QUEST Integration - Privacy

Original Effective Date:

10/01/2003

Current Effective Date:

01/01/2015

HMSA's Privacy Practices

HMSA's notice of privacy practices may be accessed by clicking on the HIPAA Notice to HMSA Members on hmsa.com. It is also available upon request to all participating health care providers and members. Copies may be obtained by contacting the HMSA Privacy Office.

Compliance with HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) privacy regulations allow covered entities, such as HMSA and its participating providers, to share protected health information (PHI) without having to obtain individual permission for the purposes of treatment, payment, and health care operations (TPO) and without giving the individual the opportunity to opt out.

Participating Provider shall keep confidential and prevent the unauthorized disclosure of any and all medical records and information required to be prepared or maintained by Participating Provider, and shall at all times comply with all applicable laws and regulations governing the confidentiality and use of Member medical records and personal information, including, but not limited to, the provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the regulations promulgated thereunder, including the Security and Privacy requirements set forth in 45 C.F.R. Parts 160 and 164 and the Administrative Simplification requirements set forth in 45 C.F.R. Part 162; the provisions of 42 C.F.R. Part 431, Subpart F; H.A.R. Chapter 17-1702; H.R.S. §346-10; 42 C.F.R. Part 2; H.R.S. § 334-5; H.R.S. Chapter 577A; and all other applicable Hawaii statutes and administrative rules.

For questions regarding HIPAA, please refer to the following contact information:

U.S. Department of Health and Human Services
90 7th Street, Suite 4-100
San Francisco, CA  94103
Phone: 800-368-1019
Fax: 202-619-3818
TDD: 800-537-7697
Email: ocrmail@hhs.gov

Quality Improvement

HIPAA privacy regulations expressly include quality assessment and improvement activities within the definition of health care operations. Thus, HMSA's Quality Improvement (QI) Program activities and utilization management activities fall under the TPO provisions. Authorization from the affected individual is not required if the individual's PHI is used for those purposes.

HMSA's QI staff routinely contact and visit the offices of participating physicians for quality improvement activities. These include office site evaluations, medical records reviews, and other QI activities.

Medical Management

HMSA's Medical Management staff may ask physicians and other health care professionals for documentation of certain services when determining whether services meet HMSA's payment determination criteria. Information may also be requested for review of appropriate billing and utilization management. Like the QI activities referenced above, the sharing of PHI for these purposes is permissible under the TPO provisions of HIPAA.

Other HMSA Departments

Other HMSA departments may also ask physicians and other health care professionals for documentation of certain services. For example, the Appeals unit may request additional information to complete a case for higher-level review. HMSA's Benefits Integrity department may also request information. As indicated earlier, information may be shared under the TPO provisions of HIPAA for such purposes.

HMSA's Disease Management Services

HMSA contracts with Carelon Behavioral HealthSM to manage its behavioral health disease management services. Beacon has signed a business associate agreement with HMSA and has agreed to safeguard PHI. Please give them the same courtesy you would give HMSA staff members.

Administrative Procedures

Under the HIPAA privacy regulations, covered entities must have in place reasonable and appropriate administrative, technical, and physical safeguards to protect PHI. All HMSA staff members receive privacy training and sign confidentiality agreements recognizing that any breach of confidentiality is grounds for termination. Also, HMSA has HIPAA-compliant business associate agreements with all contracted personnel.

Fax Machines

If PHI is sent from HMSA's QUEST Integration department to a provider's office, the sender will validate the fax number and attach a cover sheet with a message indicating that the information is confidential and intended only for the individual to whom it is addressed. HMSA's QUEST Integration department fax machines are located in secured areas and are monitored by employees who are authorized to receive the information. We ask providers who send PHI to HMSA to attach a cover sheet including a confidentiality message.

Email

HMSA rarely exchanges email containing PHI with providers. Most inquiries related to a specific member are received and answered by telephone, mail, or fax. Nevertheless, in the event that PHI is included in an email from HMSA to a provider, the message will be encrypted. The email will have instructions for accessing the encrypted information.

HHIN+

If there are two or more members with the same name and birth date, the Hawaii Health Information Network (HHIN+) will ask for additional information to ensure that information will be released for one specific member only.

Teleservice Procedures

QUEST Integration Provider Service representatives ask providers to verify their QUEST Integration provider number before any PHI (including eligibility, benefits, or claims data) is provided. Providers should be sure that their staff have appropriate provider numbers available before they call HMSA for information.

Under HIPAA, each covered entity has the responsibility to execute a business associate agreement with each of its subcontractors. HMSA will provide information to your billing service if we have been given a copy of your agreement with the billing service.

Member or claims information is not released to collection agencies. If a collection agency calls QUEST Integration Provider Service for this information, it will be directed to obtain the information from the provider. Even though a collection agency may be contracted by a provider, the employees of the agency should not misrepresent themselves as being in the employ of the provider.


Revision History

Date Nature of Revision
08/03/2026 Migrated to new platform.