The Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandates privacy and security safeguards for medical information about a person’s health status, care or payment for care, all of which are considered protected health information (PHI). Companies that utilize PHI in electronic communications, such as submission of health care claims, querying eligibility for a health plan or coordinating benefits, are subject to the requirements promulgated under HIPAA to protect PHI.

If only some of your company’s business components use PHI, however, you may be eligible to self-identify as a hybrid entity and designate which business units need to comply with HIPAA and, more importantly, which do not.