What Happens if You Break HIPAA Rules?
What happens if you break HIPAA Rules depends on whether you are a covered entity or business associate, or a member of either’s workforce. If the former, you may be liable for sanctions issued by HHS’ Office for Civil Rights, State Attorneys General, and/or the Federal Trade Commission. If the latter, the consequences depend on the content of your employer’s HIPAA sanctions policy. What Happens if You Break HIPAA Rules? If you break HIPAA Rules as a member of a covered entity´s or business associate´s workforce there are four potential outcomes: The violation could be dealt with internally by an employer Your contract of employment could be terminated You could face sanctions from professional boards You could face criminal charges which include fines and imprisonment What happens if you break HIPAA compliance rules will depend on the severity of the violation. The actions of employers, professional boards, federal regulators, and the Department of Justice will depend on several factors: The nature of the violation Whether there was knowledge that HIPAA Rules...
Can A Patient Sue for A HIPAA Violation?
A patient can sue for a HIPAA violation – and there are an increasing number of class action suits for protected health information data breaches – although not under the provisions of HIPAA laws. There is no private cause of action in HIPAA, so it is not possible for a patient to directly sue for a HIPAA violation under HIPAA. Even if HIPAA Rules have clearly been violated by a healthcare provider, and harm has been suffered as a direct result, it is not possible for patients to seek damages, at least not for the violation of HIPAA laws. So, if it is not possible for a patient to directly sue for a HIPAA violation, does that mean legal action cannot be taken against a covered entity when HIPAA has clearly been violated? While HIPAA does not have a private cause of action, it is possible for patients to take legal action against healthcare providers and obtain damages for violations of state laws. In some states, it is possible to file a lawsuit against a HIPAA covered entity on the grounds of negligence or for a breach of an implied contract, such as if a covered...
What are the Penalties for HIPAA Violations?
The penalties for HIPAA violations include civil monetary penalties ranging from $145 to $2,190,294 per violation, depending on the level of culpability. Criminal penalties can also be imposed for intentional HIPAA violations, leading to fines and potential imprisonment. In addition to financial penalties, corrective action plans may be required to address compliance deficiencies. The Department of Health and Human Services (HHS) Office for Civil Rights cannot compel a HIPAA-regulated entity to adopt a corrective action plan when a civil monetary penalty is imposed, but settlements almost always include one. State attorneys general can also bring civil actions, resulting in civil monetary penalties. Settlements are usually the preferred choice, and in such cases, there may be a requirement to pay a financial penalty and invest in cybersecurity. In this article, we provide a detailed explanation of penalties for HIPAA violations. You can also use the article in conjunction with our free HIPAA Violations Checklist to understand what is required to ensure full compliance. Please use...
BA Exemption: The HIPAA Conduit Exception Rule and Transmission of PHI
The HIPAA Conduit Exception Rule applies to organizations that would normally be considered business associates, but who are exempted from complying with HIPAA because they only have transient access to PHI. For the benefit of HIPAA compliance, it is important to understand the difference between transient access, persistent access, and no view access. The HIPAA Omnibus Final Rule and Business Associates On January 25, 2013, the HIPAA Omnibus Final Rule was published in the Federal Register. The HIPAA Omnibus Final Rule introduced a swathe of updates to HIPAA Rules, including updates attributable to the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HIPAA Omnibus Final Rule included an update to the definition of a business associate. Prior to January 25, 2013, a business associate was a person or entity that creates, receives, or transmits protected health information (PHI) on behalf of a covered entity. The Omnibus rule added ‘maintains’ to that definition. That meant companies that store electronic information – or physical records – are...
How to Report a HIPAA Violation
How you report a HIPAA violation varies depending on the nature of the violation and whether you are a member of the public, a member of a covered entity’s workforce, or a covered entity. There are also various channels for reporting a HIPAA violation. These channels include the Privacy Officer at the organization where the violation occurred, your State Attorney General, and HHS’ Office for Civil Rights. It is important for all employees in the healthcare and health insurance industries to understand what constitutes a HIPAA violation and how to report a HIPAA violation. Understanding what constitutes a HIPAA violation should be included in HIPAA training, as should the correct person to direct a report to. This person then has the responsibility to determine whether or not the HIPAA violation should be reported to the Department of Health and Human Services’ Office for Civil Rights (OCR). Potential HIPAA violations must be investigated internally by HIPAA covered entities and – where applicable – by business associates to determine the severity of the violation and...



