The Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, was enacted on August 21, 1996. Sections 261 through 264 of HIPAA require the Secretary of HHS to publicize standards for the electronic exchange, privacy and security of health information. According to HIPAA Privacy rule, Limited Data Set of ePHI is authorized only for public health, research and health care operations purposes only.
All direct identifiers should be removed prior to sharing the data for any purpose. Some of the direct identifiers include:
1. Name
2. Addresses : E-mail address, Street address, URL address, IP address etc.
3. Numbers : Telephone, Fax, License, SSN, Certificate/Serial/Medical record numbers, Drivers license, health plan beneficiary numbers etc.
4. Images: Full face photos, biometric identifiers, finger prints etc.
Under the privacy rule, The following identifying information can be shared:
1. Dates such as Admission, discharge, service, date of birth, date of death(when applicable).
2. Gender
3. Five-digit zip code or any other geographic subdivision, such as state, county, city or any other equivalent.
HIPAA requires that all the safeguards, minimum necessary, BA contracts and breach rules to be followed by the recipients to these data.