HIPAA for Billing and Coding
Understand the privacy and security obligations that govern everything a billing professional touches.
By the end of this lesson you can
- Identify what counts as protected health information
- Apply the minimum necessary standard
- Explain what disclosures are permitted for payment operations
- Recognize a breach and know the reporting obligation
Lesson Notes
Read through the key concepts before you try the challenge.
You handle protected information all day
You work in billing at Lakeside Medical Associates.
In one morning you handle a patient's name, date of birth, diagnosis codes, dates of service, insurance identifiers, and payment history. Every one of those is protected health information, and the fact that your work is administrative rather than clinical changes nothing about your obligations.
Your task: Understand what you are handling and the rules that govern it.
Protected health information is individually identifiable health information held or transmitted by a covered entity. Billing data is squarely within it — a claim links a person to a diagnosis, which is exactly the kind of association the rules exist to protect.
HIPAA permits disclosure without patient authorization for treatment, payment, and health care operations. Billing sits in the payment category, which is why you may send a claim carrying a diagnosis to a payer. That permission is specific, not general: it covers what payment requires and nothing beyond it.
| Situation | Appropriate | Not appropriate |
|---|---|---|
| Submitting a claim | The codes and identifiers the claim requires | The complete clinical record attached by default |
| Responding to a payer records request | Records for the dates and services in question | The entire chart because it is easier to send |
| Discussing an account with a colleague | What they need to resolve the issue | Details unrelated to the question |
| Looking up a record | Accounts you are assigned to work | A neighbor's or coworker's record out of curiosity |
A breach is an impermissible use or disclosure that compromises the security or privacy of protected health information. Emailing a claim to the wrong address, leaving a report on a printer, discussing an account where it can be overheard, and losing an unencrypted device all qualify. Report a suspected breach immediately to your privacy officer — the reporting obligation has deadlines, and delay makes every outcome worse.
A payer requests records to support one claim for a single date of service. What should be sent?
Challenge
Apply what you've learned in this lesson.
Apply the standard to situations you will actually face.
- List the eighteen HIPAA identifiers. Note which ones appear on a routine claim.
- For each of these, decide whether it is a breach and justify it: a claim emailed to the wrong payer address; a report left on a shared printer overnight; discussing an account with the treating provider; looking up a coworker's balance out of concern for them.
- Write a three-sentence description of the minimum necessary standard as you would explain it to a new colleague.
- Find your organization's or a sample breach reporting procedure. Note who to contact and within what timeframe.
Finished this lesson?
Progress is saved in this browser only. It is not a grade — official progress lives in Brightspace.