The HIPAA Minimum Necessary Rule Standard
The HIPAA minimum necessary rule standard applies to uses and disclosures of PHI that are permitted under the HIPAA Privacy Rule, including the accessing of PHI by healthcare professionals and disclosures to business associates and other covered entities. The standard also applies to requests for protected health information from other HIPAA covered entities. Under the HIPAA minimum necessary principle, HIPAA-covered entities are required to make reasonable efforts to ensure that uses and disclosures of PHI is limited to the minimum necessary information to accomplish the intended purpose of a particular uses or disclosure. The terms ‘reasonable’ and ‘necessary’ are open to interpretation which can cause some confusion. The use of these terms leaves it up to the judgement of the covered entity as to what information is disclosed and the efforts that should be made to restrict disclosures to more than necessary. Any decisions that are made with respect to the minimum necessary standard should be supported by a rational justification, should reflect the...
Can E-Signatures Be Used Under HIPAA Rules?
E-signatures can be used under HIPAA Rules provided mechanisms are put in place to ensure the authenticity of the signatory, to ensure the contract, document, agreement, or authorization signed with a digital signature meets legal compliance requirements, and to ensure that any PHI contained within the document is protected from unauthorized access and disclosure. The use of digital and electronic signatures in the healthcare industry helps improve the efficiency of many processes, yet questions exist about whether e-signatures can be used under HIPAA Rules. The questions primarily exist because, in the original text of HIPAA (§1173), the Secretary for Health and Human Services (HHS) is instructed to: “Adopt standards specifying procedures for the electronic transmission and authentication of signatures with respect to the transactions referred to in subsection (a)(1).” [subsection (a)(1) relates to the financial and administrative transactions in Part 162 of the HIPAA Administrative Simplification Regulations]. A proposed standard for the use of HIPAA-compliant digital signatures...
What Are Covered Entities Under HIPAA?
Examples of covered entities under HIPAA include qualifying health plans, health care clearinghouses, and healthcare providers that transmit Protected Health Information electronically for an activity regulated by HIPAA for which the Department of Health and Human Services (HHS) has adopted standards. It is important to understand which individuals, institutions, and organizations qualify as covered entities under HIPAA because these entities are required to comply with all applicable HIPAA compliance standards and implementation specifications. Generally, covered entities under HIPAA fall into three main categories: 1. Health Plans Health plans that provide healthcare coverage as their principal activity are required to comply with HIPAA. Examples of covered entities under HIPAA in this category include health insurance companies, health maintenance organizations, publicly funded healthcare programs (i.e., Medicare), and military and veterans’ health programs. Insurance companies that pay for health care as a secondary benefit are not covered entities under HIPAA. For example, if...
What Happens if You Violate HIPAA?
What happens if you violate HIPAA depends on the nature and consequences of the violation, the motive for the violation, and whether you knew – or should have known – that the violation was indeed a violation. What happens if you violate HIPAA can also depend on if or how the violation is identified. To help explain the many different factors that can influence what happens when you violate HIPAA, we will use as an example a healthcare employee who shares their EHR login credentials in the belief that a junior colleague wants to access a patient´s file in order to phone the patient´s family with an update. If the junior colleague only uses the login credentials to obtain a phone number and phone the patient´s family with an update – and the patient has not objected to this information being shared with their family – no harm has occurred and there has been no impermissible use or disclosure of PHI. Nonetheless, although the motive for sharing the EHR login credential is well meaning (and the healthcare employee does not have to stop what they are doing to retrieve the...
The Use of Technology and HIPAA Compliance
The use of technology and HIPAA compliance has become an increasingly complex subject due to the rapid adoption of technology in the health care and health insurance industries over the past twenty five years. The evolving nature of HIPAA compliant healthcare technology and the ever-changing threat landscape are also factors that can impact HIPAA compliance. At the time HIPAA was passed in 1996, healthcare IT was very different from what it is today. The passage of HIPAA coincided with the launch of the first webmail service (Hotmail), the dot.com bubble was yet to burst, the first AWS web services were still six years into the future, and it would be more than ten years until the iPhone became available. For reference, Gmail did not come out of “beta” until 2009. Acknowledging the emergence of new technologies, the Department of Health and Human Services (HHS) designed the HIPAA Security Rule to be “technology neutral”. Discussing the rationale for this in what was effectively the first legal guidelines on the appropriate use of technology in healthcare, HHS explained that the...



