Does HIPAA apply to insurance claims?

Asked by: Leanna Thompson  |  Last update: June 20, 2025
Score: 4.3/5 (40 votes)

We call the entities that must follow the HIPAA regulations "covered entities." Covered entities include: Health Plans, including health insurance companies, HMOs, company health plans, and certain government programs that pay for health care, such as Medicare and Medicaid.

Does HIPAA regulate insurance claims?

Health Care Providers.

These transactions include claims, benefit eligibility inquiries, referral authorization requests, or other transactions for which HHS has established standards under the HIPAA Transactions Rule.

Is insurance covered under HIPAA?

For HIPAA purposes, health plans include: Health insurance companies. HMOs, or health maintenance organizations. Employer-sponsored health plans.

Are insurance claims confidential?

California Insurance Code Sections 791 - 791.27, the Insurance Information and Privacy Protection Act (IIPPA), provide protections for one's personally identifiable information, which is generally provided to an agent, broker or insurance company in order to apply for insurance or submit a claim.

What does HIPAA not apply to?

Generally, public schools, colleges, and other educational institutions that provide medical services for students and staff (as a work benefit) are not considered to be covered entities under HIPAA.

Who does HIPAA not apply to and why?

28 related questions found

What are the 3 exceptions to HIPAA?

The Three Exceptions to a HIPAA Breach
  • Unintentional Acquisition, Access, or Use. ...
  • Inadvertent Disclosure to an Authorized Person. ...
  • Inability to Retain PHI.

What isn't protected under HIPAA?

Employee and education records: Any records regarding employee or student health, including known allergies, blood type, or disabilities, are not considered PHI. Wearable devices: Data collected by wearable devices including heart rate monitors or smartwatches is not PHI.

Are insurance claims privileged?

If litigation proceeds, the client often relies on information in the insurer's claims files. If a conflict must be resolved between insurer and insured, claims files are not considered privileged because they are treated as belonging to both parties.

Are insurance claims public?

Yes. There are specialty consumer reporting agencies that collect and report information about the insurance claims you have made on your property and casualty insurance policies, such as your homeowners and auto policies. They may also collect and report on your driving record.

What insurance covers breach of confidentiality?

Privacy Liability Coverage

Privacy liability coverage is essential for organizations handling sensitive employee and customer information. It helps protect the organization in the event of a data breach that exposes private data and exposes the organization to liability.

Are insurance agents bound by HIPAA?

Insurance agents are required to comply with the HIPAA Privacy and Security Rules. Agents and brokers are considered Business Associates under HIPAA. They support two different groups, and have to make sure they are compliant for both parties.

What are the three rules of HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) lays out three rules for protecting patient health information, namely:
  • The Privacy Rule.
  • The Security Rule.
  • The Breach Notification Rule.

What information can be shared without violating HIPAA?

HIPAA permits health care providers to disclose to other health providers any protected health information (PHI) contained in the medical record about an individual for treatment, case management, and coordination of care and, with few exceptions, treats mental health information the same as other health information.

Which type of insurance is not covered under HIPAA?

Life insurers do not process electronic health information for healthcare-related transactions, so HIPAA does not cover them.

Does HIPAA apply to fully insured plans?

Under a fully-insured plan, employers are insulated from this level of detail. However, employee self-disclosure opens the requirement for HIPAA compliance in a fully-insured plan. With a self-funded plan, employers collect the money from premiums paid by employees when they enroll in the company health plan.

Does HIPAA apply to everything?

HIPAA-covered entities include health insurers, healthcare providers (doctors, hospitals, pharmacies) and “business associates,” such as vendors used by hospitals. What's not subject to HIPAA may surprise you, including pharmaceutical companies, employers and universities.

Do insurance companies share information about claims?

Insurance companies will often provide the reports, with the policyholder's authorization, to assist police in completing their official accident report and determining fault. However, without consent from the insured driver or owner of the vehicle, an insurance company cannot release the claim details or report.

Is insurance coverage public information?

Insurance companies are generally required to keep your policy information confidential. However, they may share information with third parties under certain circumstances, such as with your consent, for legal reasons, or to process claims.

Can your company see your insurance claims?

The short answer is generally no. In most cases, your employer cannot view the specific details of your health insurance claims.

Are insurance claims discoverable?

California law expressly provides for discovery of information about the evidence and contents of any insurance agreement under which a carrier may be liable to satisfy all or part of a potential judgement or to indemnify or reimburse payments made to satisfy the judgment.

Are conversations with insurance privileged?

Are communications among a client, a third party, such as an insurance broker, and the client's attorney privileged? The answer is yes, if the communications are confidential and reasonably necessary to accomplish the purpose for which the lawyer was consulted.

Who denies insurance claims?

Insurance companies deny claims for many reasons, such as insufficient evidence, missed deadlines, or policy exclusions. If your insurance company denied your claim, you can file an appeal, agree to mediation or arbitration, or take the insurance company to court for bad faith.

Does insurance follow HIPAA?

Who Must Follow These Laws. We call the entities that must follow the HIPAA regulations "covered entities." Covered entities include: Health Plans, including health insurance companies, HMOs, company health plans, and certain government programs that pay for health care, such as Medicare and Medicaid.

What is exempt from HIPAA?

4. Colleges and Universities. In most cases, HIPAA compliance does not apply to school-based health programs. In other words, colleges and universities are not considered covered entities, but they may employ a healthcare provider that conducts transactions electronically, a HIPAA-covered process.

What cannot be disclosed under HIPAA?

Protected health information (PHI) cannot be shared under HIPAA. So what exactly is considered PHI according to HIPAA? It's information that can identify a particular patient, including health records, lab reports, bills, or even verbal conversations.