____________________________________________________________________________________

HIPAA Privacy Notice Requirements

December 12, 2013

____________________________________________________________________________________

The HIPAA Privacy Rule established limits on how Covered Entities may use and disclose an individual’s protected health information (PHI), and created rights for individuals with respect to their own PHI. Covered Entities include health plans, health care clearinghouses and health care providers that transmit certain health care information electronically.

The HIPAA Privacy Rule also requires Covered Entities to provide a Notice of Privacy Practices (or Privacy Notice) to each individual who is the subject of PHI.

On Jan. 25, 2013, the Department of Health and Human Services (HHS) released a final rule to implement changes made to the HIPAA Privacy Rule by the HITECH Act. The final rule, which becomes effective on Sept. 23, 2013, requires covered entities to modify and redistribute their Privacy Notices.

The HIPAA Privacy Rule includes special Privacy Notice requirements for fully insured health plans. Under these rules, issuers of fully insured health plans have the primary responsibility for the Privacy Notice and sponsors of these plans have limited responsibilities with respect to the Notice.

• If the sponsor of a fully insured plan has access to PHI for plan administrative functions, it is required to maintain a Privacy Notice and provide the notice upon request.

• If the sponsor of a fully insured plan does not have access to PHI, it is not required to maintain or provide a Privacy Notice.

 

CONTENT REQUIREMENTS

The Notice of Privacy Practices must be written in plain language and must:

• Explain how the health plan may use and disclose an individual’s PHI;

• Describe the individual’s rights with respect to his or her PHI; and

• Summarize the health plan’s legal duties with respect to the PHI.

 

There are a number of specific provisions that must be incorporated into the Privacy Notice, such as details regarding how individuals may exercise their rights with respect to PHI. A typical Privacy Notice is multiple pages long due to the numerous content requirements.

In response to requests that the Privacy Notice be modified to provide for a simpler, shorter version, HHS clarified that Covered Entities may utilize a “layered notice.” Under the layered notice approach, the full, more complete Privacy Notice must be provided to the individual and, in addition, the Covered Entity may include a shorter notice that briefly summarizes the individual’s rights and other important privacy information.

The final rule amends the content requirements of the Privacy Notice, effective Sept. 23, 2013. Under the new rule, a Privacy Notice must include the following additional information:

• A statement of an affected individual’s right to be notified following a breach of unsecured PHI;

 

 

• For health plans (other than issuers of long-term care policies) that intend to use or disclose PHI for underwriting purposes, a statement that the covered entity is prohibited from using or disclosing PHI that is genetic information for underwriting purposes; and

• Statements about uses and disclosures of PHI that require an individual’s authorization, such as disclosures for marketing purposes.

 

DELIVERY REQUIREMENTS

Delivery Deadlines

Health plans were first required to provide the Privacy Notice no later than the plan’s compliance deadline with the HIPAA Privacy Rule. For most health plans, this deadline was April 14, 2003 (small health plans had an additional year to comply, until April 14, 2004).

After the original deadline, at least once every three years, health plans must again provide the Privacy Notice, or notify participants that the notice is available and how to obtain a copy.

In addition, health plans must provide the Privacy Notice in the following circumstances:

• To new enrollees at the time of enrollment;

• Within 60 days of a material change to the notice (see below for more information and a special exception under the final rule); and

• Any time upon a participant’s request.

 

If a health plan sends out a revised notice (for example, following a material change to the notice), it will reset the three-year notice requirement.

Delivery Methods and Recipients

A health plan must provide the Privacy Notice to individuals covered by the plan. If the health plan provides the Privacy Notice to the covered employee, the plan is not required to provide a separate notice for dependents (for example, a spouse or child) covered through the employee.

The Privacy Notice must be actually delivered to participants. Merely posting the Privacy Notice on a website or on a bulletin board in the workplace is not sufficient. The Privacy Notice may be provided electronically (that is, by email) to participants who have agreed to receive an electronic notice. The health plan must provide a participant with a paper copy of the Privacy Notice if it discovers that the electronic delivery has failed.

In general, the Privacy Notice may be provided with other plan documents. It does not need to be provided as a stand-alone document. For example, a health plan could provide the Privacy Notice with the plan’s enrollment materials or with the summary plan description (SPD). However, the Privacy Notice may not be combined in the same document as a HIPAA authorization.

If a health plan maintains a website about the plan’s services or benefits, the Privacy Notice must be posted on the website and must be electronically available through the website.

Material Changes to Privacy Notice

If there is a material change to a health plan’s use or disclosures of PHI or any other information contained in the Privacy Notice, the health plan must revise its Notice to reflect the change and must distribute an updated Notice to participants. In general, a health plan may not apply a material change to its privacy practices before the effective date of the updated Privacy Notice.

According to HHS, the final rule’s changes to the Privacy Notice represent a material change. Thus, covered entities must prepare an updated Privacy Notice to provide to plan participants. The final rule contains special delivery provisions that allow some health plans to avoid the cost of a separate mailing. The final rule contains the following guidance for distributing updated Privacy Notices:

• A health plan that currently posts its Privacy Notice on its website must post the material change or a revised notice by Sept. 23, 2013 and provide the revised notice, or information about the material change and how to

 

 

obtain the revised notice, in its next annual mailing to plan participants (such as at the beginning of the plan year or during the plan’s open enrollment period).

• A health plan that does not post its Privacy Notice on a website must provide the revised notice, or information about the material change and how to obtain the revised notice, to individuals covered by the plan within 60 days of the material revision to the notice.

 

 

DOWNLOAD PDF OF THIS DOC:

HIPAA_Privacy_Notice_Requirements

Model Notices of Privacy Practices can be found at http://www.hhs.gov/ocr/privacy/hipaa/modelnotices.html

This Legislative Brief is not intended to be exhaustive nor should any discussion or opinions be construed as legal advice. Readers should contact legal counsel for legal advice.