The HIPAA payment exception allows covered entities—such as healthcare providers, health plans, and billing services—to use and disclose PHI without patient authorization specifically for payment-related activities. This provision is outlined in the HIPAA Privacy Rule, which stipulates "To avoid interfering with an individual’s access to quality health care or the efficient payment for such health care, the Privacy Rule permits a covered entity to use and disclose protected health information, with certain limits and protections, for treatment, payment, and health care operations activities.".
In simpler terms, this exception means that healthcare providers and insurance companies can handle and share patient health information to get paid for services they deliver, without needing to seek the patient’s explicit permission for every transaction. That includes submitting claims to insurance companies, processing payments, and managing collections.
The payment exception allows for the efficient processing of claims, billing, and reimbursements, which are necessary for the financial stability of healthcare providers. Without this exception, managing these administrative tasks could become excessively burdensome, potentially impacting the accessibility and efficiency of healthcare services. The exception helps ensure that healthcare providers are compensated for their services while protecting patient privacy by facilitating these processes.
The HHS clarifies that "Payment” encompasses the various activities of health care providers to obtain payment or be reimbursed for their services and of a health plan to obtain premiums, to fulfill their coverage responsibilities and provide benefits under the plan, and to obtain or provide reimbursement for the provision of health care.".
Even though the HIPAA payment exception allows for the use and disclosure of PHI, covered entities must still comply with privacy and security standards.
Yes, PHI can be shared with third-party billing services as long as it is necessary for payment functions and the service provider complies with HIPAA regulations.
While it allows PHI to be used for payment purposes, covered entities must still follow the minimum necessary rule and implement appropriate security measures to protect patient privacy.
PHI used must be restricted to what is necessary for payment-related functions. It must also comply with HIPAA privacy and security standards.