HIPAA Compliance and Medical Privacy:
Privacy versus Security

Privacy versus Security:

It is important to understand the distinction between privacy and security – both in general as well as from the HIPAA-perspective.

Privacy in general refers to the restriction of access to personal information from unwanted parties. The HIPAA privacy rule sets forth rules regarding who in the healthcare and public arenas should have access to patient identifiable information.

In contrast, security refers to the methods by which an organization maintains the called-for privacy restrictions and limits access to patient information. These technical and operational requirements have been spelled out in draft forms under the HIPAA security provisions and were released in final form in 2002.

How PreViser supports privacy: Information is "de-identified" (the key 18 identifying items are removed to meet the HIPAA safe harbor requirements), and the PreViser ID is the only code linking a set of information together as belonging to a specific non-identifiable individual. Behind the firewall at your office, all Patient information is known; behind PreViser's firewall, only patient numeric data is stored.

How PreViser supports security: Information and algorithms are kept securely behind firewalls, at both your practice and at the central PreViser servers. information is encrypted before it is sent over the Internet (outside firewalls), then "re-identified" only safely behind firewall at each practice.

Next, we will look at the PreViser ID and how it allows a patient's information to be transmitted in de-identified form.