National Institute of Neurological Disorders & Stroke

Autism Research Institute (ARI)

National Center for Learning Disabilites (NCLD)

Attention Deficit Disorder Association

Children & Adults with ADHD (CHADD)

National Institute of Mental Health (NIMH)

Autism Speaks

HIPAA provides for the protection of individually identifiable health information that is transmitted or maintained in any form or medium. The privacy rules affect the day-to-day business operations of all organizations that provide medical care and maintain personal health information.

HIPAA requires the following entities to comply:

Health Care Providers: Any provider of medical or other health Services that bills or is paid for healthcare in the normal course of business. Health care includes preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling, services, assessment, or procedure with respect to the physical or mental condition, or functional status of an individual.

Health Care Clearinghouse: Businesses that process or facilitate the processing of health information received form other businesses. It includes groups such as physician and hospital billing services.

Health Plans: Individuals or group plans that provide or pay the cost of medical care and includes both Medicare and Medicaid programs.

HIPAA protects an individual’s health information and his/her demographic information. This is called “protected health information” or “PHI”. Information meets the definition of PHI if, even without the patient’s name, if you look at certain information and you can tell who the person is then it is PHI. The PHI can relate to past, present or future physical or mental health of the individual. PHI describes a disease, diagnosis, procedure, prognosis, or condition of the individual and can exist in any medium – files, voice mail, email, fax, or verbal communications.

HIPAA defines information as protected health information if it contains the following information about the patient, the patient’s household members, or the patient’s employers: Names Dates relating to a patient, i.e. birthdates, dates of medical treatment, admission and discharge dates, and dates of death. Telephone numbers, addresses (including city, county, or zip code) fax numbers and other contact information. Social Security numbers, Medical records numbers, Photographs, Finger and voice prints. Any other unique identifying number.

HIPAA stipulates the following patient’s right under its privacy rule: Patients have a right to receive a notice of the privacy practices of any health care provider, health clearing house, or health plan. Patients have a right to see their PHI and get a copy. Patients have a right to request that changes be made to correct errors in their records or to add information that has been omitted. Patients have a right to see a list of some of the disclosures that have been made of their PHI. Patients have a right to request that you give special treatment to their PHI. Patients have a right to request confidential communications. Patients have a right to complain. A health provider can disclose an individual’s PHI without the patient’s authorization if the disclosure deals with treatment, payment, operations, or if the information is mandated by law. Otherwise, for most other uses, the patient will need to authorize the provider to make the disclosure.