1 / 5100%
I live on a one-acre "urban farm" about 10 minutes from downtown Omaha with my two littles
and husband, who sells produce at the local farmer's market and runs a yearly CSA with five
members. My son recently turned 8 and my daughter is 3, and we have a Great Pyrenees mix
named Max, a "barn" cat named Chuck, 5 chickens, and 7 quail. When I do get free time (lol),
I love to read and am the steward for two Little Free Libraries in our front yard.
The main regulation under HIPAA that governs the secure handling of PHI is the Privacy
Rule, which was issued by the U.S. Department of Health and Human Services to address the
use and disclosure of individuals' health information. The Privacy Rule also contains standards
that cover an individual's right to control how their health information is used. Ensuring the
flow of health information to promote high-quality patient care and outcomes while protecting
a patient's privacy is the main goal of the Privacy Rule. It also creates proper safeguards that
healthcare providers must implement to protect PHI, and it holds violators accountable with
criminal and civil penalties if a patient's privacy is breached.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security,
and Breach Notification Rules are the main Federal laws that protect health information. The
Privacy Rule gives you rights with respect to your health information. The Privacy Rule also
sets limits on how your health information can be used and shared with others. The Security
Rule sets rules for how your health information must be kept secure with administrative,
technical, and physical safeguards.
The HITECH Omnibus Rule, effective in 2013, provides increased protection and control of
protected health information (PHI). This rule also extends disclosure requirements and
associated liabilities under HIPAA to business associates. Business associates are required to
comply with the same disclosure requirements as a covered entity. These requirements are
typically outlined in business agreement with the covered entity and the business associate
These rules are necessary to assure patients that the health information they share with
healthcare professionals will remain confidential. Critical information may be withheld by
patients if they do not feel that the confidentiality and security are not in place. This could
affect the quality, safety, and outcome of the care provided.
Health Information Management is essential for healthcare providers and other HIPAA-
covered entities to ensure patient information privacy and security. HIM involves medical
coding and billing, ensuring compliance with government regulations, and handling customer
requests for Personal Health Information (PHI). This field also involves medical records
retention and transition to electronic formats, as well as analysis of health care trends and the
implementation of improvements. Because healthcare information overlaps many different
areas in any healthcare cycle, it became necessary for many organizations to create HIM
departments to oversee these important requirements are adhered to as well as managing
training and education of staff. Healthcare Information Managers would oversee all facets of
an organization’s collection and retention of records as well as security, privacy, analysis, and
implementations, coding, billing, and compliance.
“Health Information Management (HIM) is the practice of acquiring, analysing, and
protecting digital and traditional medical information vital to providing quality patient care.”
(AHIMA Library American Health Information Management Association standards of ethical
coding [2016 version]. HIM Body of Knowledge. (n.d.). Retrieved May 5, 2022, from
https://library.ahima.org/CodingStandards
What is Health Information Management & Why is it important? Near-term. (2018, October
4). Retrieved May 5, 2022, from https://nearterm.com/what-is-health-information-
management-why-is-it-important/
What privacy and security laws protect patients' health information? HealthIT.gov. (2018,
November 13). Retrieved May 5, 2022, from https://www.healthit.gov/faq/what-privacy-and-
security-laws-protect-patients-health-information
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 set the standards
for securing health information and protecting privacy. This federal legislation was critical as
healthcare organizations transitioned to electronic health records (EHRs). EHRs improve
continuity of care because data can be easily shared among clinics, hospitals, and providers,
but standards are necessary to ensure the transmission and exchange of information is secure
(Oachs & Watters, 2020).
There are three regulations within HIPAA that protect health information and provide patient
rights regarding their health information. The Privacy Rule pertains to how the health
information is used and to who it is given. It also sets standards for patients' rights to access
their health information and control how it is used and shared. The Security Rule takes the
standards outlined in the Privacy rule and puts them into action. This rule describes the
administrative, physical, technical, and organizational safeguards that need to be utilized to
ensure that protected health information is secure. The Breach Notification Rule requires
entities to inform patients when their data has been breached. This rule also requires entities to
have procedures in place to investigate when health information is used or shared without
authorization (Oachs & Watters, 2020).
Laws that protect patient health information are necessary because this information contains
confidential and sensitive information. Laws and regulations help determine what is
considered protected health information, how it should be managed, and penalties for non-
compliance. Patients trust that their healthcare practitioners and organizations will keep their
information secure. If patients are concerned that their health information may be mishandled,
this may deter them from seeking care.
There are so many laws that are in place to protect patient health information, and in additions
to many state regulations there are also federal laws such as the Health Insurance Portability
and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical
Health Act (HITECH), and American Recovery and Reinvestment Act of 2009 (ARRA) for
example. HIPAA, often seen misspelled as HIPPA on resumes, is the main federal law that
provides rules and regulations for protection of PHI and was enacted in 1996. Following
HIPAA in 2009 was HITECH, which evolved or widened the scope of protections of HIPAA
and expanded it to other entities not previously covered under HIPAA. HITECH is part of the
ARRA which was passed to aide in the promotion of the creation of a national healthcare
infrastructure by instituting the adoption and meaningful use of EHR systems by healthcare
providers, as well as the sharing of health information through health information exchanges
(HIEs) (Brodnik et al., 2017).
As someone who has been in HIM in one form or another, I think these laws are very
important. Everyone has a right to privacy especially as it relates to their health conditions and
patients should have a reasonable expectation of confidentiality. In the technological climate
of today, it is even more important to have laws to ensure proper handling of our patient health
information. We do need a patient's colonoscopy going viral on TikTok after all! The laws are
needed to help deter intentional breaches of information and these laws seemingly deter these
intentions.
Brodnik, M. S., Rinehart-Thompson, L. A., Reynolds, R. B., & American Health Information
Management Association. (2017). Fundamentals of law for health informatics and information
management. Ahima Press.
Oachs, P., & Watters, A. (2020). Health information management: Concepts, principles, and
practice (6th ed.). AHIMA, American Health Information Management Association.
Lutkevich, B., Wallask, S., & DelVecchio, A. (2021, April 5). Protected health information
(PHI) or personal health information. SearchHealthIT. Retrieved May 5, 2022, from
https://www.techtarget.com/searchhealthit/definition/personal-health-information
Office for Civil Rights (OCR). (2021, July 27). Summary of the HIPAA privacy rule.
HHS.Gov. Retrieved May 5, 2022, from https://www.hhs.gov/hipaa/for-
professionals/privacy/laws-
regulations/index.html#:%7E:text=The%20Privacy%20Rule%20protects%20all,health%20in
formation%20(PHI).%22
Students also viewed