Health Insurance Portability and Accountability Act (HIPAA)
What Does 'Health Insurance Portability and Accountability Act (HIPAA)' Mean?
The Act, in part, specifies requirements that a Long-Term Care Insurance policy must meet in order that premiums paid may be deducted as medical expenses, and benefits paid not to be considered taxable income. It also establishes national standards for protecting individuals' medical records and other personal health information.
More Information
The Health Insurance Portability and Accountability Act (HIPAA) of 1996, also known as the Kennedy–Kassebaum Act, was enacted by the 104th United States Congress and signed by President Bill Clinton in 1996. It became law on January 1, 1997.
HIPAA outlines important requirements for Long-Term Care Insurance policies to meet in order to be tax-qualified. Any policy that meets these requirements is eligible for tax deductions as a medical expense. Benefits are not considered taxable income either.
Other areas of HIPAA cover medical privacy and protect health insurance coverage for workers and their families when they change or lose their jobs. Both protections are essential and significant.
HIPAA and Medical Privacy
One of HIPAA's most far-reaching provisions is the Privacy Rule, which establishes national standards for protecting individuals' medical records and other personal health information. It applies to health plans, health care clearinghouses, and health care providers that conduct certain transactions electronically — collectively known as "covered entities."
Under the Privacy Rule, covered entities must:
- Safeguard the privacy of patients' protected health information (PHI)
- Give patients the right to access and request corrections to their own records
- Notify patients about how their health information may be used and shared
- Obtain patient authorization before disclosing PHI for purposes beyond treatment, payment, or health care operations
The Security Rule, a companion to the Privacy Rule, sets specific standards for protecting electronic protected health information (ePHI). As health records have moved increasingly to digital platforms, this safeguard has grown more critical. Covered entities must implement administrative, physical, and technical protections to prevent unauthorized access, use, or disclosure of ePHI.
For older adults and those navigating the long-term care system, HIPAA's privacy protections carry particular weight. Medical records, care assessments, cognitive evaluations, and financial information tied to health decisions are all subject to these protections. Family members, caregivers, and even insurers may only receive information to the extent permitted under HIPAA — and in many cases, only with the patient's explicit authorization.
Violations of HIPAA's privacy and security rules can result in significant civil and criminal penalties, enforced by the U.S. Department of Health and Human Services' Office for Civil Rights (OCR).