Free guidee-book

HIPAA Compliance: An Introduction

A free LabLynx e-book on HIPAA compliance for healthcare and lab staff, from covered entities and protected health information to the Privacy and Security Rules.

HIPAA Compliance: An Introduction, a free guide from LabLynx

Get your free copy

  • e-book
  • Instant download

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

We also email you the link.

HIPAA compliance is how healthcare providers, health plans, clearinghouses and their business associates meet the Health Insurance Portability and Accountability Act of 1996: protecting patients' health information, respecting their rights over it and training every workforce member to handle it. This LabLynx guide is a training introduction to the Privacy Rule, the Security Rule, protected health information and who must comply.

What you will learn

  • What HIPAA covers. The Privacy Rule, the Security Rule, and who oversees them.
  • Whether it applies to you. Covered entities, business associates and when an agreement between them is required.
  • What counts as PHI. The 18 identifiers, and the two approved ways to de-identify patient data.
  • When PHI may be shared. Permitted uses and disclosures, authorizations, the minimum necessary standard and patients' rights.
  • How to protect it. Administrative, physical and technical safeguards, safe disposal and workforce training.

What is inside the guide

From why training matters to how to dispose of PHI safely: here is what the guide covers, section by section.

  • Why HIPAA training matters

    HIPAA itself requires covered entities to train every workforce member, from employees to volunteers and trainees, on their privacy policies and procedures. The guide was written because too many HIPAA courses fall short in scope, clarity and accuracy, and it draws almost entirely on first-hand material from HHS and the law itself.

  • What HIPAA is

    Where CLIA sets standards for clinical testing, HIPAA protects patients' personal information, and it applies to almost any entity that handles it. The guide explains its two main areas, the Privacy Rule and the Security Rule, and the oversight role of HHS and its Office for Civil Rights.

    Go deeper: HIPAA compliance in the laboratory

  • Who needs to comply

    Covered entities are health plans, healthcare clearinghouses and any provider that transmits health information electronically in a standard transaction, such as a claim. Business associates that handle PHI on their behalf are covered too, and the guide sets out what a business associate agreement must contain and when none is needed, as when a hospital lab sends PHI to a reference lab for a patient's treatment.

  • Protected health information

    PHI is individually identifiable health information held or transmitted by a covered entity or business associate, whether electronic, paper or oral. The guide lists the 18 identifiers that make data PHI and the two approved ways to de-identify it: the Safe Harbor method and a qualified expert's statistical determination.

    Go deeper: Laboratory data privacy

  • Use and disclosure

    When PHI may be used or disclosed without a patient's authorization, from treatment, payment and healthcare operations to 12 national priority purposes, and when written authorization is required. The guide covers the minimum necessary standard, role-based access, patients' rights to notice, access, amendment and an accounting of disclosures, and who can act as a patient's personal representative.

    Go deeper: Need-to-know access in the lab

  • Administration

    The guide lists what a covered entity must have in place: written privacy policies, a privacy official, workforce training and sanctions, mitigation, data safeguards, a complaints process and documentation. It also explains organizational options such as hybrid and affiliated entities, and the standards for electronic transactions, code sets and identifiers.

  • Security

    The Security Rule protects electronic PHI and asks covered entities to keep it confidential, intact and available. It does not dictate specific measures, so the guide explains risk analysis, the administrative, physical and technical safeguards, and why an "addressable" specification is not optional.

    Go deeper: Lab cybersecurity

  • Additional compliance guidance

    How to dispose of PHI safely, from shredding and pulping paper records to clearing, purging or destroying electronic media, and why everyone who handles disposal needs training on it. The guide ends with an overview of enforcement and penalties as they stood when it was compiled in 2022.

Get the free guide

Key takeaways

  • HIPAA has two main parts. The Privacy Rule covers patients' rights over their health information and what covered entities must do to support them; the Security Rule covers the administrative, physical and technical protection of that data.
  • It reaches beyond healthcare providers. Health plans and clearinghouses are covered entities too, and since the HITECH Act their business associates, and those associates' subcontractors, are subject to HIPAA as well.
  • PHI is defined by whether it can identify a patient. The guide lists 18 identifiers, from names and dates to IP addresses and photographs, and two approved ways to de-identify data.
  • Share the minimum necessary. Outside treatment and a few other exceptions, use, disclose and request only the PHI a purpose needs, and limit staff access to PHI by role.
  • Training is part of the law. Every workforce member, including volunteers and trainees, must be trained on privacy policies as their job requires, and sanctions applied when they are broken.

Administrative requirements and recommendations

Policies and a privacy official

Written privacy policies and procedures consistent with the Privacy Rule, an official responsible for them, and a contact for complaints and questions.

Workforce training and sanctions

Train every workforce member as their role requires, and apply sanctions to those who violate the policies or the Privacy Rule.

Data safeguards

Administrative, technical and physical measures, such as shredding documents that hold PHI and locking medical records away.

Mitigation and complaints

Lessen any harm from a use or disclosure that breaks the rules, give individuals a way to complain, and never retaliate against them.

Documentation

Keep the privacy policies, notices, complaint records and other documentation the Privacy Rule requires, which the guide says must be kept for six years after they were created or last in effect.

HIPAA Compliance: An Introduction, a free guide from LabLynx

This page is the summary. The full guide has the detail.

e-book. Free.

Who it is for

Lab and healthcare staff

who handle patient information every day and need an accurate, plain grounding in what HIPAA asks of them.

Privacy and security officials

who write their organization's policies and procedures and want the rules summarized from HHS's own material.

Managers who run HIPAA training

who must train every workforce member, from employees to volunteers, and want a course that is thorough and clear.

Written for Clinical, hospital and reference laboratories, alongside hospitals, clinics, physician and dental practices, nursing homes and pharmacies.

About the author

Marketing & Operations Digital Solutions Architect

Brandon Holland is the Marketing & Operations Digital Solutions Architect at LabLynx, where he writes guides and articles for lab professionals. This guide is published by LabLynx Press under a CC BY-SA 4.0 license, from LIMSwiki articles by Alan Vaughan, edited by Shawn Douglas.

LabLynx has built laboratory information management software for more than 25 years.

Put it into practiceGet started with LabLynxThe guide asks every covered entity to review its safeguards as risks change. When your lab reviews how it protects patient information and controls who can see it, talk to LabLynx about how you handle that information today. Ask for personalized information, a demo or pricing.Talk to a LabLynx specialist

About the guide

Answers from the guide, in brief.

Get the free guide
Who does the guide say has to comply with HIPAA?
Covered entities: health plans, healthcare clearinghouses and any healthcare provider, whatever its size, that transmits health information electronically in connection with a standard transaction such as a claim or an eligibility inquiry. Using email alone does not make a provider a covered entity. Since the HITECH Act, business associates that use or receive identifiable health information on a covered entity's behalf, and their subcontractors, are subject to HIPAA as well.
What does the guide count as protected health information?
Individually identifiable health information that a covered entity or business associate holds or transmits, whether electronic, paper or oral. It relates to a person's past, present or future health, the care they receive or payment for that care, and identifies them or reasonably could. The guide lists 18 identifiers, from names, dates and medical record numbers to IP addresses and full-face photographs. Records an organization keeps as an employer are not PHI.
How does the guide explain de-identifying patient data?
HIPAA allows two approved methods. Under Safe Harbor, a covered entity removes all 18 types of identifier and has no actual knowledge that what remains could identify the person. Under the statistical approach, a qualified expert uses accepted analytic techniques to conclude that the risk of identification is very small. Any code that replaces identifiers must not be derived from the person's information, so a patient's initials cannot be used.
How does the guide explain the minimum necessary standard?
Use, disclose and request only the smallest amount of PHI needed for the purpose, with policies that keep routine disclosures to that minimum and a case-by-case review of the rest. A covered entity may not use a whole medical record unless it can justify the whole record. Exceptions include disclosures to a provider for treatment, to the patient, under an authorization, to HHS, and where the law requires them.
What does the guide say the Security Rule requires?
Administrative, physical and technical safeguards that keep electronic PHI confidential, intact and available, and protect it against reasonably anticipated threats and impermissible uses. The rule does not dictate specific measures: each covered entity weighs its size, infrastructure, costs and risks, starting from a risk analysis it repeats over time. Safeguards range from a designated security official and role-based access to facility controls, audit controls and transmission security.
What does the guide say about training staff on HIPAA?
That the law itself requires it. A covered entity must train every workforce member, including employees, volunteers and trainees, on its privacy policies and procedures as their role requires, and apply sanctions to anyone who violates them. The Security Rule adds training on security policies for everyone who works with electronic PHI, and anyone who disposes of PHI, or supervises those who do, must be trained on disposal.
HIPAA Compliance: An Introduction, a free guide from LabLynx

Free guide

HIPAA Compliance: An Introduction

e-book

  • What HIPAA covers
  • Whether it applies to you
  • What counts as PHI