Skip to content

HIPAA Basics


What Is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects the privacy and security of patient health information. It sets standards for how healthcare organizations collect, use, store, and share Protected Health Information (PHI). By following HIPAA, healthcare professionals help protect patient data, maintain compliance, and build trust between patients and providers..

Protects patient health information

Establishes privacy and security standards

Applies to healthcare organizations and business associates

Helps prevent unauthorized access to patient data

Supports secure healthcare communication

Promotes patient trust and regulatory compliance


Goals of HIPAA

HIPAA was created to protect patient information while supporting secure and efficient healthcare operations. Its rules help healthcare organizations safeguard sensitive data, maintain compliance, and build confidence between patients and providers.

Protect Patient Privacy

Ensure that patient health information is accessed and shared only by authorized individuals for approved healthcare purposes.

Secure Health Information

Protect paper records, electronic records, and other forms of patient information from unauthorized access, loss, or misuse.

Standardize Healthcare Transactions

Support the secure exchange of healthcare information by using standardized electronic transactions and code sets.

Reduce Fraud and Abuse

Encourage secure handling of healthcare information and help reduce the risk of misuse, identity theft, and unauthorized disclosure.

Build Patient Trust

Give patients confidence that their personal and medical information is handled responsibly and protected throughout their healthcare journey.

How HIPAA Works

HIPAA protects patient information throughout its entire lifecycle—from the moment it is collected until it is securely stored, shared, and retained. Every healthcare professional who handles Protected Health Information (PHI) has a responsibility to follow HIPAA guidelines and ensure patient data remains confidential and secure.

Patient Provides Health Information

Patient Registration

PHI Collected & Verified

Information Stored Securely

Authorized Staff Access PHI

Medical Documentation

Medical Coding & Billing

Electronic Claim Submission

Insurance Company Processes Claim

Payment Posted

Medical Records Retained Securely

Who Must Follow HIPAA?

HIPAA applies to organizations and professionals who create, receive, maintain, or transmit Protected Health Information (PHI). Everyone who handles patient information has a responsibility to protect it and maintain confidentiality.

Healthcare Providers

Hospitals, physicians, clinics, laboratories, pharmacies, dentists, and other healthcare professionals who provide patient care.

Health Plans

Health insurance companies, Medicare, Medicaid, employer-sponsored health plans, and other organizations that pay for healthcare services.

Healthcare Clearinghouses

Organizations that process healthcare information by converting claims and other transactions into standardized electronic formats.

Business Associates

Companies or individuals that provide services to healthcare organizations and may access Protected Health Information while performing their work.

Medical Billers

Prepare, submit, and manage insurance claims while ensuring patient information is handled securely.

Medical Coders

Review clinical documentation and assign diagnosis and procedure codes while maintaining the confidentiality of patient records.

Accounts Receivable (AR) Callers

Communicate with insurance companies to resolve unpaid or denied claims while protecting patient information during every interaction.

Insurance Verification Specialists

Verify patient insurance coverage, eligibility, and benefits before treatment while securely handling sensitive patient information.

Essential HIPAA Terms

TermSimple Definition
HIPAAA federal law that protects the privacy and security of patient health information.
PHI (Protected Health Information)Any information that can identify a patient and relates to their health, treatment, or payment.
ePHIProtected Health Information that is created, stored, or transmitted electronically.
Covered EntityA healthcare provider, health plan, or healthcare clearinghouse that must comply with HIPAA.
Business AssociateA person or organization that performs services for a covered entity and may access PHI.
Minimum Necessary StandardAccess or share only the minimum amount of PHI needed to perform a specific job.
AuthorizationWritten permission from a patient allowing the use or disclosure of PHI for specific purposes.
Notice of Privacy Practices (NPP)A document that explains how a patient’s health information may be used and shared, along with their privacy rights.
BreachUnauthorized access, use, or disclosure of Protected Health Information.
OCR (Office for Civil Rights)The U.S. Department of Health and Human Services office responsible for enforcing HIPAA compliance.

HIPAA Compliance Workflow

Protecting patient information requires secure handling at every stage of the healthcare process. From collecting patient information to storing medical records, HIPAA helps ensure that Protected Health Information (PHI) remains confidential and is accessed only by authorized individuals.

Patient Information Journey

Every patient’s health information follows a secure path throughout the healthcare process. From registration to record retention, HIPAA ensures that Protected Health Information (PHI) is accessed only by authorized individuals and used only for legitimate healthcare purposes.

1. Patient Provides Personal & Health Information

2. Patient Registration

3. Protected Health Information (PHI) Collected

4. Information Stored Securely in the EHR

5. Authorized Healthcare Staff Access PHI

6. Provider Documents the Patient Visit

7. Medical Coding & Billing Process

8. Electronic Claim Submitted to Insurance

9. Insurance Company Processes the Claim

10. Payment Posted

11. Medical Records Retained Securely

HIPAA Do’s & Don’ts

Following HIPAA is part of every healthcare professional’s daily responsibility. Whether you work in patient registration, medical billing, coding, insurance verification, or Accounts Receivable, following these simple practices helps protect patient privacy and maintain compliance.

DoDon’t
Verify a patient’s identity before discussing PHI.Share patient information with unauthorized individuals.
Access only the patient records needed for your job.Access medical records out of curiosity or without a business need.
Lock your computer before leaving your workstation.Leave your computer unlocked or unattended with PHI visible.
Store paper and electronic records securely.Leave patient documents in public or unsecured areas.
Report suspected privacy or security incidents immediately.Ignore or hide a suspected HIPAA violation.
Dispose of documents containing PHI securely.Throw documents with PHI into regular trash bins.


Keep Learning

Great job! You now understand the fundamentals of HIPAA and why protecting patient information is essential in the healthcare industry.

In the next module, you’ll learn about the Centers for Medicare & Medicaid Services (CMS)—the federal agency that administers Medicare, oversees parts of Medicaid, and establishes many of the billing, coding, and reimbursement rules used throughout the US healthcare system.



FAQ

Questions, answered

Have questions about the US healthcare system? Find clear, beginner-friendly answers to some of the most common questions to strengthen your understanding before moving on to the next module.

What is HIPAA?

HIPAA (Health Insurance Portability and Accountability Act) is a federal law that protects the privacy and security of patient health information by establishing standards for how it is collected, used, stored, and shared.

Why is HIPAA important in Medical Billing?

Medical billers work with patient demographics, insurance information, diagnoses, procedures, and payment details. Following HIPAA helps ensure this sensitive information remains private and secure throughout the billing process.

What is Protected Health Information (PHI)?

Protected Health Information (PHI) includes any information that can identify a patient and relates to their health condition, treatment, or payment for healthcare services.

Who must follow HIPAA?

HIPAA applies to healthcare providers, health plans, healthcare clearinghouses, business associates, and healthcare professionals who handle patient information, including medical billers, coders, insurance verification specialists, and AR callers.

What happens if HIPAA is violated?

HIPAA violations can result in disciplinary action, financial penalties, corrective measures, and, in some cases, legal consequences. Healthcare organizations are expected to investigate and address potential violations promptly.