HIPAA at a Glance

A doctor and nurse reviewing documents on a laptop.
A doctor and nurse reviewing documents on a laptop.

HIPAA or the Health Insurance Portability and Accountability Act is a set of practices that govern the privacy of individual health records. You may have heard of data sets that would be covered under HIPAA such as Personally Identifiable Information, Electronic Protected Health Information, or Protected Health Information (PII, ePHI, and PHI).

How Does HIPAA Impact Your Business

Businesses are expected to adhere to some specific rules, categorized as:

  • Privacy Rule
  • Security Rule
  • Transactions Rule
  • Identifiers Rule
  • Enforcement Rule

The Privacy Rule addresses how PHI and medical records of individuals may be used or disclosed with and without patient authorization. The Privacy Rule also addresses how the patient can obtain a copy of their record and request corrections. The Security Rule provides a set of Administrative, Physical, and Technical safeguards that the practice must implement to protect ePHI. In these two areas alone, the business must be ready to measure, monitor, and reduce risk to ePHI through the implementation of various technologies and practices that often have associated costs to the business.

What Is Considered PHI

Under HIPAA, PHI is any information about health care, health status, and payment for health care that can be linked to the following 18 identifiers:

NamesSocial Security Numbers
Phone NumbersFax Numbers
Email AddressesWeb URLs
Account NumbersHealth Plan Beneficiary Numbers
Full Face Photographic ImagesBiometric Identifiers
Vehicle VIN Numbers and License PlatesIP Address Numbers
Certificate/License NumbersDevice IDs and Serial Numbers
Medical Record NumbersAny Other Unique Identifying Number
All elements of dates (except year) that are directly related to an individualAll geographical subdivisions smaller than a state

What Fines Come with Ignoring the Rules

The following are primary tiers as provided by the HIPAA Journal concerning HIPAA violations:

Tier 1 Unaware of the HIPAA violation and by exercising reasonable due diligence would not have known HIPAA Rules had been violated

  • Penalty: $100 – $50,000 per violation with a maximum of $1.5 million per year

Tier 2 Reasonable cause that the covered entity knew about or should have known about the violation by exercising reasonable due diligence

  • Penalty: $1,000 – $50,000 per violation with a maximum of $1.5 million per year

Tier 3 Willful neglect of HIPAA Rules with the violation corrected within 30 days of discovery

  • Penalty: $10,000 – $50,000 per violation with a maximum of $1.5 million per year

Tier 4 Willful neglect of HIPAA Rules and no effort made to correct the volition within 30 days of discovery

  • Penalty: $50,000 per violation with a maximum of $1.5 million per year

Note that there is an emphasis on exercising reasonable due diligence in Tier 1 and 2. If the entity decides not to exercise due diligence and are aware of the violations, then it could place them in Tier 3 or 4 category because of willful neglect. Knowing where the gaps are is half the battle, and ensuring you have a healthy plan of action can help you save a lot of money in the event there is an issue.


What You Can Do Today

If you do not know where you stand concerning meeting the requirements as laid out by HIPAA or have not performed a recent Risk Assessment, you should seek to work with a qualified entity that can help you understand the risks and ensure you are exercising reasonable due diligence in identifying problems.

Corsica Technologies has trained and certified IT Auditors ready to tackle the complex problems that any compliance requirement brings, and they can help you understand the gaps you may have with those requirements in simple terms. Don’t wait to get stuck with hefty fines and poor publicity before choosing to take action.

Contact us today for a HIPAA Compliance Assessment!

Corsica Technologies
Corsica Technologies is an MSP specializing in cybersecurity solutions, managed IT services, digital transformation, and data integration. Corsica provides solutions for midmarket businesses including network monitoring, data protection, incident response, and IT support. Corsica offers unmetered technology services for fully managed or co-managed teams to address all technology needs under a one-flat monthly fee. 

Related Cybersecurity and IT Reads

Tariffs effect on computer and electronic prices for businesses - Corsica Technologies
Hardware as a Service
Garrett Wiesenberg

How Will Tariffs Affect Computer Prices for Businesses?

As the United States rolls out tariffs on imported goods, companies everywhere are working hard to understand the potential impact of these economic policies on their business. While the answers are complex and dependent on your industry, one thing is

Read more
Penetration Testing Services - Corsica Technologies
Cybersecurity
Ross Filipek

Penetration Testing Services 101

In this article: What is pentesting?  Can your own staff do it?  Should you test in off-hours?  Pentesting steps  How to prepare  What do you get? See a sample report Are you easy to hack? That’s the big question. Yet many

Read more
Windows Server 2019 end of life - Corsica Technologies
Managed IT Services
Garrett Wiesenberg

Windows Server 2019 EOL: What You Need to Know

On January 9, 2024, Windows Server 2019 officially ended mainstream support. While Microsoft will continue to provide security updates until January 9, 2029, the operating system isn’t receiving new features or bug fixes. What does that mean for you? Is

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.