IHP-600: Module 8 – Reflection Journal: HIPAA
Southern New Hampshire University
2
On August 21,1996 the Health Insurance Probability and Accountability Act (HIPAA)
was signed into law by President Bill Clinton. This federal law required the creation of a
national standard to protect sensitive patient health information from being disclosed without the
patients consent of knowledge (CDC,2018). The ultimate goal of this law was to help the
American people obtain health insurance as well as ensure employees they did not lose their
health insurance when a change of employment was to occur (HIPAA Guidance, 2021). “Other
aims of HIPAA were to tackle waste, fraud and abuse in health insurance and healthcare
provision. The Act also included sections to promote the use of medical savings accounts by
introducing tax breaks, providing coverage for employees with pre-existing medical conditions
and making the administration of health insurance easier” (Editor, 2019).
In 1999, another component of HIPAA was proposed and finalized. This important
milestone in HIPAA is known as the Privacy Rule (HIPAA Guidance, 2021). The Privacy Rule
is targeted towards protected health information which as states “is any information within a
person’s medical record that can identify them and is held by a covered entity” (HIPAA
Guidance, 2021). There are 18 types of information that are considered protected health
information which includes: Name, Address, Any dates related to the individual except for
years, Telephone number, Fax number, Email Address, Social Security Number, Medical
Record Number, Health Plan Beneficiary number, Account number, Certificate/license number,
Vehicle identifiers, serial numbers, license plate numbers, Device identifiers, serial numbers,
Web URL’s, IP address, Biometric identifiers such as fingerprints or voiceprint, Full-face
photos, and b Any other unique identifying numbers, characteristics, or codes (HIPAA Guidance,
2021).
3
Along with privacy rule, many breaches can occur with leads to HIPAA violations.
HIPAA violations fall into one of three categories: unencrypted data, employee error, or
breaches due to theft (Elmore, 2020). HIPAA violations are based on the level of negligence and
have a range of $100 to $50,000 per individual violation with a cap of $1.5 million per calendar
year (Elmore, 2020). Additionally, individuals deemed responsible can often incur jail time.
HIPAA penalties for non-compliance are broken down into a four-tier system:
• Tier 1: Covered entity had no knowledge of the breach (and could not reasonably know).
Fines generally range $100 to $50,000 per incident up to $1.5 million in penalties.
• Tier 2: Covered entity had knowledge or with reasonable diligence would have
knowledge of the violation; did not act with will neglect. Fines generally range $1,000 to
$50,000 per incident up to $1.5 million in penalties.
• Tier 3: Covered entity acted with willful neglect and corrected the problem within 30
days of the breach. Fines for this tier range $10,000 to $50,000 per incident up to $1.5
million.
• Tier 4: Covered entity willfully neglected and failed to make a timely correction. Fines
start at $50,000 per incident up to $1.5 million (Elmore, 2020).
If for whatever reason the Department of Health and Human Services should determine that the
breach was deliberate and done with malicious intent, the information can be turned over to the
Department of Justice and become a criminal matter. Criminal penalties also have a tier system,
though there are only three tiers consisting of the following:
• Tier 1: Reasonable cause or no knowledge of the violation – up to 1 year in jail.
• Tier 2: Obtaining PHI for false pretenses – up to 5 years in jail.
4
• Tier 3: Obtaining PHI for personal gain or malicious intent – up to 10 years in jail
(Alder, 2021).
Over the years HIPAA has evolved alongside technology. With new technology rapidly
increasing, so are security breaches. Fortunately, HIPAA did consider this aspect of security and
in 2004 the Security Rule was passed. This rule has three types of required standards of
implementation that must be followed by covered entities including: administrative, physical,
and technical (HIPAA Guidance, 2020). Administrative safeguards include security
management processes, assigned security persons, information access management, and
workforce training. Physical safeguards are the facility access and control and security of
workstations and devices. Finally, the technical safeguards include encryption, transmission
security, integrity controls, audit control, and access control. Although technology is rapidly
developing, so is HIPAA and its mission to protect the American’s fundamental health rights.
5
References
1. CDC. (2018, September 14). Health Insurance Portability and Accountability Act of
1996 (HIPAA). Retrieved from:
https://www.cdc.gov/phlp/publications/topic/hipaa.html
2. HIPAA Guidance. (2021, April 7). The History of HIPAA. Retrieved from:
https://www.accountablehq.com/post/history-of-hipaa
3. Editor. (2019, May 9). Why was HIPAA created? HIPAA Guide. Retrieved from
https://www.hipaaguide.net/why-was-hipaa-created/
4. Alder, S. (2021, January 15). What are the Penalties of HIPAA Violations? Retrieved
from: https://www.hipaajournal.com/what-are-the-penalties-for-hipaa-violations-
7096/
5.