Topic Deep DiveFR

HIPAA Compliance - Complete Study Guide

Study guide on HIPAA regulations for pharmacy technicians, covering the Privacy Rule, Security Rule, protected health information, patient rights, and violation consequences.

HIPAA Compliance Deep Dive

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a federal law that protects patients' health information. Pharmacy technicians handle protected health information (PHI) daily and must understand HIPAA requirements to maintain compliance and protect patient privacy.

HIPAA Overview

HIPAA has several components, but the most relevant to pharmacy practice are:

  • Title I: Health insurance portability - protects health insurance coverage when individuals change or lose jobs.
  • Title II: Administrative simplification - includes the Privacy Rule, Security Rule, and standardization of electronic transactions. This is the most tested section for pharmacy technicians.

The Privacy Rule

The Privacy Rule establishes standards for the protection of individually identifiable health information (PHI). Key provisions:

What is PHI?

Protected Health Information (PHI) includes any individually identifiable health information that relates to:

  • A patient's past, present, or future physical or mental health condition
  • The provision of healthcare to the patient
  • Payment for healthcare

PHI includes information in any form: verbal, written, or electronic. Examples include:

  • Patient name, address, date of birth, Social Security number
  • Prescription records
  • Insurance information
  • Medical diagnoses
  • Phone numbers, email addresses, medical record numbers

Permitted Uses and Disclosures

PHI may be used or disclosed without patient authorization for:

  • Treatment: Sharing information with other healthcare providers involved in the patient's care.
  • Payment: Submitting claims to insurance companies, collecting payment.
  • Healthcare operations: Quality assurance, auditing, training, accreditation activities.

These three categories are known as TPO (Treatment, Payment, and Operations).

Other permitted disclosures (generally without authorization) include:

  • Required by law (court orders, subpoenas)
  • Public health activities (disease reporting)
  • To prevent or lessen a serious threat to health or safety
  • Workers' compensation cases

Minimum Necessary Standard

When using or disclosing PHI, covered entities must make reasonable efforts to limit PHI to the minimum amount necessary to accomplish the intended purpose. This does not apply to disclosures for treatment purposes (providers need full information to treat patients).

Patient Authorization

A signed patient authorization is required for uses and disclosures not related to TPO, such as:

  • Marketing communications
  • Sale of PHI
  • Sharing information with family members (in most situations, unless the patient is present and does not object)
  • Sharing information with the patient's employer (unless workers' compensation)

Patient Rights Under HIPAA

RightDescription
Right to accessPatients may request access to their PHI and obtain copies of their records.
Right to amendPatients may request corrections to their PHI if they believe it contains errors.
Right to accounting of disclosuresPatients may request a list of disclosures of their PHI (outside of TPO and certain other categories).
Right to restrictPatients may request restrictions on certain uses or disclosures of their PHI, though covered entities are not always required to agree.
Right to confidential communicationsPatients may request to receive communications by alternative means or at alternative locations (e.g., call my cell phone, not my home phone).
Right to a Notice of Privacy PracticesPatients must receive a notice describing how their PHI may be used and their rights.

The Security Rule

The Security Rule applies specifically to electronic PHI (ePHI) and requires covered entities to implement safeguards to protect it:

Administrative Safeguards

  • Designate a security officer responsible for HIPAA compliance.
  • Conduct risk assessments to identify vulnerabilities.
  • Train workforce members on security policies and procedures.
  • Implement sanctions for policy violations.

Physical Safeguards

  • Control physical access to areas where ePHI is stored or accessed.
  • Implement workstation security (position screens away from public view).
  • Establish policies for device and media controls (proper disposal of old computers, drives).

Technical Safeguards

  • Implement access controls (unique user IDs, passwords, automatic logoff).
  • Audit controls to track who accesses ePHI.
  • Integrity controls to ensure ePHI is not improperly altered.
  • Transmission security (encryption for ePHI sent over networks).

HIPAA in Daily Pharmacy Practice

Practical steps pharmacy technicians should follow:

  • Verify patient identity before releasing prescription information or medications.
  • Speak in low tones when discussing PHI at the counter or on the phone.
  • Do not discuss patient information with unauthorized individuals (including coworkers not involved in the patient's care).
  • Position computer screens so patients and the public cannot see PHI.
  • Log out of pharmacy systems when stepping away from the workstation.
  • Dispose of PHI properly - shred paper documents, wipe electronic media.
  • Do not post patient information on social media or share it in text messages.
  • Store printed prescriptions and patient profiles securely.
  • Fax PHI only to verified numbers; use a cover sheet with a confidentiality notice.

Business Associates

A business associate is any entity that performs functions involving PHI on behalf of a covered entity (e.g., PBMs, billing companies, IT vendors, shredding companies). Covered entities must have a Business Associate Agreement (BAA) with each business associate that outlines how PHI will be protected.

Breach Notification Rule

If a breach of unsecured PHI occurs, the covered entity must:

  • Notify affected individuals without unreasonable delay (within 60 days of discovery).
  • Notify the Department of Health and Human Services (HHS).
  • For breaches affecting 500 or more individuals, notify prominent media outlets.

Violations and Penalties

HIPAA violations can result in civil and criminal penalties. Penalties are tiered based on the level of negligence. Criminal penalties can include fines and imprisonment for willful violations. The Office for Civil Rights (OCR) within HHS enforces HIPAA.

Exam Tips

  • Know what PHI is and the examples that constitute it.
  • TPO (Treatment, Payment, Operations) = uses that do NOT require patient authorization.
  • The minimum necessary standard applies to payment and operations but not to treatment disclosures.
  • Know the six patient rights under HIPAA.
  • Understand the difference between the Privacy Rule (all PHI) and the Security Rule (ePHI specifically).
  • A pharmacy technician who shares PHI on social media violates HIPAA - this is a commonly tested scenario.

Ready to put this into practice?

CPHTprep has 200 flashcards, 10 mini exams, and 7 full-length simulations covering FR.