Skip subpage navigation
The Health Insurance Portability and Accountability Act applies to your protected health information. Your PHI is any information that:
- Identifies you;
- Is about your health or demographics;
- Is maintained by a covered entity or business associate; and
- Is related to your treatment, your medical condition, and the related payment for that condition as maintained by a covered entity or business associate.
The DHA Privacy and Civil Liberties Office helps the Military Health System comply with the following HIPAA Rules:
- The HIPAA Privacy Rule defines how your PHI should be safeguarded, limits when it can be used and disclosed without your authorization, and ultimately gives you some control over your own PHI.
- The HIPAA Security Rule defines how your PHI should be protected and transferred when maintained electronically.
- The HIPAA Breach Notification Rule defines when your PHI has been inappropriately used or disclosed (see Breaches of PII and PHI page) and describes the breach response obligations of a covered entity.
The Chief of the DHA Privacy Office is the appointed HIPAA Privacy Officer and HIPAA Security Officer, and has authority over the HIPAA Privacy and Security programs at DHA.
For more information DHA’s HIPAA compliance program, please read the DHA’s HIPAA Privacy and HIPAA Security Core Tenets Policy Statement.
You also may be interested in...
Policy
Jan 6, 2022
.PDF |
239.48 KB
The HIPAA Compliant Business Associate Agreement complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, Breach and Enforcement Rules (HIPAA Rules).
- Identification #: N/A
- Type: Guideline
Policy
Mar 13, 2019
This issuance, in accordance with the authority in DOD Directive 5124.02, establishes policy and assigns responsibilities for DOD compliance with federal law governing health information privacy and breach of privacy; integrating health information privacy and breach compliance with general information privacy and security requirements in accordance ...
- Identification #: DODI 6025.18
- Type: Instruction
Policy
May 1, 2014
The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The HIPAA Security Rule establishes national standards to protect ...
- Identification #: N/A
- Type: Federal Regulation
Policy
Mar 14, 2014
.PDF |
5.79 MB
This MOU establishes a framework governing inter-Departmental transfer of PIII/PHI of beneficiaries who receive health care and/or other benefits from either Department. This MOU revises the MOU on "Defining Data-Sharing Between the Departments," executed in May and June of 2005.
- Identification #: N/A
- Type: Memorandum of Understanding
Policy
Jul 26, 2012
.PDF |
3.32 MB
This Memorandum outlines how DOD health care entities may consider a properly completed and electronically signed Form SSA-827 a valid authorization which permits the release of that individual's PHI to the Social Security Administration (SSA).
- Identification #: N/A
- Type: Memorandum
Policy
Dec 2, 2009
Establishes policy and assigns responsibilities for implementation of the standards for privacy of individually identifiable health information in accordance with parts 160 and 164 of title 45, Code of Federal Regulations.
- Identification #: DODI 6025.18
- Type: Instruction
Policy
Sep 9, 2004
.PDF |
2.09 MB
This letter outlines the roles of the HIPAA Security Official at the TRICARE Regional Offices. This person oversees all ongoing activities related to the development, implementation, and maintenance of the organization’s policies and procedures covering the security of electronic patient information.
- Identification #: N/A
- Type: Memorandum
Policy
Sep 9, 2004
.PDF |
1.72 MB
This letter outlines the requirements for Medical Treatment Facility and Dental Treatment Facility (MTF/DTF) personnel to be assigned the responsibility of managing and supervising the execution and use of security measures to protect data as well as the responsibility of managing and supervising the conduct of personnel in relation to those measures.
- Identification #: N/A
- Type: Memorandum
Policy
Sep 9, 2004
.PDF |
1.30 MB
This letter outlines HIPAA Security responsibilities for Service specific policy and procedure development and implementation. A Service Headquarters level HIPAA Security Official in each Service is needed.
- Identification #: N/A
- Type: Memorandum
Policy
Apr 9, 2003
Under 45 CFR part 164, "Standards for Privacy of Individually Identifiable Health Information" and DOD 6025.18–R, "DOD Health Information Privacy Regulation" provisions are made to allow appropriate uses and disclosures of protected health information concerning members of the armed forces to assure the proper execution of the military mission, ...
- Identification #: 68 Fed. Reg. 17357-58
- Type: Federal Regulation
Policy
Jun 18, 2002
.PDF |
115.55 KB
The purpose of this letter is to request that a Privacy Officer be appointed at each Military Treatment Facility and Dental Treatment Facility in the Military Health System.
- Identification #: N/A
- Type: Guideline
Policy
Dec 28, 2000
The Department of Health and Human Services (HHS) Preamble to Final HIPAA Privacy Rule includes standards to protect the privacy of individually identifiable health information (see pages 82704-05).
- Identification #: N/A
- Type: Federal Regulation
Policy
Aug 21, 1996
The purpose of this document is to amend the Internal Revenue Code of 1986 to improve portability and continuity of health insurance coverage in the group and individual markets, to combat waste, fraud, and abuse in health insurance and health care delivery, to promote the use of medical savings accounts, to improve access to long-term care services ...
- Identification #: 110 STAT. 1936
- Type: Federal Regulation
You are leaving Health.mil
The appearance of hyperlinks does not constitute endorsement by the Department of Defense of non-U.S. Government sites or the information, products, or services contained therein. Although the Defense Health Agency may or may not use these sites as additional distribution channels for Department of Defense information, it does not exercise editorial control over all of the information that you may find at these locations. Such links are provided consistent with the stated purpose of this website.
You are leaving Health.mil
View the external links disclaimer.
Last Updated: July 10, 2024