Nicole Wilson
August 27, 2023
5 min read
Share this post


In 1996, President Clinton supported, and the U.S. Congress enacted the Health Insurance Portability and Accountability Act (HIPAA). HIPAA enables eligible individuals to purchase health insurance after losing coverage that was sponsored by an employer regardless of preexisting health conditions. If a person is eligible, all health insurance companies selling individual plans must offer the individual health insurance despite medical conditions and history.HIPAA performs the following:

  • Minimizes health care abuse and fraud
  • Allows millions of Americans' health insurance coverage to transfer and maintain upon losing or changing employment
  • Requires the safeguarding and confidential treatment of protected health documents and information
  • Mandates standards and protocols for information with electronic billing, electronic claims, and other health care processes


A vital component of HIPAA is establishing national standards applicable to all electronic health care transactions. HIPAA also creates national identifiers for employers, providers, and health insurance plans. The intention of utilizing standards is to drastically improve the efficiency and capabilities of the health care system nationally. The use of standards in the health care industry is now ubiquitous.HIPAA mandates that all covered entities that electronically transmit data must use the electronic data interchange (EDI) protocol X12. The health care industry knows this mandate as the EDI Rule. X12 specifies how the industry is to send data electronically and precisely how all data is to be formatted. Before HIPAA, there were hundreds of different formats for data being transmitted. Now healthcare data is transmitted in a single universal format.The organizations affected by the EDI Rule include health car providers and clearinghouses that transmit any health information electronically as well as health plans. Self-funded group health plans to encompass less than 50 members are exempt. Self-administered health plans are also exempt. While not all healthcare providers are required to implement EDI, if they electronically transmit health care information, including claims, they are bound by the EDI Rule and must comply.Typical electronic health care transactions such as health care claims (837), health care claim payment/advice (835), benefit enrollment and maintenance (834), health care eligibility/benefit inquiry (270) and many more are mandated and sent by healthcare companies formatted with X12 and sent via EDI. The result is a more efficient health care system with reduced administrative overhead and increased accessibility and portability of health care data and documents.


An organized civil penalty structure for violations of HIPAA was signed into law in 2009 with the American Recovery and Reinvestment Act (ARRA). Penalties are at the discretion of the Secretary of the Department of Health and Human Services. Except in instances of willful neglect, the Secretary is prohibited from enforcing civil penalties corrected within 30 days. The Secretary bases the extent of penalties on the scope and nature of violations and often include substantial fines and possible prison sentences (fraudulent use os medical information).The penalties for willful violations are much heavier than unknowingly violating HIPAA.Range of HIPAA violations penalties:

  • An individual that unknowingly violates HIPAA (and even if exercising reasonable diligence, it is likely the violation would have occurred) is subject to a minimum of $100 per violation, not to exceed $25,000 annually and a maximum penalty of $50,000 per violation, not to exceed $1.5 million annually
  • Uncorrected violation due to willful neglect carries an equal minimum and maximum penalty of $50,000 per violation, not to exceed $1.5 million annually

A great way to ensure HIPAA compliance is to outsource your EDI service to a Value-added Network (VAN). BOLD VAN is not only a user-friendly EDI provider, we are HIPAA and X12 experts and stay current on all HIPAA mandates and topics related to EDI.

Nicole Wilson
Content Manager

Latest articles

April 10, 2024

Accent Your ERP Installation Services with BOLD VAN: The Ultimate Value-Added Network Solution

Does your client need a value-added network? Partnering with BOLD VAN can enhance your ERP installation services.

March 27, 2024

Streamline Your Salesforce Operations: BOLD VAN's Seamless EDI Integration Solution

Integrating BOLD VAN's EDI solution with Salesforce empowers your business with increased efficiency, streamlined workflows, and elevated customer service, ultimately driving growth and success.

February 29, 2024

Top EDI Providers: Streamline Supply Chains with BOLD VAN's ERP Integration

Discover seamless EDI integration for your ERP or TMS software with BOLD VAN. Optimize supply chain efficiency, boost productivity, and enhance communication with our top-tier electronic data interchange (EDI) services.

Achieve more from your EDI VAN provider.