HIPAA
The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) established national standards for electronic healthcare transactions and for the security and privacy of healthcare data. It also required national identifiers for providers, health plans, and employers. The goal was to reduce costs and improve the efficiency of the healthcare system by standardizing and encouraging the electronic exchange of data. The initial compliance deadlines for most of the provisions in HIPAA have passed.
What has Quadax done to ensure HIPAA compliance?
As a business entrusted with patient health information and required to distribute that information electronically to other business partners, we understand our obligations under the HIPAA statute. We have made every effort to conform to those rules and regulations by modifying business procedures and computer systems to incorporate compliance requirements by the specified deadlines.
Transaction Standards and Code Sets. Quadax is using the standard ICD ©, CPT ©, and HCPCS codes on electronic transactions, and all transactions are Claredi certified. Most payers have been converted to the ANSI 4010 A1 format, but the conversion process is still in progress for some payers according to their schedule for readiness.
Privacy Standards. Quadax has established internal guidelines and procedures to assure that no individual protected health information is disclosed except to authorized parties. Formal policies govern the conduct of employees regarding the confidentiality of patient information and specify penalties associated with breaches of such conduct.
Identifiers. National identifiers for employers are currently used on standard transactions. We have made the necessary program changes to our systems that have enabled the implementation of National Provider Identifiers (NPI). The rules have not been published for payer and individual identifiers.
Security. The Quadax HIPAA Security Official is Gene Calai. Quadax has implemented the following measures to prevent unauthorized access to protected health information.
- Administrative procedures. Our HIPAA Security Official has established formal procedures regarding the security of protected data.
- Physical safeguards. Quadax uses Halon
® fire protection systems for computer protection, fireproof vaults for data media storage, and off-site storage for backup media. These systems are inspected and updated regularly. Building protection includes locked entry doors controlled by passkey entry and video surveillance. - Technical measures. The software used for our healthcare billing and clearinghouse operations has multi-level operator security controls and transaction logging with audit trails of activity. The Quadax Web site uses Thawte
® SSL encryption technology to protect the transmission of data over the Internet. Unauthorized access to data from outside the Quadax network is prevented by a firewall.

