This includes:
• Health insurance companies
• HMOs
• Company health plans
• Government programs that
pay for health care, such as
Medicare, Medicaid, and the
military and veterans’ health
care programs
This includes entities that
process nonstandard health
information they receive from
another entity into a standard
(i.e., standard electronic
format or data content), or
vice versa.
(US Department of Health and Human Services, 2015)
Under HIPAA, “health information” is any information (including genetic information) that is
created or received by a health care provider, health plan, public health authority, employer,
life insurance company, school or university, or health care clearinghouse. This includes a
person’s past, present, or future physical or mental health condition; treatment provided to a
person; or past, present, or future payment for healthcare an individual receives.
Health information can exist in any form or medium, including paper, electronic, or oral
(verbal). When a covered entity creates or receives health information that identifies, or can be
used to identify, a person, HIPAA calls it “individually identifiable health information.”
Individually identifiable health information includes demographic and other information that
identifies a person such as name, address, date of birth, and Social Security number. (Privacy
Rights Clearinghouse, 2015)
Privacy Rule
The Privacy Rule gives individuals rights with respect to their protected health information
(PHI). It also explains how covered entities (those who must comply with HIPAA) can use and
disclose PHI. (Privacy Rights Clearinghouse, 2015)