Skip to main content
Back to Top
Augusta University LogoShield

Information for:

  • Current Students
  • Alumni
  • Community
  • Faculty & Staff
  • Military
  • Patients

Resources

  • A-Z Index
  • Calendar
  • Campus Maps
  • D2L LMS
  • Email
  • Libraries
  • MyAugusta
  • News
  • Jobs & Careers
  • Portals
  • Pounce
  • Shuttles
  • Admissions
  • Academics
  • About
  • Student Life
  • Athletics
  • Research
  • Health
  •   Giving
Privacy
  • Compliance, Ethics & Risk Management
  • HIPAA
  • FERPA
  • Forms
  • Data Security
    • ID Theft Prevention
    • Email FAQs & Security from IT
    • Email Security Slideshow
    • Report Lost or Stolen Device
    • Telework Risk Assessment
  • Augusta University
  • Ethics & Compliance
  • Privacy
  • Health Insurance Portability and Accountability Act (HIPAA)

Health Insurance Portability and Accountability Act (HIPAA)

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a set of federal rules designed in part to protect the privacy of an individual’s health information. 

Protected Health Information

Protected Health Information

History of HIPAA

History of HIPAA

Individual Rights under the Privacy Rule

Individual Rights under the Privacy Rule

Uses and Disclosures

Uses and Disclosures

HIPAA in Research

HIPAA in Research

Hybrid Designation

Hybrid Designation

Training Resources

HealthStream
Workforce Learn Online
HIPAA Privacy and Security Basics


Contact Us

Compliance, Ethics & Risk Management

 Health Sciences Campus

Annex I

3000Q

706-721-0900

706-721-1910

compliance@augusta.edu


Third Party Hotline:
1-800-576-6623

Submit Online Report

What is Protected Health Information (PHI)

Health Information – Any information, whether oral or recorded in any form or medium, that (1) is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or health care clearinghouse; and (2) relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.

Individually Identifiable Health Information – Information that is a subset of health information, including demographic information collected from an individual, and (1) is created or received by a health care provider, health plan, employer, or health care clearinghouse; and (2) relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and (a) that identifies the individual; or (b) with respect to which there is a reasonable basis to believe the information can be used to identify the individual .

Protected Health Information - PHI is individually identifiable health information transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium. PHI excludes education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g, records described at 20 U.S.C. 1232g(a)(4)(B)(iv), and employment records held by a covered entity in its role as employer.


History of HIPAA

  •  

    HIPAA Signed into Law by President Clinton

    August 1996

  •  

    Effective Date of the HIPAA Privacy Rule

    April 2003

  •  

    Effective Date of the HIPAA Security Rule

    April 2005

  •  

    Effective Date of the HIPAA Breach Enforcement Rule

    March 2006

  •  

    Effective Date of HITECH and Breach Notification Rule

    September 2009

  •  

    Effective Date of the Final Omnibus Rule

    March 2013

  •  

Individual Rights under the Privacy Rule

The federal privacy regulations under HIPAA grants individuals certain rights to be informed about and to control their PHI.

Rights Under HIPAA

Here’s Where to Look

Right to inspect and copy of their PHI, including receiving electronic copies of all records included in the designated record set

  • Health Information Management: Release of Information
  • Request to Inspect or Obtain Medical Records
  • e-CFR §164.524

Right to amend their PHI

  • Request to Amend PHI Form
  • e-CFR §164.526

Right to receive an accounting of disclosures of their PHI

  • Request for Accounting of Disclosures Form
  • e-CFR §164.528

Right to receive a Notice of Privacy Practices

  • Augusta University Health Notice of Privacy Practices

Right to receive confidential communications of PHI

  • Request for Confidential Communications Form
  • e-CFR §164.522b

Right to restrict disclosure on certain uses and disclosures of their PHI

  • Request to Restrict Uses and Disclosure of PHI Form
  • e-CFR §164.522a

Right to file a complaint about a covered entity’s privacy practices to the covered entity as well as to the Office for Civil Rights (OCR).

  • Privacy Officer  (706) 721-0900
  • Hotline or  (800) 576-6623
  • OCR Complaints

Uses and Disclosures

Consent

Patient’s consent is permitted but not required for uses or disclosures of PHI for treatment, payment, or hospital operations.

Authorization

Authorization is required for all uses or disclosures of PHI not allowed in the privacy rule. Voluntary consent is not sufficient.

Required elements:

  • Description of PHI used or disclosed
  • Person authorized to use or disclose
  • To whom CE may make disclosure
  • Expiration Date
  • Purpose (in some cases)

HIPAA in Research

Health Services Research and the HIPAA Privacy Rule

Health Services Research and the HIPAA Privacy Rule

IRB Policy HIPAA and Research

IRB Policy HIPAA and Research

De-Identification of Personal Information - National Institute of Standards and Technology (NIST)

De-Identification of Personal Information - National Institute of Standards and Technology (NIST)
University Shield

Augusta University

1120 15th Street, Augusta, GA 30912

  •   Campus Maps
  •   Campus Contacts
  • A-Z Directory
  • Degrees & Programs
  • Employment
  • Accessibility
  • Accreditation
  • Campus Safety
  • Compliance Hotline
  • Human Trafficking Notice
  • Privacy Notices
  • Title IX / Sexual Misconduct
Apply Now Give Now

© 2025 Augusta University

Facebook Twitter LinkedIn Youtube Instagram
©