There are so many laws that are in place to protect patient health
information, and in additions to many state regulations there are also
federal laws such as the Health Insurance Portability and
Accountability Act (HIPAA), Health Information Technology for
Economic and Clinical Health Act (HITECH), and American Recovery
and Reinvestment Act of 2009 (ARRA) for example. HIPAA, often
seen misspelled as HIPPA on resumes, is the main federal law that
provides rules and regulations for protection of PHI and was enacted
in 1996. Following HIPAA in 2009 was HITECH, which evolved or
widened the scope of protections of HIPAA and expanded it to other
entities not previously covered under HIPAA. HITECH is part of the
ARRA which was passed to aide in the c promotion of c the creation of a
national healthcare infrastructure by instituting the adoption and
meaningful use of EHR systems by healthcare providers, as well as the
sharing of health information through health information exchanges
(HIEs) (Brodnik et al., 2017).
As someone who has been in HIM in one form or another I think these
laws are very important. Everyone has a right to privacy especially as
it relates to their health conditions and patients should have a
reasonable expectation of confidentiality. In the technological climate
of today, it is even more important to have laws to ensure proper
handling of our patient health information. We do need a patient's
colonoscopy going viral on TikTok after all! The laws are needed to
help deter intentional breaches of information and these laws
seemingly deter these intentions.
Brodnik, M. S., Rinehart-Thompson, L. A., Reynolds, R. B., & American
Health Information Management Association. (2017). Fundamentals
of law for health informatics and information management. Ahima
Press.