What Is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects the privacy and security of patient health information. It sets standards for how healthcare organizations collect, use, store, and share Protected Health Information (PHI). By following HIPAA, healthcare professionals help protect patient data, maintain compliance, and build trust between patients and providers..

Goals of HIPAA
HIPAA was created to protect patient information while supporting secure and efficient healthcare operations. Its rules help healthcare organizations safeguard sensitive data, maintain compliance, and build confidence between patients and providers.
Protect Patient Privacy
Ensure that patient health information is accessed and shared only by authorized individuals for approved healthcare purposes.
Secure Health Information
Protect paper records, electronic records, and other forms of patient information from unauthorized access, loss, or misuse.
Standardize Healthcare Transactions
Support the secure exchange of healthcare information by using standardized electronic transactions and code sets.
Reduce Fraud and Abuse
Encourage secure handling of healthcare information and help reduce the risk of misuse, identity theft, and unauthorized disclosure.
Build Patient Trust
Give patients confidence that their personal and medical information is handled responsibly and protected throughout their healthcare journey.
How HIPAA Works
HIPAA protects patient information throughout its entire lifecycle—from the moment it is collected until it is securely stored, shared, and retained. Every healthcare professional who handles Protected Health Information (PHI) has a responsibility to follow HIPAA guidelines and ensure patient data remains confidential and secure.
Patient Provides Health Information
↓
Patient Registration
↓
PHI Collected & Verified
↓
Information Stored Securely
↓
Authorized Staff Access PHI
↓
Medical Documentation
↓
Medical Coding & Billing
↓
Electronic Claim Submission
↓
Insurance Company Processes Claim
↓
Payment Posted
↓
Medical Records Retained Securely
Who Must Follow HIPAA?
HIPAA applies to organizations and professionals who create, receive, maintain, or transmit Protected Health Information (PHI). Everyone who handles patient information has a responsibility to protect it and maintain confidentiality.
Healthcare Providers
Hospitals, physicians, clinics, laboratories, pharmacies, dentists, and other healthcare professionals who provide patient care.
Health Plans
Health insurance companies, Medicare, Medicaid, employer-sponsored health plans, and other organizations that pay for healthcare services.
Healthcare Clearinghouses
Organizations that process healthcare information by converting claims and other transactions into standardized electronic formats.
Business Associates
Companies or individuals that provide services to healthcare organizations and may access Protected Health Information while performing their work.
Medical Billers
Prepare, submit, and manage insurance claims while ensuring patient information is handled securely.
Medical Coders
Review clinical documentation and assign diagnosis and procedure codes while maintaining the confidentiality of patient records.
Accounts Receivable (AR) Callers
Communicate with insurance companies to resolve unpaid or denied claims while protecting patient information during every interaction.
Insurance Verification Specialists
Verify patient insurance coverage, eligibility, and benefits before treatment while securely handling sensitive patient information.
Essential HIPAA Terms
| Term | Simple Definition |
|---|---|
| HIPAA | A federal law that protects the privacy and security of patient health information. |
| PHI (Protected Health Information) | Any information that can identify a patient and relates to their health, treatment, or payment. |
| ePHI | Protected Health Information that is created, stored, or transmitted electronically. |
| Covered Entity | A healthcare provider, health plan, or healthcare clearinghouse that must comply with HIPAA. |
| Business Associate | A person or organization that performs services for a covered entity and may access PHI. |
| Minimum Necessary Standard | Access or share only the minimum amount of PHI needed to perform a specific job. |
| Authorization | Written permission from a patient allowing the use or disclosure of PHI for specific purposes. |
| Notice of Privacy Practices (NPP) | A document that explains how a patient’s health information may be used and shared, along with their privacy rights. |
| Breach | Unauthorized access, use, or disclosure of Protected Health Information. |
| OCR (Office for Civil Rights) | The U.S. Department of Health and Human Services office responsible for enforcing HIPAA compliance. |
HIPAA Compliance Workflow
Protecting patient information requires secure handling at every stage of the healthcare process. From collecting patient information to storing medical records, HIPAA helps ensure that Protected Health Information (PHI) remains confidential and is accessed only by authorized individuals.

Patient Information Journey
Every patient’s health information follows a secure path throughout the healthcare process. From registration to record retention, HIPAA ensures that Protected Health Information (PHI) is accessed only by authorized individuals and used only for legitimate healthcare purposes.
1. Patient Provides Personal & Health Information
2. Patient Registration
3. Protected Health Information (PHI) Collected
4. Information Stored Securely in the EHR
5. Authorized Healthcare Staff Access PHI
6. Provider Documents the Patient Visit
7. Medical Coding & Billing Process
8. Electronic Claim Submitted to Insurance
9. Insurance Company Processes the Claim
10. Payment Posted
11. Medical Records Retained Securely
HIPAA Do’s & Don’ts
Following HIPAA is part of every healthcare professional’s daily responsibility. Whether you work in patient registration, medical billing, coding, insurance verification, or Accounts Receivable, following these simple practices helps protect patient privacy and maintain compliance.
| ✅ Do | ❌ Don’t |
|---|---|
| Verify a patient’s identity before discussing PHI. | Share patient information with unauthorized individuals. |
| Access only the patient records needed for your job. | Access medical records out of curiosity or without a business need. |
| Lock your computer before leaving your workstation. | Leave your computer unlocked or unattended with PHI visible. |
| Store paper and electronic records securely. | Leave patient documents in public or unsecured areas. |
| Report suspected privacy or security incidents immediately. | Ignore or hide a suspected HIPAA violation. |
| Dispose of documents containing PHI securely. | Throw documents with PHI into regular trash bins. |
Keep Learning
Great job! You now understand the fundamentals of HIPAA and why protecting patient information is essential in the healthcare industry.
In the next module, you’ll learn about the Centers for Medicare & Medicaid Services (CMS)—the federal agency that administers Medicare, oversees parts of Medicaid, and establishes many of the billing, coding, and reimbursement rules used throughout the US healthcare system.
Questions, answered
Have questions about the US healthcare system? Find clear, beginner-friendly answers to some of the most common questions to strengthen your understanding before moving on to the next module.
What is HIPAA?
HIPAA (Health Insurance Portability and Accountability Act) is a federal law that protects the privacy and security of patient health information by establishing standards for how it is collected, used, stored, and shared.
Why is HIPAA important in Medical Billing?
Medical billers work with patient demographics, insurance information, diagnoses, procedures, and payment details. Following HIPAA helps ensure this sensitive information remains private and secure throughout the billing process.
What is Protected Health Information (PHI)?
Protected Health Information (PHI) includes any information that can identify a patient and relates to their health condition, treatment, or payment for healthcare services.
Who must follow HIPAA?
HIPAA applies to healthcare providers, health plans, healthcare clearinghouses, business associates, and healthcare professionals who handle patient information, including medical billers, coders, insurance verification specialists, and AR callers.
What happens if HIPAA is violated?
HIPAA violations can result in disciplinary action, financial penalties, corrective measures, and, in some cases, legal consequences. Healthcare organizations are expected to investigate and address potential violations promptly.
