Thursday, September 13, 2012

Health Insurance Exchanges: Privacy Guidelines

With the health insurance exchange surviving the SCOTUS constitutionality ruling, the work on the state health insurance exchanges has gained momentum and several U.S. states have accelerated their health exchange implementation efforts. Payers and carriers that are planning to participate in the ACA-mandated state based health insurance exchanges may have to abide with a spate of several new privacy and security regulations.

Health Insurance Exchanges will be online marketplaces where consumers can purchase health insurance and auxiliary services through these online portals. These exchanges are expected to reduce the healthcare costs and increase accessibility to care for the millions uninsured. With the complete insurance transactions happening through the internet, extra stress needs to be put on ensuring the privacy and online security of the data being interchanged between the exchanges and health plans.

Most of the state health insurance exchanges need to comply with the federal Privacy Act and all relevant applicable state laws. Exchanges also need to abide by a number of HHS rules and guidelines. However, instead of imposing one baseline standard, the HHS has given the state exchange administrators the flexibility to develop and introduce privacy and security guidelines as they deem fit as long as these guidelines follow the Federal Trade Commission Fair Information Practice Principles.

The HHS guidelines also require exchanges to collect consumer demographic data such as immigration status etc., apart from just collecting health information. The health insurance exchanges are also required to collect consumer personal data such as SSN & IRS details, from different federal agencies which will be linked to the Data Services hub, which in turn would be connected to different State systems.

Health insurance exchanges would also need to implement rules that conform to the “openness and transparency” ideologies and adopt a system where patients are granted some control over their health profiles.


No comments:

Post a Comment