HIPAA Transactions and Code Sets: Standards, NPI, and Penalties

The HIPAA transaction and code set rules, found at 45 CFR Part 162, require health plans, healthcare clearinghouses, and providers who bill electronically to use standardized formats and standardized medical code sets when they exchange routine administrative information such as claims, eligibility checks, payments, and prior authorizations.1eCFR. 45 CFR Part 162 – Administrative Requirements Non-compliance is enforced by CMS and can trigger civil money penalties reaching $2,190,294 in a single calendar year for identical violations.2Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

Who Has to Comply

Three categories of “covered entities” fall under the rules. Health plans, including private insurers, HMOs, employer-sponsored plans, Medicare, and Medicaid. Healthcare clearinghouses, meaning the intermediaries that translate between standard and non-standard formats. And healthcare providers, but only those who transmit health information electronically in connection with a transaction for which HHS has adopted a standard.3HHS.gov. Covered Entities and Business Associates

Business associates are pulled in through their contracts. If a covered entity uses an outside billing company, claims processor, or other vendor that handles protected health information on its behalf, that vendor must meet the same transaction and code set requirements, and the covered entity has to document the arrangement in a business associate agreement.3HHS.gov. Covered Entities and Business Associates

A boundary worth knowing: small providers can still bill Medicare on paper. The Administrative Simplification Compliance Act generally bars Medicare from paying non-electronic claims, but HHS must grant a waiver to institutional providers with fewer than 25 full-time equivalent employees and to physicians and suppliers with fewer than 10 FTEs. Providers who average under 10 claims per month over a calendar year also qualify, as do individual beneficiaries filing on their own behalf.4Centers for Medicare & Medicaid Services. Administrative Simplification Compliance Act Self Assessment5U.S. Department of Health and Human Services ASPE. HIPAA Administrative Simplification Compliance Act – Frequently Asked Questions

Which Transactions Must Use a Standard Format

Most standardized transactions use formats from the Accredited Standards Committee X12N, currently at Version 5010.6Centers for Medicare & Medicaid Services. Adopted Standards and Operating Rules The adopted transactions are:

  • Health claims, including coordination-of-benefits claims involving multiple payers, using the X12N 837.
  • Eligibility verification, using the X12N 270/271.
  • Claim status inquiries, using the X12N 276/277.
  • Payment and remittance advice from plans to providers, using the X12N 835.
  • Prior authorization and referral certification requests, using the X12N 278.
  • Enrollment and disenrollment in a health plan, using the X12N 834.
  • Employer premium payments to health plans, using the X12N 820.

Retail pharmacy is the major exception. Pharmacy claims run on the NCPDP Telecommunication Standard Implementation Guide Version D.0, which defines the real-time record layout between pharmacies and drug plan adjudicators. That standard was adopted in the 2009 modification rule with a January 2012 compliance deadline.6Centers for Medicare & Medicaid Services. Adopted Standards and Operating Rules

There is also a direct-data-entry exception. If a provider keys transaction data into a health plan’s web portal instead of transmitting a formatted electronic file, the format requirements of the standard do not apply. The data content and data condition requirements still do. You can type into the plan’s form, but what you type has to match what the standard demands.1eCFR. 45 CFR Part 162 – Administrative Requirements

Which Code Sets You Must Use

Code sets are the standardized vocabularies inside every transaction. HIPAA mandates six:7Centers for Medicare & Medicaid Services. Code Sets Overview

One rule inside the rule catches billing departments regularly: covered entities must use the code that was valid at the time the care was provided, not the code that happens to be valid when the claim is submitted.1eCFR. 45 CFR Part 162 – Administrative Requirements That matters because the code sets update on fixed cycles. ICD-10-CM and ICD-10-PCS update every October 1, aligned with the federal fiscal year; the current ICD-10-CM guidelines run October 1, 2025 through September 30, 2026.8Centers for Medicare & Medicaid Services. ICD-10-CM Official Guidelines for Coding and Reporting FY 2026 CPT and HCPCS update every January 1. Not switching over on the effective date is itself a compliance problem.

The National Provider Identifier

Every covered healthcare provider must use a National Provider Identifier in all HIPAA standard transactions. The NPI is a unique 10-digit number with no embedded information about specialty, location, or anything else about the provider. Health plans and clearinghouses must accept and use NPIs when processing transactions.10Centers for Medicare & Medicaid Services. National Provider Identifier Standard

Operating Rules Layered On Top

Operating rules address the practical questions the transaction standards leave open. A transaction standard defines the format and data content of a message; an operating rule defines what has to happen in the business exchange around it. The Affordable Care Act made operating rules mandatory for certain HIPAA transactions.11CMS. Operating Rules Overview

For eligibility verification and claim status, operating rules require health plans to respond to providers in real time and to include specific financial details such as deductibles, copays, coinsurance, and in-network versus out-of-network differences. Plans must also provide secure online access to this information. These rules took effect January 1, 2013.12Centers for Medicare & Medicaid Services. Operating Rules for Eligibility and Claims Status Operating rules for electronic funds transfers and remittance advice followed on January 1, 2014.11CMS. Operating Rules Overview

Claims Attachments Rule Coming in 2028

A long-missing piece of the framework is being filled in. A March 2026 final rule adopts X12 Version 6020 standards for healthcare claims attachment transactions. Under the new rule, health plans will use a standardized X12N 277 to request additional information from a provider, and providers will respond with an X12N 275. The rule takes effect May 26, 2026, with covered entity compliance required by May 26, 2028. Small health plans get no extended compliance window here, unlike some earlier HIPAA standards, and pharmacies are generally unaffected.13Federal Register. Administrative Simplification – Adoption of Standards for Health Care Claims Attachments Transactions and Electronic Signatures

Penalties for Non-Compliance

CMS enforces the rules by investigating complaints filed through its ASETT portal. Anyone who believes a covered entity is failing to meet a transaction, code set, identifier, or operating rule requirement can file a complaint. When CMS finds a violation, it first requests corrective action; if the entity does not fix the problem, CMS can impose civil money penalties.14Centers for Medicare & Medicaid Services. HIPAA Administrative Simplification Frequently Asked Questions

Penalties follow a four-tier structure based on culpability. The most recent inflation-adjusted amounts are:2Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Did not know and could not reasonably have known: $145 to $73,011 per violation, with a calendar-year cap of $2,190,294 for identical violations.
  • Reasonable cause, not willful neglect: $1,461 to $73,011 per violation, same annual cap.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, with a calendar-year cap of $2,190,294.

The per-violation numbers in the lower tiers look modest, but violations stack. A single coding error repeated across thousands of claims can be counted separately on each claim, reaching the annual cap quickly. Add the staff time and legal cost of working through the enforcement process itself, and the real exposure of a systemic problem runs well past the check written to the government.