HMSA’s Privacy Practices
HMSA’s notice of privacy practices may be accessed by clicking on the HIPAA Notice to HMSA Members on hmsa.com. It is also available upon request to all participating health care providers and members. Copies may be obtained by contacting the HMSA Privacy Office.
Compliance with HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) privacy regulations allow covered entities, such as HMSA and its participating providers, to share protected health information (PHI) without having to obtain individual permission for the purposes of treatment, payment, and health care operations (TPO) and without giving the individual the opportunity to opt out.
Quality Improvement
HIPAA privacy regulations expressly include quality assessment and improvement activities within the definition of health care operations. Thus, HMSA's Quality Improvement (QI) Program activities and utilization management activities fall under the TPO provisions. Authorization from the affected individual is not required if the individual's PHI is used for those purposes.
HMSA’s QI staff routinely contact and visit the offices of participating physicians for quality improvement activities. These include office site evaluations, medical records reviews, and other QI activities.
Medical Management
HMSA’s Medical Management staff may ask physicians and other health care professionals for documentation of certain services when determining whether services meet HMSA’s payment determination criteria. Information may also be requested for review of appropriate billing and utilization management. Like the QI activities referenced above, the sharing of PHI for these purposes is permissible under the TPO provisions of HIPAA.
Other HMSA Departments
Other HMSA departments may also ask physicians and other health care professionals for documentation of certain services. For example, HMSA’s Claims Administration department may request additional information to process a provider’s claim or the Appeals unit may request additional information to complete a case for higher-level review. HMSA’s Benefits Integrity department may also request information. As indicated earlier, information may be shared under the TPO provisions of HIPAA for such purposes.
HMSA’s Disease Management Services
HMSA contracts with Healthways and Carelon Behavioral HealthSM, to manage its disease management services (e.g., behavioral health and prenatal care). These vendors have signed business associate agreements with HMSA and have agreed to safeguard PHI. When these vendors call you or visit your office to discuss patients enrolled in the disease management services, please give them the same courtesy you would give HMSA staff members.
Administrative Procedures
Under the HIPAA privacy regulations, covered entities must have in place reasonable and appropriate administrative, technical, and physical safeguards to protect PHI. All HMSA staff members receive privacy training and sign confidentiality agreements recognizing that any breach of confidentiality is grounds for termination. Also, HMSA has HIPAA-compliant business associate agreements with all contracted personnel.
Fax Machines
If PHI is sent from HMSA to a provider’s office, the sender will validate the fax number and attach a cover sheet with a message indicating that the information is confidential and intended only for the individual to whom it is addressed. HMSA departments that receive PHI via fax are located in secured areas and are monitored by employees who are authorized to receive the information. We ask providers who send PHI to HMSA to attach a cover sheet including a confidentiality message.
HMSA rarely exchanges email containing PHI with providers. Most inquiries related to a specific member are received and answered by telephone, mail, or fax. Nevertheless, in the event that PHI is included in an email from HMSA to a provider, the message will be encrypted. The email will have instructions for accessing the encrypted information.
HHIN+
If there are two or more members with the same name and birth date, the Hawaii Health Information Network (HHIN+) will ask for additional information to ensure that information will be released for one specific member only.
Teleservice Procedures
Provider Teleservice representatives ask providers to verify their provider number before any PHI (including eligibility, benefits, or claims data) is provided. Providers should be sure that their staff have appropriate provider numbers available before they call HMSA for information.
Under HIPAA, each covered entity has the responsibility to execute a business associate agreement with each of its subcontractors. HMSA will provide information to your billing service if we have been given a copy of your agreement with the billing service.
Member or claims information is not released to collection agencies. If a collection agency calls Provider Teleservice for this information, it will be directed to obtain the information from the provider. Even though a collection agency may be contracted by a provider, the employees of the agency should not misrepresent themselves as being in the employ of the provider.
Revision History
| Date | Nature of Revision |
|---|---|
| 08/03/2026 | Migrated to new platform. |