Medicare Claims Processing Manual (Pub. 100-04), Ch. 24 § 20.3
HIPAA and ARRA on Security and Privacy
20.3 - HIPAA and ARRA on Security and Privacy
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
Two aspects of the HIPAA and ARRA legislation are pertinent to this chapter:
1. Ensuring the security of electronic data transmitted between covered entities, and
2. Ensuring the privacy of individuals who are the subject of electronic information
being transmitted between covered entities.
The ARRA legislation states the following in reference to actions to be taken by a
covered entity or their business associate in case of a breach of protected health
information:
H.R. 1-146, Subtitle D, Part 1, Section 13402 states that “a [covered entity or a]
business associate of a covered entity that accesses, maintains, retains, modifies, records,
stores, destroys, or otherwise holds, uses, or discloses unsecured protected health
information shall, following the discovery of a breach of such information, notify the
covered entity of such breach. Such notice shall include the identification of each
individual whose unsecured protected health information has been, or is reasonably
believed by the business associate to have been, accessed, acquired, or disclosed during
such breach.” See section 40.1.2.2 for a description of Medicare security and privacy
requirements.