Do HIPAA Laws Apply to Employers?

Опубликовано: 07 Июнь 2026
на канале: Etactics
916
2

HIPAA violations happen quite frequently. The U.S. Department of Health and Human Services reports that 342,032 privacy rule complaints have been filed in 2023. In 2018, records of 500 or more healthcare data breaches were being reported once a day.

HIPAA laws are put in place to prevent the sharing or disclosing of protected health information, or PHI, without a patient’s consent.

Protected health information is any information in medical records that can identify an individual receiving a healthcare offer or service through treatment, payment, operations, medical records, and more. It’s sometimes referred to as personal health information. ePHI is the same as PHI except it’s in an electronic format.

HIPAA is made up of 5 main provisions: The HIPAA Privacy Rule, Transactions and Code Sets Rule, The HIPAA Security Rule, Unique Identifiers Rule, and HIPAA Enforcement Rule.

Each of these provisions have their own rules and regulations when it comes to protecting sensitive information. So, do these HIPAA laws apply to all employers? To put it into simple terms, Ignoring HIPAA rules and regulations can lead to costly fines, lawsuits, and jail time.

There are 3 covered entities that must follow all HIPAA laws…Health plans, Healthcare clearinghouses, and Healthcare providers. If an employer does not fall under any of these categories, then HIPAA does not apply.

Both employers and employees can break HIPAA laws. A HIPAA violation in the workplace setting is any action that results in the improper disclosure of a patient’s protected health information. This includes accessing, using, disclosing, or selling PHI without authorization.

Sometimes the employer or employee may not even be aware that they are violating HIPAA laws. Violations are classified as either reasonable cause or willful neglect.

We’ve talked a lot about HIPAA violations and different fines that come along with them for both employers and employees. Here is a real world example of a HIPAA violation that took place in 2019 with a small dental practice known as Elite Dental Associates.

The Office of Civil Rights, or OCR, received a complaint from an individual that Elite had responded to a social media review by disclosing a patient’s last name and details of their protected health information on the social networking site known as Yelp.

Through Yelp users rate and write reviews for establishments based upon their experience and service.

After further assessment of the complaint, the Office for Civil Rights found that Elite had disclosed the PHI of many patients in response to patient reviews on the Elite Yelp page.

The Office for Civil Rights discovered that Elite did not have a policy and procedure about disclosure of protected health information or a Notice of Privacy Practices that compiled with the HIPAA Privacy Rule.

Due to Elite’s size and their willingness to comply, the settlement came out to be $10,000 which is still low for these circumstances.

Elite also put into place a 2 year corrective action plan monitored by the Office of Civil Rights for compliance with HIPAA rules.

This scenario is the perfect example of how an employer can break HIPAA laws, by taking the PHI of their patients and broadcasting it to the public without their consent.

Both employers and employees are responsible for the PHI of patients that they get through partnerships and working alongside healthcare practices.

If you work for a company that is a covered entity, then it is essential that you ensure your practices are HIPAA compliant. How do you do that you may ask? HIPAA laws do change, so investing in annual company training will take that extra bit of weight off your shoulders.

► Reach out to Etactics @ https://www.etactics.com​
►Subscribe: https://rb.gy/pso1fq​ to learn more tips and tricks in healthcare, health IT, and cybersecurity.
►Find us on LinkedIn:   / etactics-inc  
►Find us on Facebook:   / ​  

#HIPAA #hipaacompliance