25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Amy Schultz

Amy Schultz is a Privacy Manager who leads day-to-day HIPAA operations and incident response at Concentra, the largest provider of occupational health services in the US, with 2,000 employees, over 600 centres, over 50,000 patients daily across 44 states. With 12+ years in healthcare privacy and compliance, she is trusted to translate the HIPAA Privacy Rule, HIPAA Security Rule, and Breach Notification Rule into clear, workable processes. Amy’s work includes the full lifecycle of HIPAA obligations: auditing monthly Incident Reports, investigating complaints and Office for Civil Rights (OCR) matters, and developing defensible documentation aligned to the Minimum Necessary standard. Amy’s career at Concentra has progressed from Privacy Specialist, Senior Privacy Specialist, and Compliance Specialist, where she built hands-on expertise in hotline intake, DLP triage, OCR correspondence, and enterprise training audits, experience she now leverages to scale privacy governance. Amy holds a Bachelor of Applied Science in Public Safety Administration from St. Petersburg College and is an active HCCA member. You can contact Amy Schultz on LinkedIn.

I’m a HIPAA Privacy Manager. What’s That Mean?
Nov21

I’m a HIPAA Privacy Manager. What’s That Mean?

The Privacy Department is led by the HIPAA Privacy Manager, but who is the Department? For some small organizations, it’s just the Privacy Officer. For others, there is a team of people who work diligently to keep the Privacy Officer informed and the organization compliant. When someone asks what you do for a living, how would you explain it? If I say to staff that I’m a Privacy Manager, I typically get blank stares. I then mention HIPAA or Patient Rights, and that’s when I get a head nod or two. Privacy Officer sounds official, but honestly, what I do every day is way more involved in privacy operations than your typical privacy officer. This is the time to learn and soak up everything you can. Having a team is so important, even if it’s just one extra person. The Privacy Officer is limited without the people who make the department functional every day. Whether you’re a specialist just starting out or a manager like me with years of experience, the daily grind is tackled by us. We are diligent and timely in keeping our patients’ PHI safeguarded, giving our colleagues guidance,...

Read More
The Human Side of HIPAA Privacy is Patient’s Rights
Sep26

The Human Side of HIPAA Privacy is Patient’s Rights

Almost everyone gets into healthcare for one reason: to help people. Whether it’s at a hospital as a provider or a corporate office as a Privacy Officer, the goal tends to lean towards helping those in need.  In the healthcare sector, what comes to mind when you think of patients’ rights? Hopefully, you thought about the different rights patients have under HIPAA.  The right to access records, restrict disclosure of records, amend records, confidential communication of records, disclosure of accounting of records, and the right to file a HIPAA complaint. Your organization should have a process or practice in place for addressing each of these. A patient comes in for an employer-paid pre-employment drug screen. They sign the HIPAA form and proceed with the service. The next day, the patient contacts the center and says they would like to revoke their authorization. What do you do? A recurring patient emails the hospital requesting an amendment to their medical record. What do you do? A patient calls the clinic and requests a copy of their medical records be sent to them via email....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist