Law & Ethics
Free course
Version 1.0
Audio version available

Health Insurance Portability and Accountability Act (HIPAA)

To provide an overview of The Health Insurance Portability and Accountability Act (HIPAA) and its regulation, and to equip healthcare providers with the knowledge necessary to navigate compliance and protect patient information effectively.

Contact hours
2
Estimated time
52 minutes
Last reviewed

Free

Get Unlimited CE instead

Secure checkout. Certificates issue instantly and stay in your vault even after a subscription ends.

  • Post-test optional · 70% to pass · unlimited retakes

About this course

The Health Insurance Portability and Accountability Act (HIPAA) is a federal ruling legislated by President Bill Clinton on August 21, 1996, to protect patient information within the healthcare system. The legislation was driven by the increased use of technology in healthcare and the emergence of electronic health records. This course aims to provide a comprehensive understanding of HIPAA and its regulation. This course also aims to equip healthcare providers with the knowledge necessary to navigate compliance and protect patient information effectively.

Learning objectives

  • Describe the federal ruling on Health Insurance Portability and Accountability Act (HIPAA) and the legislated titles that create a framework that protects patient information, promotes efficient data exchange, and improves access to healthcare coverage.
  • Describe the Privacy Rule and its influence on protected health information (PHI).
  • Identify protected entities under HIPPA
  • Understand when information can be disclosed without consent
  • Describe steps that should be taken if unauthorized disclosure of private health information occurs, and penalties that may be imposed.

Course outline

13 sections · finish in any order across devices

  1. 1

    Introduction

    The Health Insurance Portability and Accountability Act (HIPAA) is a federal ruling legislated by President Bill Clinton on August 21, 1996, to protect patient information within the healthcare system.1 This legislation was driven by the increased use of technology in healthcare and the emergence of

    4 min

  2. 2

    HIPAA Privacy Rule

    The Standards for Privacy of Individually Identifiable Health Information in HIPAA, or Privacy Rule, set national standards for the disclosure and use of patient’s health information, i.e., Protected Health Information (PHI) along with electronic Protected Health Information (ePHI), by covered entit

    4 min

  3. 3

    Covered Entities

    Figure 1: Structure of HIPAA Covered Entities and Business Associates

    4 min

  4. 4

    Permitted Disclosure of Protected Health Information (PHI)

    Under HIPAA, there are several instances of permitted disclosure where a healthcare entity or covered entity can share PHI, provided they have patients’ consent.5 These include (1) Marketing and communication purposes. When healthcare providers or related entities wish to use PHI for marketing, expl

    4 min

  5. 5

    Protected Health Information (PHI)

    Protected Health Information (PHI) is any health information that can be used to identify an individual and is created, received, stored, or transmitted by covered entities.6 PHI can be in any form—oral, written, or electronic—and relates to an individual’s past, present, or potential physical or me

    4 min

  6. 6

    When Information Can Be Disclosed Without Consent

    HIPAA’s Privacy Rule also specifics conditions under which PHI can be disclosed without an individual’s explicit authorization.7 These conditions are known as TPO, which stands for treatment, payment, and healthcare operations. Disclosures related to treatment allow healthcare providers to share inf

    4 min

  7. 7

    HIPAA Security Rule

    Figure 2: Patient Rights Under the HIPAA Privacy Rule

    4 min

  8. 8

    Protecting Patient Information in Healthcare Settings

    Protecting patient information in healthcare settings is a critical responsibility that involves implementing a series of best practices, utilizing technology and data security measures, and having effective incident response plans in place.9 These efforts start with staff training. Healthcare provi

    4 min

  9. 9

    Notice of Privacy Practices (NPP)

    The Notice of Privacy Practices (NPP) is an essential document that informs patients of their rights concerning their PHI, detailing how healthcare providers may use and disclose this information.10 Required by HIPAA’s Privacy Rule, the NPP promotes transparency in the patient-provider relationship

    4 min

  10. 10

    Handling Unauthorized Disclosure of Patient Information

    When an unauthorized disclosure of patient information occurs, it is essential for healthcare organizations to respond swiftly to mitigate potential harm while still ensuring compliance with HIPAA regulations.2 The first step in addressing a breach is to follow established reporting procedures. This

    4 min

  11. 11

    Penalties for Sharing Patient Information

    Violating HIPAA results in significant penalties for covered entities, as non-compliance can lead to both civil and criminal repercussions.12 However, the severity of these penalties varies based on the nature of non-compliance, extent of the violation, and whether or not the covered entity knew or

    4 min

  12. 12

    Texas Considerations

    In Texas, there are supplementary regulations that work alongside the federal framework established by HIPAA. These state laws are designed to strengthen the protection of patient information, requiring healthcare providers to comply not only with HIPAA standards but also with state mandates that en

    4 min

  13. 13

    Conclusion

    The Health Insurance Portability and Accountability Act (HIPAA) is a foundational step in the ongoing effort to safeguard patient data. HIPAA’s Privacy Rule and Security Rule delineate comprehensive protocols for managing PHI, ensuring that healthcare providers, plans, and clearinghouses operate wit

    4 min

This course satisfies

    Requirement summaries come from our state requirement records. Always confirm details with your board before you renew.

    References and resources

    • [1] US Department of Health & Human Services. (2019). Health Information Privacy. HHS.gov. https://www.hhs.gov/hipaa/index.html
    • [2] US Department of Health and Human Services. (2022). Summary of the HIPAA privacy rule. HHS.gov; US Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
    • [3] US Department of Health & Human Services. (2022). The HIPAA Privacy Rule. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
    • ‌[4] CDC. (2024, September 10). Health Insurance Portability and Accountability Act of 1996 (HIPAA). Public Health Law. https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html
    • [5] CDC. (2024, September 10). Health Insurance Portability and Accountability Act of 1996 (HIPAA). Public Health Law. https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html
    • ‌[6] HealthIT.gov. (2019). Guide to Privacy & Security of Electronic Health Information | HealthIT.gov. Healthit.gov. https://www.healthit.gov/topic/health-it-resources/guide-privacy-security-electronic-health-information
    • [7] Nass, S. J., Levit, L. A., Gostin, L. O., & US), M. (2015). HIPAA, the Privacy Rule, and Its Application to Health Research. Nih.gov; National Academies Press (US). https://www.ncbi.nlm.nih.gov/books/NBK9573
    • [8] Office for Civil Rights. (2022, October 19). Summary of the HIPAA security rule. US Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
    • [9] McGraw, D., & Mandl, K. D. (2021). Privacy protections to encourage use of health-relevant digital data in a learning health system. NPJ Digital Medicine, 4(1). https://doi.org/10.1038/s41746-020-00362-8
    • [10] Rights (OCR), O. for C. (2008, November 19). Notice of Privacy Practices. HHS.gov. https://www.hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html
    • [11] Rights (OCR), O. for C. (2009, January 7). Notice of Privacy Practices for Protected Health Information. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/privacy-practices-for-protected-health-information/index.html
    • [12] American Medical Association. (2023). HIPAA violations & enforcement. American Medical Association. https://www.ama-assn.org/practice-management/hipaa/hipaa-violations-enforcement
    • [13] Office for Civil Rights (OCR). (2008, November 12). How OCR Enforces the HIPAA Privacy & Security Rules. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/examples/how-ocr-enforces-the-hipaa-privacy-and-security-rules/index.html
    • [14] Merrill, M. (2011, September 29). TRICARE breach puts 4.9M military clinic, hospital patients at risk. Healthcare IT News. https://www.healthcareitnews.com/news/tricare-breach-puts-49m-milatry-clinic-hospital-patients-risk
    • [15] Rights (OCR), O. for C. (2017, February 14). $5.5 million HIPAA settlement shines light on the importance of audit controls. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/memorial/index.html
    • [16] Virginia Doctor Indicted on HIPAA Charge for Talking to Patient’s Employer | Casetext. (2024). Casetext.com. https://casetext.com/analysis/virginia-doctor-indicted-on-hipaa-charge-for-talking-to-patients-employer
    • [17] Rights (OCR), O. for C. (2011, February 22). Civil Money Penalty. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/examples/cignet-health/index.html
    • [18] KOCZKODAJ, W. W., MASIAK, J., MAZUREK, M., Dominik STRZAŁKA, & ZABRODSKII, P. F. (2019). Massive Health Record Breaches Evidenced by the Office for Civil Rights Data. Iranian Journal of Public Health, 48(2), 278. https://pmc.ncbi.nlm.nih.gov/articles/PMC6556182
    • [19] HIPAA & Privacy Laws. (n.d.). Texas Health and Human Services. https://www.hhs.texas.gov/regulations/legal-information/hipaa-privacy-laws
    • [20] Identity Theft Enforcement And Protection Act | Office of the Attorney General. (n.d.). Www.texasattorneygeneral.gov. https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/identity-theft-enforcement-and-protection-act

    Update history

      Take this course and the rest of the library

      Unlimited annual access covers every course, every state you track, and your certificates forever.

      Get Unlimited CE

      Still have a question? Ask our CE assistant

      Ask by voice or text about requirements, courses, pricing or your license — you get an answer instantly.

      Ask us — instant answer
      Ask anything about your license

      Type or tap the mic and speak — ask about your state's requirements, any course, your license type or pricing, and you get an answer right away.