Are PHR vendors covered entities?
The Health Insurance Portability and Accountability Act (HIPAA) regulations do not usually classify personal health record (PHR) vendors as covered...
HIPAA usually ensures health information remains private, but different rules apply when it comes to credit card payments because it does not deal with health-related data.
HIPAA imposes compliance standards on entities that handle health records. However, a notable exemption within HIPAA exists concerning credit card processing services. Credit card processing services are explicitly excluded from the requirements of HIPAA. This exemption is based on the understanding that credit card processing services deal exclusively with card payment information and do not involve the storage, handling, or transmission of health records or electronic protected health information (ePHI).
See also: What is the HIPAA treatment exception?
For healthcare organizations, the HIPAA credit card exemption means they must be aware of the specific boundaries between their responsibilities for safeguarding health information and financial transactions.
A credit card payment service does not typically fall under the scope of HIPAA compliance because it deals exclusively with financial transactions, specifically card payment information.
In practice, while the credit card payment service itself might not be subject to HIPAA, healthcare organizations and professionals should be diligent in maintaining a clear separation between financial transactions (credit card payments) and the handling of health records to ensure compliance. They should not use credit card processing services to store or manage health records. This is not about making the credit card service HIPAA compliant but about how healthcare organizations and professionals handle their data responsibly.
See also: Guide to online payment options & HIPAA compliance
The Health Insurance Portability and Accountability Act (HIPAA) regulations do not usually classify personal health record (PHR) vendors as covered...
HIPAA authorization and Common Rule informed consent are two distinct but related elements in research involving protected health information (PHI)....
Recent research exposes a disconnect between healthcare organizations' public stance on compliance and private concerns.While institutions routinely...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.