One Misspelled Word That Tells Me Everything About Your Compliance Program

I once walked into a medical office where every break room poster, every employee handbook, and even the privacy notice taped to the front desk all read "HIPPA." Four letters in the wrong order. A small thing, maybe — until I realized the office hadn't updated its risk assessment in three years, had no business associate agreements on file, and was storing patient records on an unencrypted laptop in an unlocked drawer.

The misspelling wasn't the violation. But it was a signal. When organizations can't get the name of the law right, they usually can't get the substance right either. So let's settle the HIPAA or HIPPA question once and for all — and then talk about what actually keeps you compliant.

HIPAA or HIPPA — Which Spelling Is Correct?

The correct spelling is HIPAA. It stands for the Health Insurance Portability and Accountability Act. Congress passed it in 1996. The acronym breaks down like this: Health Insurance Portability And Accountability. Two A's at the end — one for "And," one for "Accountability."

"HIPPA" is not a law. It's not an acronym for anything. It's a typo that has become so common it now gets searched tens of thousands of times a month. Google essentially treats "HIPAA or HIPPA" as the same query because so many people get it wrong.

You can find the full text of the statute at HHS.gov's HIPAA homepage. Bookmark it. It's the only authoritative source you need.

Why the Misspelling Is More Than a Typo

Here's what I've seen in over a decade of consulting: the organizations that misspell HIPAA in their internal documents are, almost without fail, the same ones cutting corners on compliance. The spelling mistake is a proxy for lack of attention. And the Office for Civil Rights (OCR) notices lack of attention.

Think about what a patient sees when your intake form says "HIPPA Privacy Notice." They may not consciously register it. But your staff sees it. Your business associates see it. And if OCR ever investigates a complaint, your documentation is the first thing they review. Misspelling the name of the law you're supposed to follow doesn't inspire confidence.

I'm not saying OCR fines organizations for bad spelling. I'm saying that sloppy documentation correlates with sloppy compliance — and sloppy compliance absolutely leads to enforcement actions.

The $5.55 Million Lesson From Advocate Medical Group

In 2016, OCR settled with Advocate Medical Group for $5.55 million after multiple breaches affecting approximately 4 million individuals. The issues? Unencrypted laptops, lack of physical safeguards, and an inadequate risk assessment. The settlement documents painted a picture of an organization that hadn't made HIPAA compliance a priority across its workforce.

No one at Advocate got fined for spelling. They got fined for the same kind of neglect that spelling errors tend to signal — a compliance program that existed on paper but not in practice. You can review OCR's enforcement results at the HHS Resolution Agreements page.

What HIPAA Actually Requires (A Quick Refresher)

Since you searched "HIPAA or HIPPA," you might be early in your compliance journey. Here's the short version of what the law demands from every covered entity and business associate.

The Privacy Rule

Controls how protected health information (PHI) is used and disclosed. It gives patients rights over their health records and sets limits on who can access them. Every member of your workforce needs to understand the basics.

The Security Rule

Focuses specifically on electronic PHI (ePHI). It requires administrative, physical, and technical safeguards. Think access controls, encryption, audit logs, and contingency planning.

The Breach Notification Rule

If unsecured PHI is compromised, you must notify affected individuals, HHS, and in some cases, the media. Timelines are strict — 60 days from discovery for individual notices.

The Enforcement Rule

Gives OCR the teeth to investigate complaints and impose civil monetary penalties. Penalties range from $141 per violation (where the entity didn't know) up to $2,134,831 per violation for willful neglect. These numbers are adjusted annually for inflation.

HIPAA stands for the Health Insurance Portability and Accountability Act. It is a federal law enacted in 1996 that establishes national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. The law is enforced by the U.S. Department of Health and Human Services (HHS) through the Office for Civil Rights (OCR). The correct spelling is always HIPAA, never HIPPA.

Three Real Compliance Gaps That Start With Not Knowing the Basics

In my experience, the "HIPAA or HIPPA" confusion usually comes bundled with three bigger problems.

1. No Annual Workforce Training

HIPAA requires that every workforce member — not just clinical staff — receives training on your policies and procedures. "We did training two years ago" doesn't cut it. If you have nurses, medical assistants, or front-desk staff who haven't been trained on current workflows, start with our HIPAA training course designed specifically for nurses and clinical teams.

2. No Remote Work Policy

The shift to telehealth and remote administrative work created massive new exposure for PHI. If your staff accesses patient records from home and you haven't built a policy around that, you're exposed. Our Working from Home and PHI training walks through exactly what your workforce needs to know.

3. No Mobile Device Controls

Smartphones, tablets, and personal laptops accessing ePHI without encryption, passcodes, or remote-wipe capability — I see it constantly. It's one of the most common paths to a reportable breach. Our Mobile Devices and PHI course covers the technical and behavioral safeguards your team needs.

How OCR Actually Finds You

Most people assume OCR only goes after large hospitals. That's wrong. OCR investigates every complaint filed through the HHS complaint portal. A disgruntled employee, a suspicious patient, or a breach report — any of these can trigger a review.

When OCR opens an investigation, they request documentation. They want to see your risk assessment, your training records, your policies, your BAAs. If those documents are riddled with "HIPPA" — or worse, don't exist — you're already starting from a deficit.

Since 2003, OCR has investigated more than 340,000 complaints. They've settled or imposed penalties resulting in over $142 million in total enforcement actions. Your organization doesn't have to be a national health system to end up on their radar.

The Fix Is Simpler Than You Think

Correcting the spelling is easy. Building the compliance program behind it takes effort — but it's manageable if you approach it methodically.

Step one: Audit every document in your organization that references HIPAA. Fix the spelling. While you're at it, check that the content is current.

Step two: Conduct or update your risk assessment. This is the single most important requirement under the Security Rule, and it's the one OCR checks first.

Step three: Train your workforce. Not once. Annually. And make it role-specific so it actually sticks.

Step four: Document everything. If you can't prove you did it, OCR assumes you didn't.

Stop Searching "HIPAA or HIPPA" — Start Building Real Compliance

Now you know the answer: it's HIPAA. Two A's. Health Insurance Portability and Accountability Act. But knowing how to spell it is the absolute bare minimum.

The organizations that avoid enforcement actions are the ones that treat HIPAA as an ongoing operational commitment — not a poster on the wall. They train their teams, lock down their devices, update their risk assessments, and document every step.

If you're ready to move past the spelling question and into real compliance, explore our full training catalog and get your workforce up to standard before OCR comes asking questions.