HIPAA - Health Insurance Portability and Accountability Act Practice Test

โ–ถ

HIPAA privacy violations occur when a covered entity or business associate fails to safeguard protected health information (PHI) in the ways required by the Health Insurance Portability and Accountability Act. These violations range from a nurse casually mentioning a patient's diagnosis in a hallway to a hospital failing to encrypt thousands of electronic records stored on an unprotected server. Regardless of size or intent, hipaa privacy violations trigger federal scrutiny and can result in financial penalties, corrective action plans, and lasting reputational harm.

HIPAA privacy violations occur when a covered entity or business associate fails to safeguard protected health information (PHI) in the ways required by the Health Insurance Portability and Accountability Act. These violations range from a nurse casually mentioning a patient's diagnosis in a hallway to a hospital failing to encrypt thousands of electronic records stored on an unprotected server. Regardless of size or intent, hipaa privacy violations trigger federal scrutiny and can result in financial penalties, corrective action plans, and lasting reputational harm.

The Privacy Rule, which took effect in April 2003, establishes national standards for how individually identifiable health information must be used, disclosed, and protected. It covers not just large hospital systems but also solo-practice physicians, health insurance plans, pharmacy chains, and the business associates โ€” billing companies, IT vendors, cloud storage providers โ€” that handle PHI on their behalf. Understanding what the rule requires is the first step toward building a compliant organization.

Violations can be accidental or intentional, but the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services evaluates both categories with equal seriousness. An unintentional disclosure caused by a misconfigured email server may attract lower penalties than deliberate snooping into a celebrity's medical record, but neither is automatically excused. The law imposes an affirmative duty to prevent foreseeable harm, and "we didn't mean to" rarely satisfies regulators when basic safeguards were absent.

The financial exposure can be staggering. OCR can impose civil monetary penalties of up to $2,067,813 per violation category per calendar year under the tiered structure updated in 2023. Criminal penalties under the Department of Justice can add prison time on top of fines. Beyond federal action, many state attorneys general have independent authority to pursue HIPAA violations on behalf of their residents, creating the possibility of parallel enforcement proceedings that compound liability.

Healthcare organizations often underestimate how broad the definition of PHI is. It includes not only obvious items like diagnoses and treatment records but also appointment schedules, billing histories, insurance ID numbers, and even photographs from which a patient could be identified. If any of these data elements are linked โ€” or even linkable โ€” to a specific individual, they qualify as PHI and must be treated with full HIPAA-level protections.

Workforce behavior drives a surprisingly large share of privacy incidents. Employees sending PHI to personal email accounts for convenience, staff texting patient information over unsecured messaging apps, or workers accessing records of friends and family members out of curiosity โ€” all of these constitute violations that covered entities are responsible for preventing through training, technical controls, and disciplinary policies.

This article walks through the most common categories of HIPAA privacy violations, explains how OCR investigates and penalizes them, and provides practical strategies that healthcare professionals and compliance officers can use to reduce risk. Whether you are studying for a certification exam or working in a healthcare setting where PHI flows daily, the concepts here are foundational to understanding how American health privacy law operates in practice.

HIPAA Privacy Violations by the Numbers

๐Ÿ’ฐ
$2M+
Max Annual Penalty Per Violation Category
๐Ÿ“Š
60%
of Breaches Involve Unauthorized Access
๐Ÿ‘ฅ
500+
Records Trigger Mandatory OCR Reporting
โš ๏ธ
4 Tiers
Civil Penalty Categories
๐Ÿ”„
10 Years
Record Retention Requirement
Test Your Knowledge of HIPAA Privacy Violations

Most Common Types of HIPAA Privacy Violations

๐Ÿ”“ Unauthorized Disclosures

Sharing PHI with individuals who have no treatment, payment, or healthcare operations need โ€” including disclosures to family members without patient authorization, posting information on social media, or discussing cases in public areas where others can overhear.

๐Ÿšซ Failure to Provide Patient Access

Denying or unreasonably delaying a patient's request to access or obtain copies of their own medical records. OCR has made right-of-access enforcement a top priority, issuing dozens of fines exceeding $10,000 for straightforward denials.

๐Ÿ›ก๏ธ Inadequate Safeguards for PHI

Failing to implement technical, administrative, or physical safeguards โ€” such as leaving paper records unsecured, transmitting unencrypted PHI over public Wi-Fi, or neglecting to install software patches on systems storing electronic health records.

๐Ÿ“ฃ Impermissible Use of PHI for Marketing

Using a patient's PHI for marketing communications without obtaining a valid HIPAA authorization. This includes selling patient lists, targeting patients with third-party ads based on their health conditions, and promotional communications disguised as treatment information.

๐ŸŽ“ Insufficient Workforce Training

Employees who have not received adequate HIPAA training regularly cause violations through careless handling of PHI. Covered entities are liable for workforce violations when training programs are absent, outdated, or not documented with completion records.

When a complaint is filed or a breach is reported, the Office for Civil Rights opens a preliminary review to determine whether the allegations fall within its jurisdiction. OCR has authority over covered entities โ€” health plans, healthcare clearinghouses, and most healthcare providers โ€” as well as their business associates. If the respondent does not qualify as a covered entity or business associate, OCR closes the case without further action, but it may refer the matter to another agency with applicable authority.

Once jurisdiction is confirmed, OCR sends a notification letter to the covered entity and requests documentation: policies and procedures, training records, relevant correspondence, system logs, and any breach notification materials already submitted. This document-gathering phase can last several months, and organizations that fail to respond promptly risk additional findings of noncompliance layered on top of the original allegation. Cooperation is not optional โ€” HIPAA explicitly requires covered entities to allow OCR access to records and facilities during an investigation.

OCR investigators then compare the documented practices against the specific Privacy Rule requirements implicated by the complaint. For example, if a patient alleges that their records were shared with an employer, investigators will look at workforce training logs, the minimum necessary standard policies, and any authorizations on file. If the facts support a violation, OCR moves into the resolution phase, which can take the form of an informal resolution, a corrective action plan, or formal civil monetary penalty proceedings.

Informal resolution is by far the most common outcome. Under this approach, the covered entity agrees to implement specific corrective measures โ€” updating policies, retraining staff, adding technical safeguards โ€” and demonstrates compliance within a defined timeframe. OCR closes these cases with a resolution letter rather than a financial penalty. Many organizations view this as the best possible outcome, but it still creates a compliance record and may signal to OCR that deeper scrutiny is warranted if future complaints arise.

When informal resolution is not appropriate โ€” typically because the violation is serious, systemic, or the organization is uncooperative โ€” OCR issues a Notice of Proposed Determination that specifies the penalty amount and the legal basis for it. The covered entity then has thirty days to request a hearing before an administrative law judge. This formal adjudication process can take years, and many organizations negotiate a settlement before it concludes, resulting in a Resolution Agreement and Corrective Action Plan that is publicly posted on OCR's website.

State attorneys general also have independent authority under HIPAA to bring civil actions on behalf of their residents. Several states have exercised this power, adding a second layer of enforcement risk. A hospital that settles with OCR may still face state-level proceedings if the underlying breach affected residents of a state whose attorney general is actively pursuing HIPAA enforcement. Organizations operating across multiple states must therefore monitor enforcement trends at both the federal and state level simultaneously.

The breadth and depth of an OCR investigation can surprise organizations that assumed a single complaint would result in a narrow review. Investigators have discretion to expand scope if they discover evidence of systemic problems during the course of examining a specific allegation. A complaint about one denied record request can open the door to a facility-wide audit of access request procedures, potentially uncovering dozens of additional violations that compound the original exposure significantly.

Free HIPAA Compliance Questions and Answers
Practice essential HIPAA compliance rules with real exam-style questions and detailed answer explanations.
Free HIPAA Medical Information Questions and Answers
Test your understanding of how HIPAA protects medical information across covered entities and their partners.

HIPAA Privacy Violation Penalty Tiers Explained

๐Ÿ“‹ Tier 1: Unknowing

Tier 1 applies when the covered entity did not know, and by exercising reasonable diligence would not have known, that the act or omission constituted a violation. The minimum penalty is $137 per violation, with an annual cap of $34,464 for identical violations in a calendar year. This tier is reserved for organizations that had reasonable safeguards in place but still experienced an isolated, unforeseeable incident โ€” for example, a misdirected fax sent to a wrong number despite a verified contact list.

Even at Tier 1, organizations cannot simply assume the minimum will apply. OCR evaluates the totality of the compliance program, and an organization with weak overall safeguards may find OCR categorizing the same incident at a higher tier on the grounds that better controls would have prevented it. Documenting a robust, proactive compliance program is therefore essential even before any violation occurs, because that documentation is exactly what OCR will review when assessing culpability tier.

๐Ÿ“‹ Tier 2: Reasonable Cause

Tier 2 covers violations where the covered entity knew, or should have known through reasonable diligence, that an act or omission constituted a violation โ€” but where the violation did not rise to the level of willful neglect. Minimum penalties start at $1,379 per violation, with an annual cap of $68,928. A typical Tier 2 scenario involves a covered entity that received prior warnings about a compliance gap โ€” perhaps through a workforce complaint or internal audit โ€” but failed to address it in a timely manner before a violation occurred.

OCR often finds Tier 2 violations when organizations lack updated policies or have documented training requirements that employees demonstrably did not complete. The reasoning is straightforward: a healthcare organization in the business of handling sensitive information is expected to know the basic requirements of the law governing that information. Gaps that persist after internal red flags are discovered signal reasonable cause even if the organization never intended to violate the Privacy Rule.

๐Ÿ“‹ Tier 3 & 4: Willful Neglect

Willful neglect violations are divided into two sub-tiers based on whether the covered entity corrected the problem after discovery. Tier 3 โ€” willful neglect corrected within 30 days โ€” carries a minimum of $13,785 per violation and an annual cap of $137,844. Tier 4 โ€” willful neglect not corrected โ€” has a minimum of $68,928 per violation and an annual cap of $2,067,813. OCR is required by statute to impose penalties for willful neglect; it has no discretion to waive them, unlike Tiers 1 and 2.

Willful neglect means conscious, intentional failure or reckless indifference to the obligation to comply with HIPAA. Examples include ignoring repeated breach reports from employees, selling PHI to third parties without authorization, or refusing to implement any access controls despite clear regulatory requirements. Organizations found in willful neglect often face parallel criminal referrals to the Department of Justice, where individuals responsible for the conduct may face up to ten years in federal prison under the most serious criminal provisions.

Reporting a HIPAA Privacy Violation: Benefits and Risks

Pros

  • Self-reporting may demonstrate good faith and lead to reduced OCR penalties
  • Early disclosure allows the organization to control the narrative before media coverage
  • Breach notification to patients fulfills a legal obligation and preserves trust
  • Reporting triggers internal investigation that often uncovers additional vulnerabilities
  • Cooperation with OCR typically shortens the investigation timeline significantly
  • Documented self-reporting creates a compliance record that can mitigate future enforcement

Cons

  • Self-reporting alerts OCR to a violation it might not otherwise have discovered
  • Formal OCR investigations can last years and consume substantial staff resources
  • Resolution Agreements are publicly posted and can attract negative media attention
  • Patients notified of a breach may file individual complaints or pursue state-law claims
  • Corrective Action Plans require ongoing monitoring and periodic progress reports to OCR
  • Financial penalties, even at Tier 1, can strain budgets at smaller covered entities
HIPAA De-identification and Data Anonymization
Master the Safe Harbor and Expert Determination methods for removing PHI identifiers under HIPAA rules.
HIPAA Electronic Health Records (EHR) Compliance
Test your knowledge of EHR security requirements, audit logs, access controls, and electronic PHI protections.

HIPAA Privacy Compliance Checklist for Covered Entities

Designate a Privacy Officer responsible for developing and implementing HIPAA policies.
Conduct an annual risk analysis covering all systems that create, receive, maintain, or transmit PHI.
Train all workforce members on HIPAA Privacy Rule requirements within 30 days of hire and annually thereafter.
Establish and document minimum necessary standards for all routine PHI uses and disclosures.
Obtain signed Business Associate Agreements with every vendor that accesses or processes PHI.
Post a current Notice of Privacy Practices in the facility and on the organization's public website.
Implement a written process for patients to request access to their records and respond within 30 days.
Log all PHI disclosures that are not for treatment, payment, or healthcare operations for the six-year accounting period.
Maintain a breach response plan and test it at least annually with tabletop exercises.
Document all sanctions applied to workforce members who violate privacy policies.
Patients Have 30 Days โ€” Not 30 Business Days

OCR's right-of-access initiative has produced more than 50 enforcement actions since 2019, with fines ranging from $3,500 to $240,000. Covered entities must provide patients with a copy of their records within 30 calendar days of the request, with one 30-day extension if the records are not readily available. Charging excessive fees or refusing to send records to a third party designated by the patient are among the most common triggers for right-of-access complaints filed with OCR.

Preventing HIPAA privacy violations requires a layered approach that addresses people, processes, and technology simultaneously. No single safeguard is sufficient on its own. An organization may invest heavily in encryption and access controls but still suffer a violation because a workforce member intentionally bypassed those controls to access a family member's records. Conversely, a culture of strong privacy awareness can compensate for gaps in technical infrastructure, at least temporarily, but will eventually fail without supporting systems.

Workforce training is the most consistently cited corrective action in OCR resolution agreements, which means it is also the most consistently missing element in organizations that experience violations. Effective training goes beyond distributing a policy document and collecting signatures. It should use realistic scenarios drawn from the organization's own work environment, cover the specific types of PHI employees encounter daily, and test comprehension rather than just exposure. Training records must be retained for six years and made available to OCR on request.

Technical safeguards for electronic PHI include access controls that limit system access to authorized users based on their job function, audit controls that log and examine activity in systems containing ePHI, integrity controls that ensure ePHI is not improperly altered or destroyed, and transmission security that guards ePHI moving across networks. While encryption is not explicitly required by the Security Rule, OCR treats failure to encrypt as a significant risk factor, and unencrypted portable devices are responsible for a disproportionate share of large breaches reported on the OCR breach portal.

Physical safeguards are equally important and often overlooked. Workstation use policies should specify that screens displaying PHI must be positioned away from waiting areas and public spaces. Visitors to clinical areas should be escorted or supervised. Paper records must be stored in locked areas when not in use, and document disposal must use cross-cut shredding or locked shred bins serviced by certified destruction vendors. Many violations reported to OCR involve paper records that were improperly discarded โ€” found in dumpsters, recycling bins, or even sold at auction with equipment.

Business associate management is a persistent compliance challenge, particularly as healthcare organizations rely on an expanding ecosystem of cloud services, telehealth platforms, revenue cycle vendors, and health information exchanges. Each of these vendors must sign a Business Associate Agreement before receiving access to PHI, and covered entities must periodically verify that those vendors maintain adequate safeguards. Vendors who subcontract PHI work must in turn obtain Business Associate Agreements from their subcontractors โ€” a chain of accountability that is frequently broken in practice.

Minimum necessary is a foundational Privacy Rule principle that organizations frequently misapply. It requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose. This does not apply to disclosures for treatment purposes between healthcare providers, but it does apply to disclosures for payment, operations, and most other purposes. Implementing role-based access controls in EHR systems is a practical way to enforce the minimum necessary standard technically rather than relying solely on workforce judgment.

Incident response planning separates organizations that quickly contain breaches from those whose violations expand because of delayed or disorganized reactions. An effective plan identifies who is responsible for detecting, reporting, and assessing potential violations; establishes escalation paths and documentation requirements; and specifies the decision tree for determining whether a breach triggers the 60-day notification obligation to OCR and affected individuals. Organizations that run tabletop exercises at least annually consistently demonstrate faster and more effective responses to real incidents when they occur.

For healthcare professionals preparing for HIPAA certification exams or workforce compliance training, understanding the conceptual framework of the Privacy Rule is as important as memorizing specific requirements. Exam questions are frequently scenario-based, requiring test-takers to apply principles to realistic situations rather than simply recall definitions. The most productive study approach pairs careful reading of the actual regulatory text with practice questions that force application of those concepts to concrete fact patterns.

The Privacy Rule's structure revolves around a few core concepts that appear repeatedly in exam questions. PHI is the central object of protection โ€” any individually identifiable health information held by a covered entity or its business associates. The eighteen HIPAA identifiers that must be removed to achieve de-identification under the Safe Harbor method are a frequent exam topic, as are the conditions under which de-identified data loses its de-identified status upon re-linkage with external datasets.

Permitted uses and disclosures form the backbone of Privacy Rule analysis. The rule divides disclosures into those that are required (to the individual upon request or to OCR during compliance reviews), those that are permitted without authorization (for treatment, payment, healthcare operations, and a specified list of public interest purposes), and those that require a valid written authorization. Distinguishing between these three categories โ€” and knowing the specific conditions that apply to each โ€” is essential for both exam success and real-world compliance work.

The minimum necessary standard generates some of the most nuanced exam questions because its application varies by context. It applies to uses within the organization, disclosures to outside parties, and requests for PHI from other entities โ€” but not to disclosures to treating providers, disclosures to the patient, or disclosures authorized by the patient. Understanding these exceptions prevents the common mistake of applying minimum necessary too broadly or too narrowly in scenario questions.

Patient rights under the Privacy Rule are another high-yield exam area. Patients have the right to access and obtain copies of their PHI, to request amendments to records they believe are inaccurate, to receive an accounting of certain disclosures, to request restrictions on certain uses and disclosures, to request confidential communications, and to receive a Notice of Privacy Practices. Each right has specific conditions, timelines, and exceptions that exam questions probe systematically. Knowing not just what the right is but when it applies and when it can be legitimately denied is critical for accurate answers.

Business associate relationships are tested both conceptually and practically. Exam questions may ask you to identify whether a particular vendor qualifies as a business associate, what a compliant Business Associate Agreement must contain, or what happens when a business associate violates HIPAA. The 2013 Omnibus Rule made business associates directly liable for HIPAA compliance rather than merely contractually obligated โ€” a significant shift that frequently appears in exam content covering post-2013 regulatory developments.

One of the most effective study strategies for HIPAA exams is to work through OCR enforcement case summaries, which are publicly available on the HHS website. Each summary describes the facts of a real case, the specific Privacy Rule provisions violated, the corrective actions required, and the penalty imposed. These cases provide rich scenario material that mirrors the structure of exam questions and simultaneously builds the practical pattern recognition that healthcare professionals need in their actual work environments.

Practice HIPAA Medical Information Questions Now

Real-world HIPAA compliance looks different across the spectrum of covered entities. A large academic medical center may have a dedicated compliance department, a full-time Privacy Officer, a sophisticated EHR with granular role-based access controls, and a legal team that monitors OCR enforcement trends. A solo-practice dentist operating on thin margins may have one front-desk employee, paper records, and no formal compliance infrastructure whatsoever. Both are covered entities subject to identical Privacy Rule requirements, but the resources available for compliance look nothing alike.

Small practices face a disproportionate compliance burden relative to their resources, yet they also tend to face proportionally lower penalties when violations occur at Tier 1 or Tier 2 because OCR exercises discretion in calibrating penalties to the organization's financial condition. That discretion is not guaranteed, however, and it disappears entirely for willful neglect violations. Small practices that completely ignore HIPAA โ€” maintaining no policies, conducting no training, executing no Business Associate Agreements โ€” are exactly the organizations most likely to trip into the willful neglect category.

Health information technology vendors occupy a complex position in the HIPAA landscape. As business associates, they are directly liable for their own compliance failures under the Omnibus Rule. Software-as-a-service providers, cloud hosting companies, and electronic health record vendors routinely handle enormous volumes of PHI across thousands of covered entity clients. A single security vulnerability in a major EHR platform can simultaneously expose millions of patients' records across hundreds of hospital systems, creating breach notification obligations that cascade across the entire client base simultaneously.

The intersection of HIPAA with emerging technologies creates new compliance questions that the original 1996 statute could not have anticipated. Wearable health devices, remote patient monitoring platforms, AI-powered diagnostic tools, and consumer health applications all potentially create, receive, or transmit PHI in ways that may or may not bring their developers within HIPAA's regulatory scope. The line between a regulated health app and an unregulated wellness app is frequently unclear, and OCR has issued guidance attempting to draw those distinctions โ€” but new technologies continue to outpace regulatory clarity.

Social media presents a particularly acute risk area for healthcare workforce members. Posting a photo from inside a clinical facility can inadvertently capture patients in the background. Venting about a difficult case online โ€” even without using names โ€” can violate HIPAA if details are specific enough to identify an individual. Participating in online communities where healthcare workers share workplace stories can cross privacy lines with a single thoughtless comment. Covered entities should maintain explicit social media policies and include social media scenarios in annual workforce training.

Telehealth expansion following 2020 created a wave of new compliance questions around video platforms, remote prescribing, and interstate patient care. Platforms not covered by a Business Associate Agreement cannot be used for telehealth visits involving PHI, regardless of how popular or convenient they may be. The temporary enforcement discretion OCR exercised during the COVID-19 public health emergency permitted the use of non-HIPAA-compliant video platforms under specific conditions โ€” but that flexibility was time-limited and does not represent the permanent regulatory baseline that covered entities must maintain going forward.

Healthcare organizations that treat HIPAA compliance as a one-time checkbox exercise rather than an ongoing program consistently encounter the same pattern: initial compliance activities at implementation, followed by years of drift as policies become outdated, training lapses, and new risks emerge without corresponding controls. OCR investigators are skilled at identifying this pattern from documentation gaps, and the absence of recent updates to policies and training materials is itself a red flag that elevates scrutiny of the underlying conduct being investigated.

HIPAA Healthcare Provider Obligations and Covered Entities
Identify which providers qualify as covered entities and understand their specific HIPAA obligations under federal law.
HIPAA - Health Insurance Portability and Accountability Act Administrative Safeguards Questions and Answers
Practice HIPAA administrative safeguard requirements including workforce training, access management, and contingency planning.

HIPAA Questions and Answers

What is the most common type of HIPAA privacy violation?

Unauthorized disclosure of PHI to individuals without a permissible purpose is the most frequently reported violation type. This includes sharing patient information with family members without authorization, discussing cases in public areas, and sending PHI to the wrong recipient via email or fax. Impermissible disclosures account for the majority of complaints received by OCR annually, making workforce training on disclosure rules the highest-priority compliance investment for most covered entities.

How long does an OCR HIPAA investigation take?

OCR investigations vary widely in duration depending on complexity, volume of documentation, and whether the case resolves informally or proceeds to formal adjudication. Simple cases that resolve through technical assistance or informal resolution may close within a few months. Cases requiring corrective action plans typically take six to eighteen months. Formal civil monetary penalty proceedings involving an administrative law judge can take two to five years or longer before a final resolution is reached and publicly announced.

Can an individual sue for a HIPAA privacy violation?

HIPAA does not create a private right of action, meaning individuals cannot sue covered entities directly under the federal statute for privacy violations. Enforcement authority rests exclusively with OCR and the Department of Justice at the federal level, and with state attorneys general at the state level. However, a HIPAA violation may simultaneously constitute a violation of state privacy laws that do allow private lawsuits, so affected individuals can sometimes pursue civil remedies through state-law claims arising from the same underlying conduct.

What is the minimum necessary standard under HIPAA?

The minimum necessary standard requires covered entities to make reasonable efforts to limit the PHI they use, disclose, or request to the minimum amount needed to accomplish the intended purpose. It applies to internal uses, external disclosures, and requests for PHI from other entities. Key exceptions include disclosures for treatment between healthcare providers, disclosures to the patient, and disclosures specifically authorized by the patient. Covered entities must implement policies identifying the persons or classes of persons who need access to PHI for specific job functions.

What triggers mandatory breach reporting to OCR?

A breach of unsecured PHI must be reported to OCR when it affects 500 or more individuals โ€” within 60 days of discovery โ€” or when it affects fewer than 500 individuals, in which case the covered entity may log the breach and report it to OCR annually by March 1 of the following year. The notification obligation applies unless the breach falls within one of three exceptions: the information was unintentionally acquired by an authorized person, the disclosure was inadvertent between authorized persons, or the covered entity has a good-faith belief that the unauthorized person could not have retained the information.

Are business associates directly liable for HIPAA violations?

Yes. Since the 2013 Omnibus Rule, business associates are directly liable for their own HIPAA compliance failures, not merely contractually obligated to covered entities. OCR can investigate and penalize business associates directly, independent of any action against the covered entity that hired them. Business associates are required to comply with the Security Rule in its entirety and with specific provisions of the Privacy Rule, including the prohibition on using or disclosing PHI in ways that violate the rule or their Business Associate Agreement.

What are the 18 identifiers that must be removed for HIPAA de-identification?

The Safe Harbor de-identification method requires removal of 18 categories: names; geographic subdivisions smaller than a state; dates (except year) related to an individual; phone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate or license numbers; vehicle identifiers; device identifiers; web URLs; IP addresses; biometric identifiers; full-face photographs; and any other unique identifying number, characteristic, or code. After removing all 18 identifiers, the covered entity must also have no actual knowledge that the remaining information could identify an individual.

How does HIPAA apply to mental health records?

Mental health records are PHI and receive the same baseline protections as any other health information under HIPAA. However, psychotherapy notes receive heightened protection โ€” they are defined separately from the rest of the medical record and require a specific authorization for most uses and disclosures, even those that would otherwise be permitted for treatment, payment, or operations. Psychotherapy notes also cannot be compelled from covered entities in most legal proceedings without a court order or patient authorization, providing a stronger shield than ordinary medical records.

Can an employer access an employee's medical records under HIPAA?

Generally no. HIPAA restricts covered entities from disclosing PHI to employers without patient authorization. However, employers who sponsor self-insured group health plans are themselves covered entities with respect to that plan's PHI, and separate barriers must be maintained between the plan and the employer's human resources function. Employment-related medical examinations conducted by company physicians create a separate category governed partly by ADA rules. Employees who suspect their employer improperly accessed their medical information should file a complaint with OCR as well as consult state employment law remedies.

What should I do if I witness a HIPAA privacy violation at work?

Healthcare workforce members who witness a potential privacy violation should report it through their organization's internal compliance or Privacy Officer channel as the first step. Most covered entities maintain a compliance hotline or incident reporting system for exactly this purpose. If internal reporting is not available or has not produced results, individuals can file a complaint directly with OCR online at the HHS website within 180 days of discovering the violation. HIPAA prohibits covered entities from retaliating against workforce members who in good faith report a compliance concern.
โ–ถ Start Quiz