Back to Top Skip to main content Skip to sub-navigation

How HIPAA Protects You

The Health Insurance Portability and Accountability Act (HIPAA) is designed to balance privacy, efficiency, and quality. A covered entity generally does not need your permission to share your protected health information (PHI) with another covered entity for treatment, payment, or healthcare operations, commonly referred to as TPO. For example, a doctor will generally not ask your permission before:

  • Sending your records to a second doctor for a second opinion (treatment);
  • Consulting with another health care provider regarding your medical status (treatment);
  • Asking TRICARE for reimbursement for the services you received (payment);
  • Sharing medical services provided for coverage and justification of charges (payment);
  • Reviewing your records to conduct MHS provider training programs, including certification and licensing (health care operations); and
  • Reviewing your records to see if your doctor followed protocol (health care operations).

However, HIPAA does give you the right to:

  • Learn how the Military Health System (MHS) will use and disclose your PHI;
  • Request to limit who can access your PHI;
  • Find out when a covered entity discloses your PHI to others;
  • Request to view and receive a copy of your PHI; and
  • Request to amend your PHI if incorrect or incomplete.

HIPAA also requires the MHS to:

  • Make sure your PHI is stored securely if maintained electronically;
  • Make sure your PHI is available when you need healthcare; and
  • Notify you if your PHI is lost or stolen.

You also may be interested in...

HIPAA Compliant Business Associate Agreement

Policy

The HIPAA Compliant Business Associate Agreement complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, Breach and Enforcement Rules (HIPAA Rules).

DoD Manual 6025.18-Implementation of the HIPAA Privacy Rule in DoD Health Care Programs

Policy

This issuance, in accordance with the authority in DoD Directive 5124.02, establishes policy and assigns responsibilities for; DoD compliance with federal law governing health information privacy and breach of privacy; Integrating health information privacy and breach compliance with general information privacy and security requirements in accordance with federal law and DoD issuances; Health information technology, system interoperability, and exchange of electronic health information, in relation to federal law governing health information privacy and breach; and DoD contracting and procurement activities in relation to federal law governing health information privacy and breach.

Health Information Privacy HIPAA Complaint Form

Form/Template
11/3/2014

The Health Information Privacy HIPAA Complaint Form is used by DHA to proceed with a complaint. DHA uses the information provided to determine if DHA has jurisdiction and, if so, how to process your complaint.

Recommended Content:

How HIPAA Protects You | HIPAA Compliance within the MHS

DoD Directive 5400.11: Department of Defense Privacy Program

Policy

This Regulation is reissued under the authority of DoD Directive 5400.11, “DoD Privacy Program,” May 8, 2007. It provides guidance on section 552a of title 5 United States Code (U.S.C.), the Privacy Act of 1974, as amended, and prescribes uniform procedures for implementation of the DoD Privacy Program.

General Mapping of HIPAA Security Rule to Existing DoD Policies and IA Controls

Fact Sheet
5/14/2014

This document represents an updated mapping of the HIPAA Security Rule to select DoD policies and IA controls. It does not constitute the rendering of legal advice or an exhaustive list of all possible mappings of the Security Rule to DoD policies or IA controls. The document is intended to provide general information and to allow different departments and components to customize the mapping according to their security policies.

Recommended Content:

How HIPAA Protects You | HIPAA Compliance within the MHS

Examples of PII

Fact Sheet
5/1/2014

Personally identifiable information (PII) is information that identifies, links, relates, or is unique to, or describes you. This also includes information which can be used to distinguish or trace your identity and any other personal information which is linked or linkable to you.

Recommended Content:

Privacy Act at DHA | Privacy Impact Assessments | HIPAA Compliance within the MHS | How HIPAA Protects You | Submit a Data Sharing Application | Breaches of PII and PHI | Freedom of Information Act | DHA Privacy Contract Language | Research Protections | Privacy Act and HIPAA Privacy Training

DoD/Veterans Affairs (VA) Sharing Memorandum of Understanding (MOU)

Policy

This MOU establishes a framework governing inter-Departmental transfer of PIII/PHI of beneficiaries who receive health care and/or other benefits from either Department. This MOU revises the MOU on "Defining Data-Sharing Between the Departments," executed in May and June of 2005.

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Spanish - Latin American

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Spanish - Latin American, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Russian

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Russian, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Portuguese - European

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Portuguese - European, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Poster - Print-Ready Version (portrait)

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready poster version of the brochure, measuring 24” x 36” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Korean

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Korean, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version (Tri-fold)

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, Tri-fold version of the brochure, measuring 8.5” x 14” (landscape/2-sided).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Turkish

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Turkish, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Thai

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Thai, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices
<< < 1 2 3 > >> 
Showing results 1 - 15 Page 1 of 3
Last Updated: March 20, 2019

DHA Address: 7700 Arlington Boulevard | Suite 5101 | Falls Church, VA | 22042-5101

Some documents are presented in Portable Document Format (PDF). A PDF reader is required for viewing. Download a PDF Reader or learn more about PDFs.