A dermatology practice in Massachusetts left a voicemail on a patient's home phone, confirming a diagnosis in front of the patient's family. That single voicemail triggered an OCR complaint, a months-long investigation, and a corrective action plan that consumed more staff hours than anyone wants to admit. When most people hear "HIPAA laws privacy," they picture stacks of paperwork and annual checkbox training. But in reality, privacy violations happen in voicemails, hallways, and unencrypted emails — not in policy binders.
I've spent years helping covered entities untangle what HIPAA privacy requirements actually look like when rubber meets road. This post breaks down what OCR enforces, what your staff keeps getting wrong, and the specific protections your organization needs to have in place right now.
What HIPAA Laws Privacy Actually Protect — And What They Don't
The HIPAA Privacy Rule, codified at 45 CFR Part 164, Subpart E, establishes national standards for the protection of individually identifiable health information — what the industry calls protected health information, or PHI. That includes names, dates of birth, Social Security numbers, diagnoses, treatment records, billing information, and any data that could identify a patient tied to their health condition.
But here's where organizations trip up: HIPAA laws privacy protections don't cover everything medical. They apply to covered entities (health plans, healthcare clearinghouses, and providers who transmit any health information electronically) and their business associates. If you're a fitness app or a workplace wellness vendor that doesn't file electronic claims, HIPAA might not apply to you at all.
That distinction matters. I've seen organizations assume they're exempt when they're not — and vice versa. The first step in any compliance program is knowing whether you meet the definition of a covered entity under the statute.
PHI vs. De-Identified Data
PHI is any health information that includes one of the 18 identifiers listed in the Privacy Rule. Strip all 18 identifiers (or apply the expert determination method), and you have de-identified data, which HIPAA no longer covers. Most organizations underestimate how many identifiers they're storing. ZIP codes, dates of service, and medical record numbers all count.
The $4.75 Million Lesson from Memorial Healthcare System
In 2017, HHS announced a $5.5 million settlement with Memorial Healthcare System for failing to implement procedures to regularly review audit logs, access reports, and security incident tracking. Employees had been accessing patient PHI without authorization for over a year. The organization had policies on paper. What it didn't have was anyone checking whether those policies were being followed.
This is the pattern I see over and over. Organizations write HIPAA privacy policies during their initial compliance push, put them in a SharePoint folder, and forget about them. OCR doesn't penalize you for lacking a policy — they penalize you for lacking implementation.
The Minimum Necessary Standard That Everyone Ignores
One of the most misunderstood provisions in HIPAA laws privacy requirements is the minimum necessary standard. When using or disclosing PHI, your workforce must limit the information to the minimum necessary to accomplish the purpose. That means a billing coordinator shouldn't have access to psychotherapy notes. A front-desk employee doesn't need to see surgical records.
In my experience, most electronic health record systems come with role-based access controls built in. The problem isn't the technology — it's that no one configures the roles properly. Everyone gets admin-level access because it's easier than mapping job functions to data access. That shortcut is exactly what OCR investigates.
Your Staff Is Your Biggest Privacy Risk
Forget the sophisticated hackers. In most privacy breaches I've reviewed, the culprit is an employee who looked up a neighbor's medical record, a nurse who texted a photo of a patient chart to a colleague on a personal phone, or a receptionist who confirmed a patient's appointment to someone claiming to be a family member.
Workforce training isn't a suggestion under HIPAA — it's a requirement. 45 CFR § 164.530(b) requires covered entities to train all workforce members on their privacy policies and procedures. "All workforce members" includes volunteers, trainees, and contractors — not just salaried employees.
If you're running a clinical operation, HIPAA training built for nurses and clinical workflow addresses these scenarios directly, with practical examples your staff will actually remember.
Mental Health Records Deserve Extra Attention
Psychotherapy notes receive heightened protection under the Privacy Rule. They can't be disclosed for treatment, payment, or healthcare operations without explicit patient authorization — a standard far stricter than what applies to most other PHI. Behavioral health providers carry additional risk simply because of the sensitivity of the information they handle.
If your practice touches mental or behavioral health data, specialized HIPAA training for mental and behavioral health is worth the investment. Generic training programs don't cover psychotherapy note carve-outs or substance use disorder regulations under 42 CFR Part 2.
What Happens When a Breach Occurs: The Notification Clock Starts Ticking
Under the Breach Notification Rule, a covered entity must notify affected individuals within 60 days of discovering a breach of unsecured PHI. If the breach affects 500 or more individuals, you must also notify HHS and prominent media outlets in the affected state. That 60-day window is not flexible.
I've seen small practices delay reporting because they weren't sure the incident "counted." Here's the rule: any impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach unless you can demonstrate through a four-factor risk assessment that there's a low probability the PHI was compromised. Document that assessment. OCR will ask for it.
How Do HIPAA Laws Privacy Rules Apply to Email?
This is one of the most common questions I get. HIPAA does not prohibit sending PHI via email, but it requires that ePHI be protected during transmission. That means encryption. Standard Gmail or Outlook without encryption does not satisfy the Security Rule's transmission security requirements under 45 CFR § 164.312(e)(1). If a patient requests unencrypted email and you've warned them of the risk, you can honor that request — but document the conversation.
State Laws That Stack on Top of HIPAA
HIPAA sets a federal floor, not a ceiling. Many states impose stricter privacy requirements. Texas is a prime example. The Texas Medical Records Privacy Act (HB 300) requires covered entities operating in Texas to provide specific staff training on state privacy requirements — training that goes beyond federal HIPAA mandates.
If your organization operates in Texas or treats Texas residents, HB 300 training is a state-mandated obligation, not an optional add-on. Penalties under Texas law can reach $250,000 per violation.
Other states with notably stricter health privacy laws include California (CMIA), New York (SHIELD Act), and Illinois. If you operate across state lines — telehealth providers, take note — you must comply with the strictest applicable law for each patient.
The Three Privacy Rule Requirements OCR Checks First
When OCR opens an investigation, they typically zero in on three areas before anything else:
- Notice of Privacy Practices (NPP): Have you provided a clear, current NPP to every patient? Is it posted in your facility and on your website? OCR checks timestamps and distribution logs.
- Right of Access: Can patients get copies of their records within 30 days? The OCR Right of Access Initiative has produced more than 40 enforcement actions since 2019. Penalties have ranged from $3,500 to $240,000.
- Workforce Training Records: Can you prove your staff was trained, when they were trained, and what they were trained on? "We did it but didn't document it" is not a defense.
If your organization can't produce documentation in all three areas within 48 hours of an OCR request, you have a gap that needs to close immediately.
Building a Privacy Program That Survives an Investigation
Compliance isn't a document — it's an operating rhythm. Here's what I recommend to every organization I work with:
- Annual risk assessment: Required under the Security Rule, and OCR's single most-cited deficiency in enforcement actions.
- Role-based access reviews: Quarterly, at minimum. Terminate access for departed employees on their last day — not the following week.
- Incident response plan: Written, tested, and updated. Your staff should know who to call and what to document within minutes of discovering a potential breach.
- Ongoing training: Annual training is the minimum. Supplement with refreshers after policy changes, new hires, and enforcement trends. Browse the full HIPAA training catalog for role-specific options.
HIPAA laws privacy requirements haven't loosened since the Omnibus Rule took effect in 2013 — they've only tightened through enforcement precedent and state-level legislation. The organizations that avoid penalties aren't the ones with the thickest policy manuals. They're the ones whose staff can describe, in plain language, what they're supposed to do when a patient's sister calls asking for lab results.
That's the gap between compliance on paper and compliance in practice. Close it before OCR does it for you.