←Module 8
Lesson · 24 min

HIPAA for Billing and Coding

Understand the privacy and security obligations that govern everything a billing professional touches.

By the end of this lesson you can

  • Identify what counts as protected health information
  • Apply the minimum necessary standard
  • Explain what disclosures are permitted for payment operations
  • Recognize a breach and know the reporting obligation
📘 Reading Lesson

Lesson Notes

Read through the key concepts before you try the challenge.

You handle protected information all day

On the job

You work in billing at Lakeside Medical Associates.

In one morning you handle a patient's name, date of birth, diagnosis codes, dates of service, insurance identifiers, and payment history. Every one of those is protected health information, and the fact that your work is administrative rather than clinical changes nothing about your obligations.

Your task: Understand what you are handling and the rules that govern it.

Protected health information is individually identifiable health information held or transmitted by a covered entity. Billing data is squarely within it — a claim links a person to a diagnosis, which is exactly the kind of association the rules exist to protect.

HIPAA permits disclosure without patient authorization for treatment, payment, and health care operations. Billing sits in the payment category, which is why you may send a claim carrying a diagnosis to a payer. That permission is specific, not general: it covers what payment requires and nothing beyond it.

SituationAppropriateNot appropriate
Submitting a claimThe codes and identifiers the claim requiresThe complete clinical record attached by default
Responding to a payer records requestRecords for the dates and services in questionThe entire chart because it is easier to send
Discussing an account with a colleagueWhat they need to resolve the issueDetails unrelated to the question
Looking up a recordAccounts you are assigned to workA neighbor's or coworker's record out of curiosity
The minimum necessary standard in practice
Accessing a record you have no work reason to see is a violation even if you tell no one and change nothing. Access is logged, audits are routine, and curiosity about a coworker's, neighbor's, or public figure's record is among the most common causes of termination in healthcare administration. There is no version of this that is harmless.

A breach is an impermissible use or disclosure that compromises the security or privacy of protected health information. Emailing a claim to the wrong address, leaving a report on a printer, discussing an account where it can be overheard, and losing an unencrypted device all qualify. Report a suspected breach immediately to your privacy officer — the reporting obligation has deadlines, and delay makes every outcome worse.

Check your understanding

A payer requests records to support one claim for a single date of service. What should be sent?

Challenge

Apply what you've learned in this lesson.

Apply the standard to situations you will actually face.

  1. List the eighteen HIPAA identifiers. Note which ones appear on a routine claim.
  2. For each of these, decide whether it is a breach and justify it: a claim emailed to the wrong payer address; a report left on a shared printer overnight; discussing an account with the treating provider; looking up a coworker's balance out of concern for them.
  3. Write a three-sentence description of the minimum necessary standard as you would explain it to a new colleague.
  4. Find your organization's or a sample breach reporting procedure. Note who to contact and within what timeframe.

Finished this lesson?

Progress is saved in this browser only. It is not a grade — official progress lives in Brightspace.