Inquiries, Illuminated
-
Yes we accept a variety of Insurances, Reach out to see if your insurance is one of the ones we work with.
-
Your initial appointment is 90 minutes. During this session we explore your reasons for seeking therapy, begin to formulate the goals you want to work on, and discuss recommended next steps.
-
HIPAA (Health Insurance Portability and Accountability Act) — Overview and What Insurers Require in Georgia
HIPAA basics
Purpose: HIPAA is a federal law that protects the privacy and security of individuals’ protected health information (PHI) and provides standards for electronic health care transactions.
Key rules: The Privacy Rule (limits uses and disclosures of PHI), the Security Rule (sets standards for safeguarding electronic PHI), the Breach Notification Rule (requires notification after unsecured PHI breaches), and provisions governing transactions and code sets.
Covered entities and business associates: Covered entities include health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with certain transactions. Business associates are persons or organizations that perform services for covered entities that involve access to PHI; they must sign business associate agreements (BAAs) and comply with applicable HIPAA requirements.
PHI and permissible uses/disclosures
PHI includes any individually identifiable health information in any form (paper, electronic, oral) related to past, present, or future physical or mental health, provision of health care, or payment for health care.
Permitted uses/disclosures without patient authorization include treatment, payment, and health care operations; certain public health activities; reporting of abuse/neglect as required by law; and other limited exceptions.
Authorizations are required for most uses or disclosures beyond those permitted by the Privacy Rule.
Georgia-specific considerations
Federal HIPAA law applies in Georgia; providers and insurers operating in Georgia must comply with HIPAA’s requirements.
State law may provide greater privacy protections than HIPAA; when state law is more protective, the state law controls. Georgia statutes and regulations related to confidentiality of medical records, mental health records, substance use disorder records, HIV/AIDS status, and minor consent may impose additional restrictions on disclosure and require special handling or written authorization.
Examples of Georgia-specific protections:
Mental health and behavioral health records: Georgia law includes confidentiality protections that can limit disclosures; providers should verify state statutes and agency rules when handling psychotherapy notes and other behavioral health records.
Substance use disorder records: Federal 42 CFR Part 2, which often provides heightened protections for substance use treatment records, may apply in addition to HIPAA. Part 2 generally requires patient consent for disclosures of substance use treatment records, with limited exceptions.
HIV/AIDS-related information: Georgia law imposes confidentiality protections for records revealing HIV status and requires specific consent for disclosure in many circumstances.
Minor consent and parental access: Georgia law governs minors’ ability to consent to certain types of treatment (e.g., reproductive health, substance use treatment) and may affect parental access to records. Providers should review which services minors may consent to without parental involvement and how that affects access to PHI.
Insurance requirements — what insurers typically require in Georgia (legal and practical considerations)
Credentialing and enrollment: Insurers require providers to complete credentialing, supply licensing and malpractice insurance documentation, and attest to compliance with applicable laws (including HIPAA).
Business Associate Agreements (BAAs): Insurers (as health plans or covered entities) must have BAAs with business associates who handle PHI on their behalf. Providers and vendors must execute BAAs when exchanging PHI with insurers or payors.
Privacy and security safeguards: Insurers expect contracted providers and vendors to implement appropriate administrative, physical, and technical safeguards for PHI consistent with HIPAA Security Rule requirements. This includes risk assessments, workforce training, access controls, encryption where appropriate, and incident response policies.
Notice of Privacy Practices (NPP): Many insurers require providers to maintain and provide a Notice of Privacy Practices to patients, describing how PHI is used and disclosed and patient rights under HIPAA.
Reporting breaches and incidents: Contracts commonly require prompt reporting to the insurer of any security incident or breach affecting PHI that may impact claims, billing, or the insurer’s members.
Data use and disclosure limitations: Insurers may impose contractual limits on the use and disclosure of PHI beyond HIPAA minima, particularly for sensitive conditions. Contracts frequently specify permissible uses for claims processing, care coordination, quality improvement, and audit.
Minimum necessary standard: Insurers expect providers and vendors to adhere to the HIPAA minimum necessary standard, limiting PHI disclosed to what is reasonably necessary for the purpose.
Compliance documentation and audits: Insurers may require evidence of HIPAA compliance measures — policies, training records, risk assessments, and audit access — and may perform audits or reviews.
State-specific licensing and reporting: Insurers expect compliance with Georgia statutory reporting obligations (e.g., reporting certain communicable diseases, abuse, or adverse events) and may require notice or cooperation in regulatory matters.
Practical steps for Georgia providers and insurers to ensure compliance
Conduct a comprehensive HIPAA risk assessment and document remediation steps.
Implement
-
Currently is 2–3 days and can change based on availability.