Skip to Page Content
Home  |  Contact Us  |  Press Room  |  Site Overview  |  Help  |  Login  |  Register
Add to MyNCSL

HIPAA: Impacts and Actions by States
Medical record privacy, security and electronic transactions.
 

Updated: March 18, 2008

The Health Insurance Portability and Accountability Act of 1996, known as HIPAA, continues to have a broad impact on state health policy, as well as on virtually all health providers, insurers and health consumers. Listed below are brief updates and resources of potential interest to state legislatures.

Electronic Transactions Requirements:

Federal regulations required compliance with new HIPAA national standards for electronic health care transactions, code sets and national identifiers for providers, health plans, and employers, as of an October 2003 deadline.  The federal Administrative Simplification Compliance Act (ASCA) required all claims sent to the Medicare Program be submitted electronically starting October 2003.  (This is separate from medical privacy requirements, below.)

HIPAA Logo

Health Insurance Portability and Accountability Act of 1996 (HIPAA)

HIPAA-covered entities such as providers completing electronic transactions, healthcare clearinghouses and large health plans must use only the National Provider Identifier (NPI) to identify covered healthcare providers in standard transactions by May 23, 2007. All such organizations need to ensure they are prepared for the (NPI) May 2007 deadline.  Details and strategies: NPI: Strategies for an Implementation Process To Meet the May 2007 Deadline. (12/06).

 NOTE: NCSL provides links to other Web sites from time to time for information purposes only. Providing these links does not necessarily indicate NCSL's support or endorsement of the site.

Health Information Technology

NCSL’s Project HITCh—for Health Information Technology Champions—supports state legislative decision-making about HIT. For details about what states are doing, go to www.ncsl.org/programs/health/forum/hitch/.  Also, a 2007 NCSL report describes and provides links to specific state legislation on HIT and public reporting: www.ncsl.org/programs/health/Transparency.htm.

Medical Record Privacy:

As of April 14, 2003 "health plans, hospitals, doctors and other health care providers around the country must comply with new federal privacy regulations," according to Secretary Tommy Thompson of the Department of Health and Human Services (HHS). Billions of dollars are being spent to bring public and private sector records into compliance. The following is the department's description, stated in April, 2003:
"These new federal health privacy regulations set a national floor of privacy protections that will reassure patients that their medical records are kept confidential. The rules will help to ensure appropriate privacy safeguards are in place as we harness information technologies to improve the quality of care provided to patients. Consumers will benefit from these new limits on the way their personal medical records may be used or disclosed by those entrusted with this sensitive information.

The new protections give patients greater access to their own medical records and more control over how their personal information is used by their health plans and health care providers. Consumers will get a notice explaining how their health plans, doctors, pharmacies and other health care providers use, disclose and protect their personal information. In addition, consumers will have the ability to see and copy their health records and to request corrections of any errors included in their records. Consumers may file complaints about privacy issues with their health plans or providers or with our Office for Civil Rights."


PRIVACY ON-LINE RESOURCES:

HIPAA State Actions: Overviews and Examples:

HIPAA Administrative Simplification

HHS Summary of HIPAA Administrative Simplification- links to the federal website featuring legal requirements, implementation and enforcement for 2004.

HIPAA Wellness and Nondiscrimination

DOL ISSUES CHECKLIST FOR WELLNESS PROGRAMS.  Wellness programs must be carefully reviewed to assure that they fit within a variety of legal boundaries. Most important for 2008 and beyond are the nondiscrimination rules under HIPAA. The Department of Labor (DOL) has issued helpful guidance in Field Assistance Bulletin 2008-02 (FAB 2008-02), including a useful checklist. This guidance can be reviewed by any policymaker or plan sponsor implementing a wellness program or considering one. ["CheckUp" by Sibson, 3/10/08)New item

HIPAA Security Rules for 2005

In a separate process, HHS also has issued a Final Security Rule requiring health plans, certain health care providers and health information clearinghouses to establish "adequate administrative, physical, and technical safeguards to prevent unauthorized access to electronic patient health information."  Most covered entities will have until April 21, 2005 to comply with the new security standards.

 --------------

NOTE: NCSL provides links to other Web sites from time to time for information purposes only. Providing these links does not necessarily indicate NCSL's support or endorsement of the site.

Return to  Health Finance  ||  Health Insurance and Managed Care Overviw  ||  Health Topics, A to Z

Denver Office: Tel: 303-364-7700 | Fax: 303-364-7800 | 7700 East First Place | Denver, CO 80230 | Map
Washington Office: Tel: 202-624-5400 | Fax: 202-737-1069 | 444 North Capitol Street, N.W., Suite 515 | Washington, D.C. 20001