No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

HIPAA’s Privacy Rule Is 20 Years Old. Why Do Organizations Keep Breaking It?

Reported privacy rule violations climbed nearly 25% in 2021

by Staff and Wire Reports
June 28, 2023
in Compliance
medical records hipaa

The pandemic showed us that large numbers of Americans don’t really understand HIPAA and what protections it provides consumers despite the fact that it’s been around for decades. While one could forgive ignorance on the part of people who don’t deal with HIPAA requirements every day, it’s less forgivable when organizations to which the law applies seem ignorant of it. Still, federal data shows that reported violations of HIPAA’s privacy rule climbed by nearly 25% in the most recent year. What types of violations are still happening — and how can they be avoided?

Regulators began enforcing HIPAA’s privacy rule for healthcare insurers and providers in 2003. Since then, more than 300,000 complaints of rule violations have been alleged and more than 1,700 matters have been referred to the DOJ for possible criminal investigation.

Despite protocols designed to protect patients and organizations, HIPAA violations continue to occur frequently. Even healthcare organizations that diligently follow HIPAA regulations can be vulnerable to unintentional violations, which can lead to harm to patients, costly penalties, reputational damage and legal action. Authorities have imposed fines totaling $134 million since regulators began enforcing HIPAA’s privacy rule.

The most commonly reported violations in 2021 (the most recent year for data) were: impermissible use and disclosures, access, safeguards, administrative safeguards and breach notifications. Here are some tips for organizations to remain compliant with HIPAA’s privacy regulations.

A masked professional holds up their covid-19 vaccination card.
Compliance

‘My Employer Can’t Ask for Proof of Vaccination’ and Other Myths Regarding COVID-19 and HIPAA

by K Royal
September 7, 2021

When it comes to COVID-19 and HIPAA, many misunderstand the law’s scope and purview, especially in a professional setting. Privacy attorney K Royal dispels common misconceptions within.

Read moreDetails

Information disclosure

As we said, most unintentional HIPAA violations are due to an organization accidentally accessing or releasing protected health information (PHI). For example, employees discussing PHI in the breakroom or with friends and family is a HIPAA violation. 

Conversations that include sensitive information should be limited to those who are authorized to hear it. These conversations should take place in a private place that is not accessible to unauthorized personnel. Other tips for protecting PHI:

  • Implement appropriate employee training and management data solutions that require authorization codes or identity verification.
  • Implement employee email and cybersecurity training and best practices. Disclosing PHI to unauthorized personnel can occur by CCing multiple patients in one email, sending PHI to the wrong patient or disclosing PHI on social media. 
  • Verify what information is being requested before transmitting it. Even when the correct patient record is provided, if the individual has authorized only parts of their medical record to be disclosed but the entire record was shared, that’s a violation.

Device loss

Another common way for PHI to be accessed by unauthorized individuals is through misplaced or stolen devices like laptops, USB drives, tablets and smartphones. Devices from healthcare organizations typically contain sensitive patient information.

Healthcare professionals often take work devices home and leave them unattended in their home, car or public areas. This creates a situation where these devices can easily be stolen, lost or accessed by unauthorized individuals.

Best practices to prevent PHI disclosure in the event of a lost or stolen device include:

  • Device encryption
  • Electronic PHI (ePHI) encryption
  • Device tracking software
  • Training around device handling
  • Password protection
  • Activity monitoring of systems and devices
  • Multi-factor authentication

Improper disposal of sensitive patient information

Failing to dispose of PHI and ePHI properly, including throwing away complete copies of PHI without shredding it or failing to wipe ePHI from USBs or portable hard drives, is a HIPAA violation. 

Healthcare organizations should routinely conduct shredding or pulping of physical copies of PHI and destroy or wipe portable devices that store PHI.

Third-party risk

Nearly all healthcare organizations work with third-party companies, with many requiring access to PHI. Any company that has access to or handles PHI is required to be HIPAA-compliant. Third-party vendors that do business with healthcare organizations need a business associate agreement (BAA) before they access PHI. A BAA helps ensure the protection of PHI by legally binding HIPAA-covered organizations and third-party vendors, which may not already be set up to handle sensitive healthcare information.

Tags: HIPAA
Previous Post

Psychological Safety: An Essential Workplace Guide

Next Post

GHG Verification an Overlooked Board Responsibility?

Staff and Wire Reports

Staff and Wire Reports

Related Posts

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

data privacy concept human figure padlock

Data Privacy Rules Built for Human Behavior Have an AI Agent Problem

by Srikanth Sallaka
June 8, 2026

Regulators are beginning to treat under-governed AI deployments as intentional conduct

virginia state flag

Are You Ready for Virginia’s Sweeping Reproductive Health Privacy Law?

by Meghan O’Connor
April 29, 2025

Broadly defined ‘reproductive and sexual health information’ may affect any company doing business in the state

demystifying data de ID collage

Demystifying Data De-Identification for US Privacy Compliance

by L. Hannah Ji-Otto, David Chen and Julie Kilgore
October 30, 2024

De-identification is a valuable tool for protecting consumer privacy, but the process requires diligent compliance with multiple state and federal...

Next Post
greenhouse gas emissions

GHG Verification an Overlooked Board Responsibility?

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights