What Does HIPAA Mean for Your Privacy?

Just like your financial and personal information, keeping your medical information private is vital. And in today's online world, that can be a challenge.

Get peace of mind with a comprehensive estate plan

Trustpilot star rating bar
Woman reviewing papers at a desk with a laptop

Contents

Updated on: October 25, 2021
Read time: 4 min

Protecting your sensitive medical information is important. While it can be beneficial for your various medical care providers to quickly share your records over the internet, your medical information can also be used for marketing purposes and—just like information you might carelessly post on social media—it might even be accessed by hackers.

To provide some privacy protection for medical information, Congress passed HIPAA, which stands for the Health Insurance Portability and Accountability Act. But while HIPAA provides some privacy protection, it also has its limits.

mom taking son to the doctor

What Is HIPAA and What Is Its Purpose?

HIPAA is a federal law designed to protect a patient's sensitive information from being released without their consent.

So, what does HIPPA mean for your privacy? The short answer is that HIPAA helps protect your privacy, but it probably does not provide as much protection as you might think or as much as you would like.

To understand what HIPAA actually does, it's important to know what its two primary purposes are:

  1. To make it easier for people to obtain and maintain medical insurance, which includes being able to change health insurance plans as your employment situation changes. This is the "portability" part of the Act.
  2. To protect the privacy of patient information. This is the "accountability" part of the Act.

HIPAA Privacy Rules

HIPAA actually consists of two parts: the Act as enacted by Congress and numerous rules created by the U.S. Department of Health and Human Services (HHS) to implement the Act. Two of these rules that set forth privacy requirements are:

  • Standards for Privacy of Individually Identifiable Health Information. Known as the "Privacy Rule," it covers what is called "protected health information" (or PHI).
  • Security Standards for the Protection of Electronic Protected Health Information. Known as the "Security Rule," it has additional requirements for safeguarding PHI that is created, received, stored, or transmitted electronically.

Information that is considered PHI includes:

  • Hospital and physician records regarding your medical conditions and treatments.
  • Prescriptions.
  • Lab test results.
  • Billings and insurance claims.
  • Appointment histories.
  • Financial and personal information, such as your name, date of birth, age, address, phone number, email address, Social Security number, and insurance information.

HIPAA Covered Entities

HIPAA does not apply to everyone. It only applies to what the Act calls a "covered entity," which basically includes:

  • Health care providers.
  • Health plans. This includes Medicare and Medicaid.
  • Business associates of health care providers and plans. These provide billing, claims processing, or other services.

This leaves out many others who may obtain medical information about you and your family. Some examples of organizations that are not covered by HIPAA are life insurance companies, employers, school districts, law enforcement agencies, and many state and municipal agencies. Therefore, the medical information you disclose in your life insurance application, or medical information you give to your child's school, is not protected under HIPAA.

If you let your friend know that you have a particular medical condition, and that friend passes that information to someone else, there is no HIPAA violation because HIPAA does not apply to your friend.

Personal Health Information Disclosures

HIPAA rules set forth circumstances under which PHI can be disclosed by a covered entity. This can be broken down into two categories: disclosures that require your written permission and disclosures that can be made without your permission.

Disclosures Requiring Permission

Generally, patient permission for disclosure of PHI is required, unless the HIPAA Privacy Rule specifically permits disclosure without permission. This includes information:

  • To be used for marketing purposes.
  • Being disclosed in return for financial compensation.
  • Regarding psychotherapy and substance abuse treatment.
  • To be included in a hospital patient directory.
  • Disclosed to a friend or family member with authorization granted by a health care power of attorney or a HIPAA authorization form. This is often done as part of a comprehensive estate plan.

Disclosures Without Permission

Information may be disclosed without your permission if it's necessary for medical treatment, billing, and payment processing.

There are also some rather broad and generally-worded exceptions to the Privacy Rule, which allow government access, such as:

  • When required by law.
  • Public health activities, such as reporting disease outbreaks.
  • Judicial and administrative proceedings, such as court orders and subpoenas.
  • Law enforcement.
  • To prevent or lessen a serious threat to health or safety.
  • Essential government functions.

HIPAA Violations

If a covered entity violates HIPAA rules, it can incur civil fines and criminal penalties. Complaints regarding HIPAA violations are handled by the HHS Office for Civil Rights (OCR).

However, there has been criticism of OCR and the U.S. Department of Justice for failing to aggressively pursue violators.

How You Can Help Protect Your Privacy

Health care providers, medical insurers, and other covered entities typically make efforts to assure they are in compliance with HIPAA privacy rules. This includes training their employees on the rules. However, there are a few things you can do to enhance the privacy, and accuracy, of your medical information:

  • You have the right under HIPAA to see and obtain copies of your medical records. If you find inaccurate information, you have the right to have corrections added to your records.
  • Read privacy notices. These tell you how the covered entity will use and share your information. They will state when information may be disclosed without your permission and what your rights are to limit this sharing of information. Often, they also give you choices to limit or eliminate some of this sharing.
  • Opt out of fundraising and marketing communications.

It's important to understand the basic purpose of HIPAA, its privacy rules, and the limitations of those privacy rules. The HHS website can provide more information about your rights under HIPAA, as can the CDC website.

Get peace of mind with a comprehensive estate planStart my estate plan
Twitter logoFacebook logoLinkedIn logoReddit logo

This article is for informational purposes. This content is not legal advice, it is the expression of the author and has not been evaluated by LegalZoom for accuracy or changes in the law.

70 days ago
Trustpilot star rating bar

legal zoom is the way to go

The representative was very knowledgeable about how long it takes to transfer a deed from one person to the next he explained everything and he was very pleasant when speaking to him

Ross
70 days ago
Trustpilot star rating bar

I find that LegalZoom has all the…

I find that LegalZoom has all the answers if you're starting a business an LLC and incorporation or you're doing a trust or a Will. These are the people you want to trust don't go to an expensive attorney you're just throwing your money away. Legal soon gets five stars!

Sean Christopher
70 days ago
Trustpilot star rating bar

I spoke to the representative today about a Trust...

I spoke to the representative today regarding a question about an existing Living Trust. She was very helpful - told me exactly what I needed to know and how to accomplish it. As a representative in the Financial field I guide clients all the time on where to get documents done right - and its always LegalZoom - easy and effecient!

Gareth
79 days ago
Trustpilot star rating bar

We could not be more Pleased with the…

We could not be more Pleased with the help and service we had during the up dating of our Living Will and Advanced Directive

Richard Poulton
82 days ago
Trustpilot star rating bar

Legal Assistance for the rest of us

Legal Zoom has made it easy and affordable for us to create an LLC, a Will, and a Trust for our families.

K Chapman
85 days ago
Trustpilot star rating bar

pleasant and willing representatives…

pleasant and willing representatives ready to help me navigate through your system and supply attorney contact information for my legal questions for my last will & testament

Mark Impink
85 days ago
Trustpilot star rating bar

LegalZoom .com has exceptional, real, staff to help. I met one!

I purchased multiple accounts to update both our Living Wills and Estate Plans. After utilizing LegalZoom.com’s user-friendly and intuitive platform for these legal documents, I found it necessary to call for clarification on some information within our account. I spoke with Sandra Balderas, who expertly addressed the mistakes I had inadvertently made. Her professionalism and friendliness greatly enhanced the experience. I realized that LegalZoom is not only a straightforward website to navigate for such complex matters, but it also boasts exceptional employees. Thank you, LegalZoom.com, and especially Sandra Balderas, for guiding me through the process. I’m thrilled to have discovered LegalZoom.com.

Max -Phoenix, Arizona
85 days ago
Trustpilot star rating bar

Sarah was most helpful today regarding updating my estate plan

Sarah was most helpful today regarding updating my LZ docs created 3 years ago. She made sure I had all the information I needed, not just what I asked for. Thank you Sarah!

Diane Floyd
91 days ago
Trustpilot star rating bar

Quick and easy experience creating a…

Quick and easy experience creating a will package.

Kristin Steel
96 days ago
Trustpilot star rating bar

Used them past 10 years

Used them past 10 years. I needed another will and power of attorney.

MERLYN C
96 days ago
Trustpilot star rating bar

Tammy was wonderful and very…

Tammy was wonderful and very knowledgeable. It's because of her that I am going to open a living trust with legal zoom. She was great. Thank You

Erin
104 days ago
Trustpilot star rating bar

Pleasant Experience

Patience and weel given explanation about the process of how a "Living Trust" & "Deed" works after transitioning and guidance on how to contact an attorney whenever I need legal advice.

Sharron Martin
106 days ago
Trustpilot star rating bar

It was a breeze to deal with Legalzoom…

It was a breeze to deal with Legalzoom and finished my estate plan within an hour!! Thanks again

BT
110 days ago
Trustpilot star rating bar

Great team…

Mark and Legal Zoom make estate planning affordable and attainable.

Christopher Maginnis
142 days ago
Trustpilot star rating bar

Living Will & Forming my LLC

I have used Lega Zoom for several items, including my living will and items to form my LLC for my business. It's fast, easy, and thorough. The customer service is fantastic! I am working with David on a few items for my will,l and he has been a delight. He follows up when he says he will and is incredibly helpful. I highly recommend this company.

Kristen J
154 days ago
Trustpilot star rating bar

Nadia made it very easy for me to make…

Nadia made it very easy for me to make a decision to sign up and create my estate planning documents with legalsoom. She was very professional and knowledgeable about the package that I chose. She also offered her direct contact for any future questions I might have.

Melita D'Anna
163 days ago
Trustpilot star rating bar

Kylie helped me to review my history of…

Kylie helped me to review my history of trying to complete my estate plan and contacting a legal advisor that comes with my account. She was patient, knowledgable, and helpful.

Paula
167 days ago
Trustpilot star rating bar

I have worked with Mark Champ on… Last Will & Testament, Living Will, Quit Claim Deed

I have worked with Mark Champ on several documents I needed and every time he has provided me with every thing I needed and with so much graciousness and knowledge. It has always been such a pleasure working with Mark!!!!!!!!!!!!!

Cathy Donaldson
202 days ago
Trustpilot star rating bar

Most Dedicated Representative!

Patti Green was the most informative person in guiding me through the process of completing my estate plan . She was always there for me to answer my questions and give excellent advice . Also , she was very polite and considerate ! Legal Zoom is so fortunate to have Patti on their team . Thank you , Patti for all of your assistance and kindness !

Priscilla Page
280 days ago
Trustpilot star rating bar

Patti Green is GREAT!

Ms. Patti Green walked me through the Estate Planning process. She was very professional, patient and kind. Planning for when you are no longer here is very intricate and difficult. Working with Ms. Green helped give the assurance that I am doing the right thing for myself and loved ones.

TRINESSA
Rated4.6out of 5 based on23,929+ reviewson

Showing our favorite reviews