IHP-600: Module 8 – Reflection Journal: HIPAA
Southern New Hampshire University
2
On August 21,1996 the Health Insurance Probability and Accountability Act (HIPAA)
was signed into law by President Bill Clinton. This federal law required the creation of a national
standard to protect sensitive patient health information from being disclosed without the patients
consent of knowledge (CDC,2018). The ultimate goal of this law was to help the American
people obtain health insurance as well as ensure employees they did not lose their health
insurance when a change of employment was to occur (HIPAA Guidance, 2021). “Other aims of
HIPAA were to tackle waste, fraud and abuse in health insurance and healthcare provision. The
Act also included sections to promote the use of medical savings accounts by introducing tax
breaks, providing coverage for employees with pre-existing medical conditions and making the
administration of health insurance easier” (Editor, 2019).
In 1999, another component of HIPAA was proposed and finalized. This important
milestone in HIPAA is known as the Privacy Rule (HIPAA Guidance, 2021). The Privacy Rule is
targeted towards protected health information which as states “is any information within a
person’s medical record that can identify them and is held by a covered entity” (HIPAA
Guidance, 2021). There are 18 types of information that are considered protected health
information which includes: Name, Address, Any dates related to the individual except for years,
Telephone number, Fax number, Email Address, Social Security Number, Medical Record
Number, Health Plan Beneficiary number, Account number, Certificate/license number, Vehicle
identifiers, serial numbers, license plate numbers, Device identifiers, serial numbers, Web
URL’s, IP address, Biometric identifiers such as fingerprints or voiceprint, Full-face photos, and e
Any other unique identifying numbers, characteristics, or codes (HIPAA Guidance, 2021).
Along with privacy rule, many breaches can occur with leads to HIPAA violations.
HIPAA violations fall into one of three categories: unencrypted data, employee error, or breaches
3
due to theft (Elmore, 2020). HIPAA violations are based on the level of negligence and have a
range of $100 to $50,000 per individual violation with a cap of $1.5 million per calendar year
(Elmore, 2020). Additionally, individuals deemed responsible can often incur jail time. HIPAA
penalties for non-compliance are broken down into a four-tier system:
• Tier 1: Covered entity had no knowledge of the breach (and could not reasonably know).
Fines generally range $100 to $50,000 per incident up to $1.5 million in penalties.
• Tier 2: Covered entity had knowledge or with reasonable diligence would have
knowledge of the violation; did not act with will neglect. Fines generally range $1,000 to
$50,000 per incident up to $1.5 million in penalties.
• Tier 3: Covered entity acted with willful neglect and corrected the problem within 30
days of the breach. Fines for this tier range $10,000 to $50,000 per incident up to $1.5
million.
• Tier 4: Covered entity willfully neglected and failed to make a timely correction. Fines
start at $50,000 per incident up to $1.5 million (Elmore, 2020).
If for whatever reason the Department of Health and Human Services should determine that the
breach was deliberate and done with malicious intent, the information can be turned over to the
Department of Justice and become a criminal matter. Criminal penalties also have a tier system,
though there are only three tiers consisting of the following:
• Tier 1: Reasonable cause or no knowledge of the violation – up to 1 year in jail.
• Tier 2: Obtaining PHI for false pretenses – up to 5 years in jail.
• Tier 3: Obtaining PHI for personal gain or malicious intent – up to 10 years in jail (Alder,
2021).
4
Over the years HIPAA has evolved alongside technology. With new technology rapidly
increasing, so are security breaches. Fortunately, HIPAA did consider this aspect of security and
in 2004 the Security Rule was passed. This rule has three types of required standards of
implementation that must be followed by covered entities including: administrative, physical,
and technical (HIPAA Guidance, 2020). Administrative safeguards include security management
processes, assigned security persons, information access management, and workforce training.
Physical safeguards are the facility access and control and security of workstations and devices.
Finally, the technical safeguards include encryption, transmission security, integrity controls,
audit control, and access control. Although technology is rapidly developing, so is HIPAA and its
mission to protect the American’s fundamental health rights.
5
References
1. CDC. (2018, September 14). Health Insurance Portability and Accountability Act of
1996 (HIPAA). Retrieved from:
https://www.cdc.gov/phlp/publications/topic/hipaa.html
2. HIPAA Guidance. (2021, April 7). The History of HIPAA. Retrieved from:
https://www.accountablehq.com/post/history-of-hipaa
3. Editor. (2019, May 9). Why was HIPAA created? HIPAA Guide. Retrieved from
https://www.hipaaguide.net/why-was-hipaa-created/
4. Alder, S. (2021, January 15). What are the Penalties of HIPAA Violations? Retrieved
from: https://www.hipaajournal.com/what-are-the-penalties-for-hipaa-violations-
7096/
5.