The Health Insurance Portability and Accountability Act of 1996 (HIPAA) includes a series of "administrative simplification" provisions designed to improve the efficiency and effectiveness of the healthcare system, including standards for electronic healthcare transactions. By ensuring consistency throughout the industry, the national standards are intended to make it easier for health plans, doctors, hospitals and other providers to process claims and other transactions electronically. HIPAA also establishes privacy and security standards to protect patient-identifiable health information, referred to as "protected health information" or "PHI."
Introduction
Under HIPAA, all healthcare providers must use HIPAA-compliant, standard electronic formats if they are submitting electronic media claims. Health plans must accept electronic claims submitted in the new formats, process the claims, and send an electronic remittance in the HIPAA-compliant, standard formats. The HIPAA rules about electronic formats do not apply to providers filing paper claims. The deadline for both providers and health plans to change their electronic systems was effective October 16, 2003.
Summarized below are the steps HMSA is taking to ensure that its activities are in compliance with the HIPAA provisions. Please note that specific dates and HMSA's plans for compliance with HIPAA regulations are subject to change as a result of situations, such as regulatory changes, that are beyond HMSA's control.
HIPAA Compliance Background
Transactions and Code Sets
HMSA had a HIPAA readiness team working toward compliance with the rules for electronic transactions and standard code sets since April 2000 and was in compliance by the October 16, 2003, deadline.
Privacy
Maintaining the privacy of individually identifiable health information has always been a priority for HMSA. As a result, HMSA’s compliance effort was directed toward reviewing current practices in conjunction with the specific requirements of the HIPAA Privacy regulations. Much work in ensuring appropriate handling of protected information was done in 1999 and 2000 when the Hawaii Privacy of Health Care Information Act was passed and became effective. Although this state law was repealed in 2001, much of the foundation for compliance with HIPAA had been laid because the state law was very similar to the HIPAA Privacy regulations. HMSA’s additional efforts to comply with the specific requirements of the HIPAA Privacy regulations brought HMSA into compliance by the mandated compliance date of April 14, 2003.
Security
Ensuring the security of information and systems has been an ongoing priority for HMSA. HMSA's security policies, procedures and practices are industry best practices. HMSA has strengthened its corporate-wide Information Protection Program, including implementation of an Information Protection unit with an identified security official, continued development of security policy and standards, security architecture, platform standards, and processes supporting access controls, incident management, risk assessment, compliance and controls, data classification, and security awareness. HMSA also addressed infrastructure and applications upgrades necessary to ensure compliance with the policies, procedures, processes and architecture.
Revision History
| Date | Nature of Revision |
|---|---|
| 08/03/2026 | Migrated to new platform |