The
US Health Insurance Portability and Accountability Act of 1996, referred
to as HIPAA, contains many elements dealing with a broad range of health
related issues, including patient privacy and security standards.
The privacy regulations were released to implement requirements of the administrative simplification section of HIPAA, requiring:
HIPAA applies to "covered entities", including:
Most
covered entities have until April 14, 2003 to comply with the HIPAA privacy
standards. Entities with annual receipts of less than five million dollars
will have an additional twelve months to comply. The remaining standards,
including the draft "Health Information Security Standards",
are yet to be published, but are expected to be issued in the near future.
Once published, there will be approximately twenty-six months before they
become effective.
