Certified Solutions.
HIPAA became law - Answer: 1996
What is the purpose of HIPAA? - Answer: • To make health insurance portable under ERISA;
• To move health care onto a nationally standardized electronic billing platform; and
• To prevent fraud, waste and abuse
Intent - Answer: purpose of this subtitle to improve the Medicare program under title XVIII of
the Social Security Act, the Medicaid program under title XIX of such Act, and the efficiency and
effectiveness of the health care system, by encouraging the development of a health
information system through the establishment of standards and requirements for the electronic
transmission of certain health information.
What is Protected Health Information (PHI)? - Answer: information that is transmitted by
electronic media, maintained in electronic media, or transmitted or maintained in any other
Page 1 of 19
,form or medium. PHI excludes IIHI in education records covered by the Family Educational
Rights and Privacy Act (FERPA)
What is Electronic Protected Health Information
(EPHI)? - Answer: is when IIHI is transmitted by electronic media or maintained in electronic
media.
What is De-identified Information? - Answer: To be de-identified the data set must exclude:
• Names
• Geographic subdivisions smaller than a state,
except for the initial three digits of a zip code if,
according to the current publicly available data
from the Bureau of the Census:
--The geographic unit formed by combining
all zip codes with the same three initial digits
contains more than 20,000 people; and
--The initial three digits of a zip code for all
such geographic units containing 20,000 or
fewer people is changed to 000
• All elements of dates (except year) for dates
directly related to an individual, including birth
date, admission date, discharge date, date of
death; and all ages over 89 and all elements of
dates (including year) indicative of such age,
except that such ages and elements may be
aggregated into a single category of age 90 or
older
• Telephone numbers
• Fax numbers
Page 2 of 19
, • Electronic mail addresses
• Social security numbers
• Medical record numbers
• Health plan beneficiary numbers
• Account numbers
• Certificate/license numbers
• Vehicle identifiers and serial numbers, including
license plate numbers
• Device identifiers and serial numbers
• Web Universal Resource Locators (URLs)
• Internet Protocol (IP) address numbers
• Biometric identifiers, including finger and voice
prints
• Full face photographic images and any
comparable images; and
• Any other unique identifying number,
characteristic, or code, except as permitted; and
--The CE does not have actual knowledge that the information could be used alone or
in combination with other information to
identify an individual who is a subject of the
information.
What is Limited data set? - Answer: CE may use or disclose a
limited data set if the CE enters into a data use agreement with the following direct identifiers
of the individual or of relatives, employers, or
household members of the individual:
• Names;
• Postal address information, other than town or
city, state, and zip code;
Page 3 of 19