and providers.
The federal law was signed by President Bill Clinton on Aug. 21, 1996. HIPAA overrides state
laws regarding the safety of medical information, unless the state law is considered more
stringent than HIPAA.
What is the purpose of HIPAA?
HIPAA, also known as Public Law 104-191, has two main purposes: to provide continuous
health insurance coverage for workers who lose or change their job and to ultimately reduce the
cost of healthcare by standardizing the electronic transmission of administrative and financial
transactions. Other goals include combating abuse, fraud and waste in health insurance and
healthcare delivery, and improving access to long-term care services and health insurance.
What are the 5 main components of HIPAA?
HIPAA contains five sections, or titles:
Title I: HIPAA Health Insurance Reform. Title I protects health insurance coverage
for individuals who lose or change jobs. It also prohibits group health plans from denying
coverage to individuals with specific diseases and preexisting conditions and from setting
lifetime coverage limits.
Title II: HIPAA Administrative Simplification. Title II directs the U.S. Department of
Health and Human Services (HHS) to establish national standards for processing
electronic healthcare transactions. It also requires healthcare organizations to implement
secure electronic access to health data and to remain in compliance with privacy
regulations set by HHS.
Title III: HIPAA Tax-Related Health Provisions. Title III includes tax-related
provisions and guidelines for medical care.
Title IV: Application and Enforcement of Group Health Plan Requirements. Title
IV further defines health insurance reform, including provisions for individuals with
preexisting conditions and those seeking continued coverage.
Title V: Revenue Offsets. Title V includes provisions on company-owned life insurance
and the treatment of those who lose their U.S. citizenship for income tax purposes.
In healthcare circles, adhering to HIPAA Title II is what most people mean when they refer to
HIPAA compliance. Also known as the Administrative Simplification provisions, Title II
includes the following HIPAA compliance requirements:
National Provider Identifier Standard. Each healthcare entity, including individuals,
employers, health plans and healthcare providers, must have a unique 10-digit National
Provider Identifier number, or NPI.
Transactions and Code Sets Standard. Healthcare organizations must follow a
standardized mechanism for electronic data interchange (EDI) in order to submit and
process insurance claims.
HIPAA Privacy Rule. Officially known as the Standards for Privacy of Individually
Identifiable Health Information, this rule establishes national standards to protect patient
health information.
HIPAA Security Rule. The Security Standards for the Protection of Electronic Protected
Health Information (ePHI) sets standards for patient data security.
HIPAA Enforcement Rule. This rule establishes guidelines for investigations into
HIPAA compliance violations.
Providing individuals with easy access to their health information empowers them to be more in
control of decisions regarding their health and well-being.9 For example, individuals with access
to their health information are better able to monitor chronic conditions, adhere to treatment
plans, find and fix errors in their health records, track progress in wellness or disease
management programs, and directly contribute their information to research. With the increasing
use of and continued advances in health information technology, individuals have ever
expanding and innovative opportunities to access their health information electronically, more
quickly and easily, in real time and on demand. Putting individuals "in the driver's seat" with
respect to their health also is a key component of health reform and the movement to a more
patient-centered health care system.
The regulations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA),
which protect the privacy and security of individuals' identifiable health information and
establish an array of individual rights with respect to health information, have always recognized
the importance of providing individuals with the ability to access and obtain a copy of their
health information.9 With limited exceptions, the HIPAA Privacy Rule (the Privacy Rule)
provides individuals with a legal, enforceable right to see and receive copies upon request of the
information in their medical and other health records maintained by their health care providers
and health plans.
General Right
The Privacy Rule generally requires HIPAA covered entities (health plans and most health care
providers) to provide individuals, upon request, with access to the protected health information
(PHI) about them in one or more "designated record sets" maintained by or for the covered
entity. This includes the right to inspect or obtain a copy, or both, of the PHI, as well as to direct
the covered entity to transmit a copy to a designated person or entity of the individual's choice.
Individuals have a right to access this PHI for as long as the information is maintained by a
covered entity, or by a business associate on behalf of a covered entity, regardless of the date the
information was created; whether the information is maintained in paper or electronic systems
onsite, remotely, or is archived; or where the PHI originated (e.g., whether the covered entity,
another provider, the patient, etc.).
This growth represents a range of factors, from new health-care treatments and services to better
coverage, higher utilization, and rising prices. Some of these changes are desirable: As a country
gets richer, spending a higher share of income on health may be optimal (Hall and Jones 2007).
Countries with a higher level of output per capita tend to have a higher level of health
expenditures per capita (Sawyer and Cox 2018). In addition, as the population ages, health
deteriorates and health-care spending naturally rises. Finally, if productivity advancements are
more rapid in tradable goods like agriculture or manufacturing than in services like health care or
education, the latter will tend to rise in relative price and as a share of GDP.
But some of the increase in health-care costs is undesirable (Cutler 2018). Rent-seeking,
monopoly power, and other flaws in health-care markets sometimes result in unnecessary care or
in elevated health-care prices. In several of the facts that follow, we describe these factors and
how they are shaping health care.
Spending by private and public payers have both increased. The United States has a health-care
system that largely consists of private providers and private insurance, but as health care has
become a larger part of the economy, a higher share of health-care funding has been provided by
government (figure B). As of 2018, 34 percent of Americans received their health care via
government insurance or direct public provision (Berchick, Barnett, and Upton 2019).
Some important regulatory bodies in the USA include the State Offices of Health Care Quality
which is responsible for certifying and licensing all the health care and community long-term
care facilities. The Centers for Medicare and Medicaid (CMS) supervise and regulate the
provisions linked to the healthcare system, providing care at a subsidized rate through different
programs.
These include Medicare for older people and the disabled; Medicaid for the low-income
individuals and families; and State Children’s Health Insurance Program (SCHIP) for the under-
19 population. It also monitors compliance with the Health Insurance Portability and
Accountability Act (HIPAA).
Another is the Agency for Healthcare Research and Quality (AHRQ), part of the U.S.
Department of Health & Human Services (HHS), which works to boost the quality of healthcare
and improve patient safety at a lower cost.
Non-profit watchdog organizations include the National Committee for Quality Assurance
(NCQA), which monitors managed care, and the Joint Commission on Accreditation of Health
Care Organizations (JCAHO) that ranks healthcare organizations by the quality of care. Such a
ranking will affect insurance payments. The HHS also heads other regulatory departments,
including the Centers for Disease Control and Prevention (CDC) in Atlanta, that monitors public
health for birth defects, disabilities, genetics, environmental health, injury, violence, and travel
guidelines, among others. It also looks into possible infectious outbreaks.
The Food and Drug Administration (FDA) is a federal agency that oversees the drug supply to
the USA for safety and efficacy. The Environmental Protection Agency (EPA) is a federal
agency concerned with making and enforcing regulations that protect the environment, based on
existing laws.
Following are the regulations that must be complied with in a HIPAA-compliant email:
1. A HIPAA-compliant email must be encrypted as it makes the data unreadable during the
transmission and at rest.
oAs per the HIPAA email rules, the messages in transit containing the ePHI have
to meet the encryption requirements. It helps secure the emails that users are
sending outside a protected email network.
oEmails having PHI shouldn’t be sent unless they are encrypted with a third-party
program or with 3DES, AES, or similar algorithms. If the PHI is in the form of
text, the message must be encrypted. Otherwise, the attachment having the PHI
can be encrypted.
oThough encryption is merely an element of HIPAA email compliance, however, it
is essential. During the interception of a message, the encryption makes the
content unreadable and, thus, more secure by preventing any impermissible
disclosure of ePHI.
2. A covered entity may go for a risk analysis to understand the level of risk and decide
whether encryption will be required or use another option. The OCR requires complete
documents explaining why the encryption has not been chosen and how safe it is to use
the other option.
3. An entity can choose any appropriate encryption method, but it should be on par with the
latest technological advances.
4. HIPAA-covered entities can ensure better security by obtaining up-to-date encryption
guidance from the National Institute of Standards and Technology. It recommends using
Advanced Encryption Standard 128, 192, or 256-bit encryption at the time of writing.
However, these standards tend to change from time to time, so one needs to check
NIST’s latest guidance before implementing email encryption.
References
Oikonomou, E. et al. (2019). Patient Safety Regulation in the NHS: Mapping the Regulatory
Landscape of Healthcare. BMJ Open. https://dx.doi.org/10.1136%2Fbmjopen-2018-028663.
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6615819/
Risso-Gill, I. et al. (2014). Assessing The Role of Regulatory Bodies in Managing Health
Professional Issues and Errors in Europe. International Journal for Quality in Health Care,
Volume 26, Issue 4, August 2014, Pages 348–357. https://doi.org/10.1093/intqhc/mzu036.
https://academic.oup.com/intqhc/article/26/4/348/1789585
Grimm, N. et al. (2021). Healthcare Regulations: Who Does What?
https://www.yourtrainingprovider.com/healthcare-regulations-who-does-what/. Accessed on
October 18, 2021.
A Primer to Public-Private Partnerships in Infrastructure Development. 5.1. Functions of a
regulator. Retrieved from:
https://www.unescap.org/ttdw/ppp/ppp_primer/51_functions_of_a_regulator.html. Accessed on
October 18, 2021.
Students also viewed