HIPAA applies only to covered entities and their business associates. The US Department of Health and Human Services lists three kinds of covered entity: health plans, health care clearinghouses, and health care providers such as doctors, clinics, nursing homes and pharmacies. Providers are covered only if they transmit health information electronically in a transaction for which HHS has adopted a standard. Business associates handle protected health information for a covered entity, as a billing service does.
Three rules do most of the work. The Privacy Rule protects identifiable health information in any form, electronic, paper or spoken, and requires reasonable efforts to use or disclose only the minimum necessary. The Security Rule requires administrative, physical and technical safeguards for electronic information. The Breach Notification Rule requires affected people to be told without unreasonable delay, and within 60 days of discovering a breach of unsecured information. HHS must be told too, and so must local media when more than 500 residents of a state are affected.
Infection control starts with the CDC’s Standard Precautions. They apply to every patient in every setting, whether or not infection is suspected: hand hygiene, protective equipment chosen for the task, respiratory hygiene and cough etiquette, safe injection practices, and cleaning and disinfection.
Notice who carries the training duty. Under 45 CFR 164.530(b), a covered entity must train every workforce member, including volunteers and trainees, on its own privacy policies and procedures, and document it. Under OSHA’s Bloodborne Pathogens standard, 29 CFR 1910.1030, an employer must train each employee with occupational exposure at initial assignment and at least annually. That training must be free, given in working hours and cover the employer’s own exposure control plan. HIPAA Awareness and Infection-Control Awareness are planned as introductions to the reasoning behind these rules.