Summary: The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that requires health care providers — including doctors of optometry and optometry practices — to protect the privacy and security of patients’ protected health information (PHI).
If your optometry practice electronically transmits health information for certain transactions (like billing or eligibility checks), you are a “covered entity” under HIPAA and must comply.
This includes common activities such as:
PHI is information that identifies a patient or could reasonably be used to identify them. It includes things like:
PHI must be protected whether it’s oral, written, or electronic.
HIPAA allows secure electronic communication if reasonable safeguards are in place. Safeguards could include:
Patients can also object to certain electronic communications and ask for alternatives.
Under HIPAA’s Breach Notification Rule:
✔ Train staff on privacy and security policies.
✔ Perform regular risk assessments of how ePHI is stored and shared.
✔ Maintain up‑to‑date NPPs and security safeguards.
✔ Have signed business associate agreements with vendors.
✔ Act quickly and transparently if a breach occurs.
This overview is for general understanding only. HIPAA compliance involves detailed legal and technical requirements. You should work with legal counsel or HIPAA compliance professionals to ensure your practice meets all federal and applicable state requirements.
For more information and for access to a complete list of AOA HIPAA resources, please visit this link.