"The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is best known for
protecting the privacy and security of patients’ medical records. It provides certain patient rights
over the access, use, and distribution of personally identifiable health information, as well as
criteria for information disclosures and security requirements that health care providers, insurance
plans, and clearinghouses must follow." (Codington-Lacerte, C. 2021)
"Health information technology is protected under the Health Insurance Portability and
Accountability Act of 1996 (HIPAA). HIPAA was enacted to protect health care coverage for people
when they lost employment or changed jobs and safeguard medical information and establish
security standards for access to electronic health care transactions, among other provisions. The
establishment of HIPAA had a great effect concerning how and who can access medical records. It
also laid out penalties for violations, but these were rarely enforced. This led to the creation of
federal health care information privacy and security rules known as the HITECH Act, which
modified some parts of HIPAA and set stricter guidelines for enforcing standards." (Harmon, 2022)
HIPAA and the HITECH Act work simultaneously to ensure patient privacy rights, no matter in
written or electronical form are protected at its highest level and ensure that those that violate
these laws are held at the highest penalty.
took another position in the supply chain for a pharmaceutical company with clinical trials in
progress for new treatments for cystic fibrosis. It was interesting to learn about the different trial
phases and prepare for filing with the FDA in the United States, EMA in Europe, and PMDA in
Japan. Unfortunately, in October 2020, our clinical trial phase III ended with no positive results,
and most of the company was laid off during the COVID pandemic. My nursing program was at a
standstill because hospitals were overwhelmed and did not want students on the floor trying to
train. I always regretted not going into health information technology instead of my MHA, and
after some research, I ended up at SNHU. I currently work for a healthcare technology company
remotely. I analyze eprescribe data from health entities and help them identify different trends
and pharmacies that the entity could contract with for the 340B drug program. I believe my degree
will help me in my current role at my company, and I still want to pursue my nursing degree. I
hope to be a director of quality and care at a hospital. Outside of school and work, I have a six-
year-old daughter, and my husband is preparing for a deployment to Europe this September. My
daughter and I are very active outdoors. We love to hike, and with the summer weather
approaching, we are beach bums on Onset Beach in Wareham.
I believe everyone is familiar with the HIPAA Privacy Rule as the national standard to protect
individuals' health records and any protected health information. Inside the privacy, the rule is the
authorization to release information. The authorization to release information must be a HIPAA
compliant release form and, at the very least, contain the following:
a specific description of the information that will be used/disclosed
the purpose for which the information will be disclosed
the name of the person or entity to whom the information will be disclosed
An expiration date for the consent to use/disclose the information is withdrawn. Some states may
allow an "expiration event," but my health organization was specific about a date.
A signature and date signed by the individual or individual's representative (which will require
another form needed before releasing any information)
For any information released by health professionals, the authorization to release is needed. It is
important for health professionals to be very familiar with this form, know where it is stored in the
health record, and reference the form before giving any information to a person that is not the
patient. The privacy law is very important and needed. I have heard of situations when patients
are brought into the emergency department after a motor vehicle accident with police
accompanying the patient, trying to see if the physician can determine if the patient is under the
influence. Health professionals DO NOT have the right to release any information about that
patient to law enforcement without a subpoena or warrant. Once the patient enters our facility,
our responsibility is to the patient. There are legal ways and processes for law enforcement to use
if a patient's medical record is needed.
HIPAA Journal. (2022, February 3). HIPAA release form. HIPAA Journal. Retrieved May 5, 2022,
from https://www.hipaajournal.com/hipaa-release-form/
Codington-Lacerte, C. (2021). Health Insurance Portability and Accountability Act of 1996. Salem
Press Encyclopedia.
Harmon, A. (2022). Health Information Technology for Economic and Clinical Health Act (HITECH
Act). Salem Press Encyclopedia.