No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

HIPAA’s Privacy Rule Is 20 Years Old. Why Do Organizations Keep Breaking It?

Reported privacy rule violations climbed nearly 25% in 2021

by Staff and Wire Reports
June 28, 2023
in Compliance
medical records hipaa

The pandemic showed us that large numbers of Americans don’t really understand HIPAA and what protections it provides consumers despite the fact that it’s been around for decades. While one could forgive ignorance on the part of people who don’t deal with HIPAA requirements every day, it’s less forgivable when organizations to which the law applies seem ignorant of it. Still, federal data shows that reported violations of HIPAA’s privacy rule climbed by nearly 25% in the most recent year. What types of violations are still happening — and how can they be avoided?

Regulators began enforcing HIPAA’s privacy rule for healthcare insurers and providers in 2003. Since then, more than 300,000 complaints of rule violations have been alleged and more than 1,700 matters have been referred to the DOJ for possible criminal investigation.

Despite protocols designed to protect patients and organizations, HIPAA violations continue to occur frequently. Even healthcare organizations that diligently follow HIPAA regulations can be vulnerable to unintentional violations, which can lead to harm to patients, costly penalties, reputational damage and legal action. Authorities have imposed fines totaling $134 million since regulators began enforcing HIPAA’s privacy rule.

The most commonly reported violations in 2021 (the most recent year for data) were: impermissible use and disclosures, access, safeguards, administrative safeguards and breach notifications. Here are some tips for organizations to remain compliant with HIPAA’s privacy regulations.

A masked professional holds up their covid-19 vaccination card.
Compliance

‘My Employer Can’t Ask for Proof of Vaccination’ and Other Myths Regarding COVID-19 and HIPAA

by K Royal
September 7, 2021

When it comes to COVID-19 and HIPAA, many misunderstand the law’s scope and purview, especially in a professional setting. Privacy attorney K Royal dispels common misconceptions within.

Read moreDetails

Information disclosure

As we said, most unintentional HIPAA violations are due to an organization accidentally accessing or releasing protected health information (PHI). For example, employees discussing PHI in the breakroom or with friends and family is a HIPAA violation. 

Conversations that include sensitive information should be limited to those who are authorized to hear it. These conversations should take place in a private place that is not accessible to unauthorized personnel. Other tips for protecting PHI:

  • Implement appropriate employee training and management data solutions that require authorization codes or identity verification.
  • Implement employee email and cybersecurity training and best practices. Disclosing PHI to unauthorized personnel can occur by CCing multiple patients in one email, sending PHI to the wrong patient or disclosing PHI on social media. 
  • Verify what information is being requested before transmitting it. Even when the correct patient record is provided, if the individual has authorized only parts of their medical record to be disclosed but the entire record was shared, that’s a violation.

Device loss

Another common way for PHI to be accessed by unauthorized individuals is through misplaced or stolen devices like laptops, USB drives, tablets and smartphones. Devices from healthcare organizations typically contain sensitive patient information.

Healthcare professionals often take work devices home and leave them unattended in their home, car or public areas. This creates a situation where these devices can easily be stolen, lost or accessed by unauthorized individuals.

Best practices to prevent PHI disclosure in the event of a lost or stolen device include:

  • Device encryption
  • Electronic PHI (ePHI) encryption
  • Device tracking software
  • Training around device handling
  • Password protection
  • Activity monitoring of systems and devices
  • Multi-factor authentication

Improper disposal of sensitive patient information

Failing to dispose of PHI and ePHI properly, including throwing away complete copies of PHI without shredding it or failing to wipe ePHI from USBs or portable hard drives, is a HIPAA violation. 

Healthcare organizations should routinely conduct shredding or pulping of physical copies of PHI and destroy or wipe portable devices that store PHI.

Third-party risk

Nearly all healthcare organizations work with third-party companies, with many requiring access to PHI. Any company that has access to or handles PHI is required to be HIPAA-compliant. Third-party vendors that do business with healthcare organizations need a business associate agreement (BAA) before they access PHI. A BAA helps ensure the protection of PHI by legally binding HIPAA-covered organizations and third-party vendors, which may not already be set up to handle sensitive healthcare information.


Tags: HIPAA
Previous Post

Psychological Safety: An Essential Workplace Guide

Next Post

GHG Verification an Overlooked Board Responsibility?

Staff and Wire Reports

Staff and Wire Reports

Related Posts

virginia state flag

Are You Ready for Virginia’s Sweeping Reproductive Health Privacy Law?

by Meghan O’Connor
April 29, 2025

Broadly defined ‘reproductive and sexual health information’ may affect any company doing business in the state

demystifying data de ID collage

Demystifying Data De-Identification for US Privacy Compliance

by L. Hannah Ji-Otto, David Chen and Julie Kilgore
October 30, 2024

De-identification is a valuable tool for protecting consumer privacy, but the process requires diligent compliance with multiple state and federal...

paper medical records

What HIPAA-Covered Entities & Other Companies Need to Know About Cookies & Tracking Tech

by Steve Britt
October 21, 2024

New state laws seek to regulate collecting of health data

Medical professional enters information into electronic medical record

Navigating HIPAA Compliance in the Cloud: Is Google Workspace the Right Fit?

by Nick Harrahill
August 15, 2023

By 2025, an estimated 85% of enterprises will shift to a cloud-first mindset, while others will adopt a hybrid approach...

Next Post
greenhouse gas emissions

GHG Verification an Overlooked Board Responsibility?

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights