Skip to main content

Military Health System

HIPAA Compliance within the MHS

The Health Insurance Portability and Accountability Act (HIPAA) applies to your protected health information (PHI). Your PHI is any information that:

  • Identifies you;
  • Is about your health or demographics;
  • Is maintained by a covered entity or business associate; and
  • Is related to your treatment, your medical condition, and the related payment for that condition as maintained by a covered entity or business associate.

The DHA Privacy and Civil Liberties Office (PCLO) helps the Military Health System (MHS) comply with the following HIPAA Rules:

  • The HIPAA Privacy Rule defines how your PHI should be safeguarded, limits when it can be used and disclosed without your authorization, and ultimately gives you some control over your own PHI.
  • The HIPAA Security Rule defines how your PHI should be protected and transferred when maintained electronically. 
  • The HIPAA Breach Notification Rule defines when your PHI has been inappropriately used or disclosed (see Breaches of PII and PHI page) and describes the breach response obligations of a covered entity.

The Chief of the DHA Privacy Office is the appointed HIPAA Privacy Officer and HIPAA Security Officer, and has authority over the HIPAA Privacy and Security programs at DHA.

For more information DHA’s HIPAA compliance program, please read the DHA’s HIPAA Privacy and HIPAA Security Core Tenets Policy Statement.

You also may be interested in...

HIPAA Compliant Business Associate Agreement

Policy

The HIPAA Compliant Business Associate Agreement complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, Breach and Enforcement Rules (HIPAA Rules).

Draft Version 7030 Dashboard Metrics

Technical Document
7/25/2019

This graphic dashboard depicts MHS change analysis information pertaining to the reviews of the X12 Version 7030 Draft Implementation Guides.

Recommended Content:

HIPAA Compliance within the MHS | Current Initiatives

DOD Instruction 6025.18: Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DOD Health Care Programs

Policy

This issuance, in accordance with the authority in DOD Directive 5124.02, establishes policy and assigns responsibilities for DOD compliance with federal law governing health information privacy and breach of privacy; integrating health information privacy and breach compliance with general information privacy and security requirements in accordance with federal law and DOD issuances; health information technology, system interoperability, and exchange of electronic health information, in relation to federal law governing health information privacy and breach; and DOD contracting and procurement activities in relation to federal law governing health information privacy and breach.

Connecting with Local SIT

Technical Document
9/28/2018

Recommended Content:

HIPAA Compliance within the MHS

Health Information Privacy HIPAA Complaint Form

Form/Template
11/3/2014

The Health Information Privacy HIPAA Complaint Form is used by DHA to proceed with a complaint. DHA uses the information provided to determine if DHA has jurisdiction and, if so, how to process your complaint.

Recommended Content:

How HIPAA Protects You | HIPAA Compliance within the MHS

General Mapping of HIPAA Security Rule to Existing DoD Policies and IA Controls

Fact Sheet
5/14/2014

This document represents an updated mapping of the HIPAA Security Rule to select DoD policies and IA controls. It does not constitute the rendering of legal advice or an exhaustive list of all possible mappings of the Security Rule to DoD policies or IA controls. The document is intended to provide general information and to allow different departments and components to customize the mapping according to their security policies.

Recommended Content:

How HIPAA Protects You | HIPAA Compliance within the MHS

Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules (45 C.F.R. Parts 160 and 164)

Policy

The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The HIPAA Security Rule establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. Refer to 45 C.F.R. Parts 160 and 164 for additional information.

Examples of PII

Fact Sheet
5/1/2014

Personally identifiable information (PII) is information that identifies, links, relates, or is unique to, or describes you. This also includes information which can be used to distinguish or trace your identity and any other personal information which is linked or linkable to you.

Recommended Content:

Privacy Act at DHA | Privacy Impact Assessments | HIPAA Compliance within the MHS | How HIPAA Protects You | Breach Prevention and Response | Freedom of Information Act | Privacy Contract Language | Research Protections | HIPAA and Privacy Act Training

DoD/Veterans Affairs (VA) Sharing Memorandum of Understanding (MOU)

Policy

This MOU establishes a framework governing inter-Departmental transfer of PIII/PHI of beneficiaries who receive health care and/or other benefits from either Department. This MOU revises the MOU on "Defining Data-Sharing Between the Departments," executed in May and June of 2005.

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Spanish - Latin American

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Spanish - Latin American, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Vietnamese

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Vietnamese, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Russian

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Russian, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Korean

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Korean, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version - Thai

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, portrait version of the brochure in Thai, measuring 8.5” x 11” (vertical).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices

MHS Notice of Privacy Practices (NoPP) - Brochure - Print-Ready Version (Tri-fold)

Publication
10/1/2013

The MHS Notice of Privacy Practices (NoPP) describes how medical information about you may be used and disclosed and how you can get access to this information. This is a print-ready, Tri-fold version of the brochure, measuring 8.5” x 14” (landscape/2-sided).

Recommended Content:

HIPAA Compliance within the MHS | How HIPAA Protects You | MHS Notice of Privacy Practices
<< < 1 2 3 > >> 
Showing results 1 - 15 Page 1 of 3
Last Updated: September 01, 2022
Follow us on Instagram Follow us on LinkedIn Follow us on Facebook Follow us on Twitter Follow us on YouTube Sign up on GovDelivery