IHP-600: Module 8 – Reflection Journal: HIPAA
Southern New Hampshire University
2
On August 21,1996 the Health Insurance Probability and Accountability Act
(HIPAA) was signed into law by President Bill Clinton. This federal law required the
creation of a national standard to protect sensitive patient health information from being
disclosed without the patients consent of knowledge (CDC,2018). The ultimate goal of this
law was to help the American people obtain health insurance as well as ensure employees
they did not lose their health insurance when a change of employment was to occur
(HIPAA Guidance, 2021). “Other aims of HIPAA were to tackle waste, fraud and abuse in
health insurance and healthcare provision. The Act also included sections to promote the
use of medical savings accounts by introducing tax breaks, providing coverage for
employees with pre-existing medical conditions and making the administration of health
insurance easier” (Editor, 2019).
In 1999, another component of HIPAA was proposed and finalized. This important
milestone in HIPAA is known as the Privacy Rule (HIPAA Guidance, 2021). The Privacy
Rule is targeted towards protected health information which as states “is any information
within a person’s medical record that can identify them and is held by a covered entity”
(HIPAA Guidance, 2021). There are 18 types of information that are considered protected
health information which includes: Name, Address, Any dates related to the individual
except for years, Telephone number, Fax number, Email Address, Social Security Number,
Medical Record Number, Health Plan Beneficiary number, Account number,
Certificate/license number, Vehicle identifiers, serial numbers, license plate numbers, Device
identifiers, serial numbers, Web URL’s, IP address, Biometric identifiers such as
fingerprints or voiceprint, Full-face photos, and Any other unique identifying numbers,
characteristics, or codes (HIPAA Guidance, 2021).
3
Along with privacy rule, many breaches can occur with leads to HIPAA violations.
HIPAA violations fall into one of three categories: unencrypted data, employee error, or
breaches due to theft (Elmore, 2020). HIPAA violations are based on the level of
negligence and have a range of $100 to $50,000 per individual violation with a cap of $1.5
million per calendar year (Elmore, 2020). Additionally, individuals deemed responsible can
often incur jail time. HIPAA penalties for non-compliance are broken down into a four-tier
system:
• Tier 1: Covered entity had no knowledge of the breach (and could not reasonably
know). Fines generally range $100 to $50,000 per incident up to $1.5 million in
penalties.
• Tier 2: Covered entity had knowledge or with reasonable diligence would have
knowledge of the violation; did not act with will neglect. Fines generally range
$1,000 to $50,000 per incident up to $1.5 million in penalties.
• Tier 3: Covered entity acted with willful neglect and corrected the problem within
30 days of the breach. Fines for this tier range $10,000 to $50,000 per incident up
to $1.5 million.
• Tier 4: Covered entity willfully neglected and failed to make a timely correction.
Fines start at $50,000 per incident up to $1.5 million (Elmore, 2020).
If for whatever reason the Department of Health and Human Services should determine that
the breach was deliberate and done with malicious intent, the information can be turned
over to the Department of Justice and become a criminal matter. Criminal penalties also
have a tier system, though there are only three tiers consisting of the following:
4
• Tier 1: Reasonable cause or no knowledge of the violation – up to 1 year in jail.
• Tier 2: Obtaining PHI for false pretenses – up to 5 years in jail.
• Tier 3: Obtaining PHI for personal gain or malicious intent – up to 10 years in jail
(Alder, 2021).
Over the years HIPAA has evolved alongside technology. With new technology rapidly
increasing, so are security breaches. Fortunately, HIPAA did consider this aspect of security
and in 2004 the Security Rule was passed. This rule has three types of required standards
of implementation that must be followed by covered entities including: administrative,
physical, and technical (HIPAA Guidance, 2020). Administrative safeguards include security
management processes, assigned security persons, information access management, and
workforce training. Physical safeguards are the facility access and control and security of
workstations and devices. Finally, the technical safeguards include encryption, transmission
security, integrity controls, audit control, and access control. Although technology is rapidly
developing, so is HIPAA and its mission to protect the American’s fundamental health
rights.
5
References
1. CDC. (2018, September 14). Health Insurance Portability and Accountability Act
of 1996 (HIPAA). Retrieved from:
https://www.cdc.gov/phlp/publications/topic/hipaa.html
2. HIPAA Guidance. (2021, April 7). The History of HIPAA. Retrieved from:
https://www.accountablehq.com/post/history-of-hipaa
3. Editor. (2019, May 9). Why was HIPAA created? HIPAA Guide. Retrieved from
https://www.hipaaguide.net/why-was-hipaa-created/
4. Alder, S. (2021, January 15). What are the Penalties of HIPAA Violations?
Retrieved from: https://www.hipaajournal.com/what-are-the-penalties-for-
hipaa-violations-7096/
5.