HIPAA Compliance Deep Dive
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a federal law that protects patients' health information. Pharmacy technicians handle protected health information (PHI) daily and must understand HIPAA requirements to maintain compliance and protect patient privacy.
HIPAA Overview
HIPAA has several components, but the most relevant to pharmacy practice are:
- Title I: Health insurance portability - protects health insurance coverage when individuals change or lose jobs.
- Title II: Administrative simplification - includes the Privacy Rule, Security Rule, and standardization of electronic transactions. This is the most tested section for pharmacy technicians.
The Privacy Rule
The Privacy Rule establishes standards for the protection of individually identifiable health information (PHI). Key provisions:
What is PHI?
Protected Health Information (PHI) includes any individually identifiable health information that relates to:
- A patient's past, present, or future physical or mental health condition
- The provision of healthcare to the patient
- Payment for healthcare
PHI includes information in any form: verbal, written, or electronic. Examples include:
- Patient name, address, date of birth, Social Security number
- Prescription records
- Insurance information
- Medical diagnoses
- Phone numbers, email addresses, medical record numbers
Permitted Uses and Disclosures
PHI may be used or disclosed without patient authorization for:
- Treatment: Sharing information with other healthcare providers involved in the patient's care.
- Payment: Submitting claims to insurance companies, collecting payment.
- Healthcare operations: Quality assurance, auditing, training, accreditation activities.
These three categories are known as TPO (Treatment, Payment, and Operations).
Other permitted disclosures (generally without authorization) include:
- Required by law (court orders, subpoenas)
- Public health activities (disease reporting)
- To prevent or lessen a serious threat to health or safety
- Workers' compensation cases
Minimum Necessary Standard
When using or disclosing PHI, covered entities must make reasonable efforts to limit PHI to the minimum amount necessary to accomplish the intended purpose. This does not apply to disclosures for treatment purposes (providers need full information to treat patients).
Patient Authorization
A signed patient authorization is required for uses and disclosures not related to TPO, such as:
- Marketing communications
- Sale of PHI
- Sharing information with family members (in most situations, unless the patient is present and does not object)
- Sharing information with the patient's employer (unless workers' compensation)
Patient Rights Under HIPAA
| Right | Description |
|---|---|
| Right to access | Patients may request access to their PHI and obtain copies of their records. |
| Right to amend | Patients may request corrections to their PHI if they believe it contains errors. |
| Right to accounting of disclosures | Patients may request a list of disclosures of their PHI (outside of TPO and certain other categories). |
| Right to restrict | Patients may request restrictions on certain uses or disclosures of their PHI, though covered entities are not always required to agree. |
| Right to confidential communications | Patients may request to receive communications by alternative means or at alternative locations (e.g., call my cell phone, not my home phone). |
| Right to a Notice of Privacy Practices | Patients must receive a notice describing how their PHI may be used and their rights. |
The Security Rule
The Security Rule applies specifically to electronic PHI (ePHI) and requires covered entities to implement safeguards to protect it:
Administrative Safeguards
- Designate a security officer responsible for HIPAA compliance.
- Conduct risk assessments to identify vulnerabilities.
- Train workforce members on security policies and procedures.
- Implement sanctions for policy violations.
Physical Safeguards
- Control physical access to areas where ePHI is stored or accessed.
- Implement workstation security (position screens away from public view).
- Establish policies for device and media controls (proper disposal of old computers, drives).
Technical Safeguards
- Implement access controls (unique user IDs, passwords, automatic logoff).
- Audit controls to track who accesses ePHI.
- Integrity controls to ensure ePHI is not improperly altered.
- Transmission security (encryption for ePHI sent over networks).
HIPAA in Daily Pharmacy Practice
Practical steps pharmacy technicians should follow:
- Verify patient identity before releasing prescription information or medications.
- Speak in low tones when discussing PHI at the counter or on the phone.
- Do not discuss patient information with unauthorized individuals (including coworkers not involved in the patient's care).
- Position computer screens so patients and the public cannot see PHI.
- Log out of pharmacy systems when stepping away from the workstation.
- Dispose of PHI properly - shred paper documents, wipe electronic media.
- Do not post patient information on social media or share it in text messages.
- Store printed prescriptions and patient profiles securely.
- Fax PHI only to verified numbers; use a cover sheet with a confidentiality notice.
Business Associates
A business associate is any entity that performs functions involving PHI on behalf of a covered entity (e.g., PBMs, billing companies, IT vendors, shredding companies). Covered entities must have a Business Associate Agreement (BAA) with each business associate that outlines how PHI will be protected.
Breach Notification Rule
If a breach of unsecured PHI occurs, the covered entity must:
- Notify affected individuals without unreasonable delay (within 60 days of discovery).
- Notify the Department of Health and Human Services (HHS).
- For breaches affecting 500 or more individuals, notify prominent media outlets.
Violations and Penalties
HIPAA violations can result in civil and criminal penalties. Penalties are tiered based on the level of negligence. Criminal penalties can include fines and imprisonment for willful violations. The Office for Civil Rights (OCR) within HHS enforces HIPAA.
Exam Tips
- Know what PHI is and the examples that constitute it.
- TPO (Treatment, Payment, Operations) = uses that do NOT require patient authorization.
- The minimum necessary standard applies to payment and operations but not to treatment disclosures.
- Know the six patient rights under HIPAA.
- Understand the difference between the Privacy Rule (all PHI) and the Security Rule (ePHI specifically).
- A pharmacy technician who shares PHI on social media violates HIPAA - this is a commonly tested scenario.