HIPAA cheatsheet
HIPAA Privacy and Security high-yield drill
The rule
Use or disclose the minimum PHI the job needs, on an approved channel, with a documented permission.
Next step
If the permission or the identity is missing, stop and route. Do not send the chart to be helpful.
Never miss
- PHI is identifiable health information held by a covered entity or business associate.
- Minimum necessary still applies to payment and operations.
- The Security Rule is about ePHI: administrative, physical, and technical safeguards.
- Unsecured PHI has a breach presumption unless a documented assessment shows low probability of compromise.
- Treatment, payment, and operations do not need an authorization. Most extra disclosures do.
- A business associate agreement must exist before a vendor handles PHI.
Traps
- Curiosity looks in a celebrity or neighbor chart.
- Shared logins and unlocked cafe sessions.
- A later authorization used to erase an earlier disclosure.
- Reading a full lab report onto a voicemail the patient did not request.
Shortcuts
- Ask: who, what, why, which channel, and is there a permission.
- Two identifiers before you open the record.
- Incident: stop, document, follow the sanction path.
Terms
- PHI. Individually identifiable health information held or transmitted by a covered entity or business associate.
- Minimum necessary. Limit uses and disclosures to what the job needs.
- ePHI. Electronic PHI. The Security Rule's scope.
- Designated record set. Medical and billing records used to make decisions about the individual. The unit of the right of access.
- TPO. Treatment, payment, and health-care operations. Usually no authorization.
- Business associate. A person or entity that handles PHI for a covered function and is not workforce.
- Breach presumption. An impermissible use or disclosure of unsecured PHI is a breach unless the four-factor assessment shows low probability of compromise.
- Right of access. The individual may obtain PHI in the designated record set, with limited exceptions.
Memory hooks
- APT. Administrative, Physical, Technical The three Security Rule safeguard groups.
- WHO-WHAT-WHY. Who is asking, what they want, why they may have it A 10-second Privacy Rule screen before any send.