HIPAA Compliance Case Study

523 Words2 Pages

The two main questions that many mental health care professionals pose in relation to HIPAA (the Health Insurance Portability and Accountability Act) are: 1. If I am a solo practitioner – do I need to comply with HIPAA? 2. Do I need to become HIPAA compliant even though I do not submit electronic bills to insurance companies? Many therapists and mental health organizations believe they are exempt from the HIPAA regulations if they do not electronically submit bills to insurance. While it is true that generally only mental health care professionals who transmit electronic billing to insurance are covered by HIPAA, HIPAA remains an important aspect of the standard of care when it comes to security and privacy regarding electronic records. …show more content…

Under HIPAA, certain restrictions apply if and when PHI is transmitted electronically. HIPAA Security Rule requires that those subject to HIPAA maintain reasonable and appropriate administrative, technical, and physical safeguards for protecting PHI. Administrative safeguards address the implementation of office policies and procedures, staff training, and other measures designed to carry out security requirements. Physical safeguards require providers to implement policies and procedures that limit physical access to electronic and physical information systems (e.g., computers, files, etc.) and the facilities (e.g., a business office) in which the records are housed. Examples might be as simple as a lock on the door of the room in which the computers are located or as complex as a retinal scan. Technical standards require a provider to create policies and procedures that govern the technical aspects of accessing PHI within computer systems by appropriate persons, such as implementing access controls, regularly updating and running anti-virus and firewall software, using and regularly changing individual passwords, using secure transmission systems or encryption when e-mailing or transmitting patient

Open Document