COMDTINST 6000.8 — Health Insurance Portability And Accountability Act (hipaa) Privacy Rule Compliance In Cg Health Care Programs

COMDTINST 6000.8 governs HIPAA Privacy Rule compliance in Coast Guard health care programs and the protection of health information.

Search COMDTINST 6000.8

  • Publication number: COMDTINST 6000.8
  • Title: HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) PRIVACY RULE COMPLIANCE IN CG HEALTH CARE PROGRAMS
  • Date: 4/30/2024
  • Proponent: CG-1K2

View COMDTINST 6000.8 on armypubs.army.mil


It addresses PHI uses and disclosures, authorization requirements, privacy incidents, breaches, definitions, and military command exceptions. It requires designated privacy and security officers and establishes procedures for handling protected health information.

Topics covered

  • HIPAA Privacy Rule compliance
  • Protected health information
  • PHI uses and disclosures
  • HIPAA authorization requirements
  • Privacy incidents and breaches
  • Military command exception
  • HIPAA privacy and security officers

Questions and answers

What health information does the HIPAA Privacy Rule protect?

HIPAA’s Privacy Rule protects individually identifiable health information (called Protected Health Information (PHI)) that is held or transmitted by a covered entity (CE) or its business associate(s) (BA), in any form or media, whether electronic, paper, or oral. (paragraph 5)

Can a healthcare provider disclose a service member’s PHI to military command authorities?

Under the Military Command Exception, a healthcare provider may disclose the PHI of service members for authorized activities to appropriate military command authorities.

What is a privacy incident involving personally identifiable information?

The term encompasses both suspected and confirmed incidents involving PII, whether intentional or inadvertent, which raises a reasonable risk of harm.

When is health information not individually identifiable health information?

Health information that does not identify an individual and there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information. (paragraph 7)

What is a HIPAA complaint?

A written statement submitted to a CG CE’s HIPAA privacy officer or to the HHS Office for Civil Rights alleging that the CG CE has violated an individual's health information privacy rights or committed a violation of the HIPAA Privacy or Security Rule provisions.

Ask Reggie.Bot a question about COMDTINST 6000.8