What doesn't HIPAA protect?
Asked by: Shaylee White | Last update: July 14, 2026Score: 4.1/5 (22 votes)
HIPAA does not protect health information held by non-covered entities (employers, apps, schools), de-identified data, or employment/education records. It applies specifically to covered entities (healthcare providers, plans) handling Protected Health Information (PHI). Data in consumer trackers or shared with employers is generally not covered.
What is not protected by HIPAA?
HIPAA does not protect health information held by non-covered entities, including consumer apps (Fitbit, 23andMe), employer records (personnel files, drug tests), school records (FERPA), life/disability insurance, and de-identified data. It only applies to covered entities (providers, health plans) and their business associates.
What are the 5 main rules of HIPAA?
The 5 main HIPAA rules—Privacy, Security, Enforcement, Breach Notification, and Transactions & Code Sets—collectively protect patient health information (PHI) by regulating its use, storage, and transmission. They mandate safeguards for electronic data (ePHI), enforce penalties for violations, require reporting of data breaches, and standardize electronic healthcare transactions.
What are the top 5 HIPAA violations?
The 5 most common violations to the HIPAA Privacy Rule, frequently cited by the Office for Civil Rights (OCR), include impermissible disclosures of protected health information (PHI), lack of patient access to records, insufficient safeguards for PHI, failure to manage risk, and violating the "minimum necessary" rule. These violations often involve snooping, lost devices, or improper disposal.
What are the HIPAA 3 rules?
The three primary rules of HIPAA (Health Insurance Portability and Accountability Act) are the Privacy Rule, which sets standards for protecting patient information; the Security Rule, which mandates safeguards for electronic protected health information (ePHI); and the Breach Notification Rule, which requires notifying patients and authorities of data breaches.
When HIPAA Doesn't Protect You
What is the golden rule of HIPAA?
The principle underlying the specifics of the Privacy Rule is sometimes referred to as the HIPAA golden rule: handle patient information with the same level of confidentiality and respect you'd want your own data to be treated.
What is a HIPAA violation example?
A HIPAA violation occurs when protected health information (PHI) is accessed, used, or disclosed without authorization. Common examples include snooping on patient records, mishandling unencrypted devices (like a stolen laptop), social media exposure, improper disposal of files, and failing to report breaches within 60 days.
What is the biggest HIPAA violation?
2025 HIPAA Violation Fines and Settlements
The largest HIPAA violation to date belongs to Anthem, Inc., which paid a penalty of $16 million to the OCR in 2018 for a massive 2015 cyberattack and $115 million in a class-action lawsuit settlement.
What is the most common privacy violation?
Some of the most common privacy violations include insufficient legal basis for data processing, unclear privacy notification details, and data breaches. Businesses that violate privacy laws might receive fines, be forced to stop data processing, or face other legal penalties.
What are common HIPAA mistakes?
Employees discussing patient information in open areas or to family and friends are other common HIPAA violations that can put a practice at risk. Employees must be mindful of their environment, keep confidential information to themselves, and restrict all conversations regarding patients to private places.
What are the 4 main parts of HIPAA?
The four main regulations under HIPAA (Health Insurance Portability and Accountability Act) are the Privacy Rule, Security Rule, Breach Notification Rule, and the Omnibus Rule. Together, these regulations protect patient health information, set standards for electronic data security, mandate notifications during breaches, and extend compliance requirements to business associates.
What are the exceptions to a HIPAA breach?
HIPAA breach exceptions apply when an impermissible use or disclosure of Protected Health Information (PHI) has a low probability of compromise, or fits into three specific, narrow scenarios. These exceptions include good-faith, unintentional, or authorized-person scenarios, provided the information cannot be further accessed or used.
Does HIPAA apply to everyone?
No, HIPAA does not apply to everyone. It only applies to specific entities and the professionals who work with them.
What can you not say with HIPAA?
Protected health information (PHI) cannot be shared under HIPAA.
- Healthcare claims.
- Documentation of doctor's visits.
- Payment and remittance information.
- Coordination of healthcare benefits.
- Claim status.
- Health claims attachments.
- Enrollment information in a health plan.
- Eligibility information for health plans.
What information can be shared without consent?
Information can be shared without consent if it is justified in the public interest or required by law. Do not delay disclosing information to obtain consent if that might put children or young people at risk of significant harm.
Which of the following examples is not a HIPAA violation?
Common examples of actions that are not HIPAA violations include:
What is a real life example of a HIPAA violation?
Real-life HIPAA violations often stem from unauthorized access, improper disclosures, or lack of security safeguards, ranging from employee snooping to large-scale data breaches. Key examples include employees accessing records out of curiosity, lost or stolen unencrypted devices, sharing patient information on social media, and improper disposal of physical records.
What is the most strict privacy law?
The General Data Protection Regulation (GDPR) is the toughest privacy and security law in the world. Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU.
Which is most likely a HIPAA violation?
The action most likely to result in a HIPAA violation is asking your friends to promise they won’t repeat anything you tell them about work.
What are the 5 main HIPAA rules?
The 5 main HIPAA rules governing the protection of patient health information (PHI) are the Privacy Rule, Security Rule, Breach Notification Rule, Transactions and Code Sets Rule, and Enforcement Rule. These rules mandate how protected health information is used, stored, transmitted, and enforced.
What counts as a violation of Hippa?
A HIPAA violation occurs when a healthcare provider, health plan, or healthcare clearinghouse (covered entity) fails to protect the privacy, security, or integrity of a patient's Protected Health Information (PHI). This includes both unauthorized access to medical records and the failure to implement required data safeguards.
What are the top five HIPAA violations?
The 5 most common violations to the HIPAA Privacy Rule, frequently cited by the Office for Civil Rights (OCR), include impermissible disclosures of protected health information (PHI), lack of patient access to records, insufficient safeguards for PHI, failure to manage risk, and violating the "minimum necessary" rule. These violations often involve snooping, lost devices, or improper disposal.
Is gossiping a HIPAA violation?
When does workplace gossip become a HIPAA violation? It becomes a violation when a covered entity or business associate workforce member discloses PHI to someone without a need to know, without a permissible purpose or valid authorization, and outside the minimum necessary standard.
What is a level 3 violation?
Level 3 violations are serious breaches of conduct that may involve a serious violation of a professional code of conduct or include extreme cases of dishonesty and maliciousness. Level 3 violations may include a violation of law, or may be likely to cause direct harm to others.
How common are HIPAA violations?
HIPAA violations are very common, with over 300,000 complaints reported to the Office for Civil Rights (OCR) since 2003 and over 1,000 investigations opened annually. They occur daily across the healthcare industry, often involving unauthorized access to records, stolen devices, or employee errors, leading to significant fines.