Is this form HIPAA compliant?
WIC is not a HIPAA Covered Entity and is governed by federal regulations related to Personally
Identifiable Information (PII). However, the WIC Referral System follows HIPAA protocols and
procedures for data collection and storage.
The application that stores the information entered into this form meets the security requirements
required for HIPAA. Access to referral data is obtained through an electronic application. This
application has role-based access and is only seen by WIC staff who would be following up with
referrals or monitoring referral progress for WIC. This application is hosted across the web on a SSL
(Secure Socket Layer Line) and the information is stored on a database that is within a classified
network of servers hosted currently at eFort. This classified architecture only hosts applications that
involve PII and PHI datasets.
In regards to a medical practitioner entering data for referral, the HIPAA Privacy Rule allows those
doctors, nurses, hospitals, laboratory technicians, and other health care providers that are covered
entities to use or disclose protected health information, such as X-rays, laboratory and pathology
reports, diagnoses, and other medical information for treatment purposes without the patient’s
authorization. This includes sharing the information to consult with other providers, including
providers who are not covered entities, to treat a different patient, or to refer the patient (i.e.
referral to WIC). See 45 CFR 164.506.