A $4.75 Million Wake-Up Call Nobody Expected

In 2022, a single stolen laptop cost a health system millions. Not because the laptop was valuable — because the ePHI on it wasn't encrypted. The Office for Civil Rights (OCR) at HHS investigated and found a cascade of failures under both the HIPAA privacy and security rules. No current risk analysis. No device-level encryption policy. No documentation showing anyone had even considered these basics.

That's the case of Banner Health, which paid $1.25 million after a breach affecting nearly 3 million people. It followed a pattern I've seen over two decades of consulting: organizations that treat the privacy and security rules as separate checklists instead of an integrated system.

This post breaks down what the HIPAA privacy and security rules actually require, how OCR enforces them, and the specific steps that separate organizations that thrive from those that write settlement checks.

What Are the HIPAA Privacy and Security Rules?

The HIPAA Privacy Rule governs who can access, use, and disclose protected health information (PHI) in any form — paper, verbal, or electronic. It establishes patients' rights over their health data and sets limits on what covered entities and business associates can do with it.

The HIPAA Security Rule narrows the focus to electronic PHI (ePHI). It requires covered entities to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. You can read the full regulatory text at 45 CFR Part 164.

Think of it this way: the Privacy Rule tells you what to protect and when you can share it. The Security Rule tells you how to protect it when it lives on a server, laptop, or cloud platform.

Where Most Organizations Trip Up

In my experience, the confusion starts when people treat these as two separate compliance projects. They're not. A nurse who accesses a patient record without authorization violates the Privacy Rule. But the system that let her access it without proper controls? That's a Security Rule failure. OCR investigates both simultaneously, and penalties stack.

I've audited behavioral health clinics, pharmacies, and large hospital systems. The mistake is almost always the same: policies exist on paper, but nobody trained the staff, and nobody tested the controls.

The Privacy Rule: More Than a Notice on a Clipboard

Every covered entity posts a Notice of Privacy Practices. Most patients ignore it. But the Privacy Rule's requirements go far deeper than that notice.

Minimum Necessary Standard

Your workforce should only access the PHI they need for their specific job function. A billing coordinator doesn't need therapy notes. A front desk receptionist doesn't need lab results. If your EHR gives everyone the same access level, you have a minimum necessary problem — and it's one of the most common Privacy Rule violations I encounter.

Patient Rights That Create Real Obligations

The Privacy Rule gives patients the right to access their records, request amendments, and receive an accounting of disclosures. Under the HHS Right of Access Initiative, OCR has aggressively enforced patients' access rights since 2019. Settlements in these cases have ranged from $3,500 to $240,000 — often against small practices that simply didn't respond to record requests within 30 days.

If you're running a nursing team or a behavioral health practice, your staff needs to know these timelines cold. Our HIPAA training for nurses in clinical workflow covers these obligations in detail, mapped to the actual scenarios your team faces daily.

The Security Rule: Three Safeguard Categories That Actually Matter

The Security Rule organizes its requirements into three categories. Every one of them has produced enforcement actions.

Administrative Safeguards

This is where the risk analysis lives — and where the majority of OCR penalties land. A risk analysis isn't a one-time checklist. It's an ongoing, documented process that identifies threats to ePHI, evaluates your current controls, and drives remediation.

I've reviewed risk analyses that were three pages long and covered nothing. I've also seen 200-page documents that no one in leadership had ever read. Both fail. What OCR wants is evidence that your organization identified real threats, assigned someone to fix them, and followed up.

Physical Safeguards

Workstation security, device disposal, facility access controls. Think about every laptop, tablet, and desktop in your organization. Now think about what happens when an employee leaves. If you don't have a documented process for revoking access and recovering devices, you have a physical safeguard gap.

Technical Safeguards

Encryption, access controls, audit logs, transmission security. Encryption is addressable under the Security Rule, which means you can choose not to encrypt — but you must document why and implement an equivalent measure. In practice, I've never seen an organization successfully argue that encryption wasn't reasonable. Just encrypt everything.

How OCR Actually Enforces the HIPAA Privacy and Security Rules

OCR enforcement follows a predictable pattern. A breach gets reported. OCR investigates. They find not just the breach itself but the underlying compliance failures that enabled it.

The Anthem Lesson: $16 Million

In 2018, Anthem Inc. paid $16 million to settle HIPAA violations after a cyberattack exposed nearly 79 million records. OCR found that Anthem had failed to conduct an enterprise-wide risk analysis, failed to implement sufficient procedures to review information system activity, and failed to identify and respond to suspected or known security incidents. Every one of those failures maps to a specific Security Rule standard.

Penalty Tiers You Should Know

OCR uses a four-tier penalty structure based on the level of culpability:

  • Tier 1 (Did not know): $137 to $68,928 per violation
  • Tier 2 (Reasonable cause): $1,379 to $68,928 per violation
  • Tier 3 (Willful neglect, corrected): $13,785 to $68,928 per violation
  • Tier 4 (Willful neglect, not corrected): $68,928 to $2,067,813 per violation

These amounts are adjusted annually for inflation. When you have hundreds or thousands of affected records, each one can constitute a separate violation. The math gets catastrophic fast.

Workforce Training: The Cheapest Insurance You're Probably Skipping

Both the Privacy Rule and the Security Rule require workforce training. Not suggested — required. And not just at onboarding. The Security Rule at 45 CFR § 164.308(a)(5) mandates ongoing security awareness training and periodic reminders.

Here's what I've seen consistently: organizations that invest in role-specific training have fewer breaches, faster incident response times, and dramatically better outcomes if OCR comes knocking. Generic annual training videos don't cut it. A pharmacy technician faces different PHI risks than a psychiatric nurse practitioner.

That's why role-specific programs matter. Our HIPAA and HITECH training for pharmacy professionals addresses the unique handling requirements for prescription data and third-party disclosures. For behavioral health settings, our HIPAA training for mental and behavioral health goes deep on 42 CFR Part 2 crossover issues and psychotherapy note protections.

The Breach Notification Rule Ties It All Together

When a breach of unsecured PHI happens, the Breach Notification Rule kicks in. You must notify affected individuals within 60 days, notify HHS, and — if the breach affects 500 or more people — notify prominent media outlets in the affected jurisdiction.

This is the rule that makes everything public. Every breach of 500+ records appears on the HHS Breach Portal, sometimes called the "Wall of Shame." Once your organization's name appears there, patients, partners, and payers all see it.

I've watched organizations spend more on breach notification logistics — printing, mailing, call centers — than they would have spent on the controls that would have prevented the breach in the first place.

Your Compliance Checklist for 2026

If you do nothing else this quarter, tackle these five items:

  • Update your risk analysis. If it hasn't been revised in the last 12 months, it's stale.
  • Audit user access. Review who has access to what, and revoke anything that violates the minimum necessary standard.
  • Encrypt all ePHI at rest and in transit. No exceptions, no excuses.
  • Train by role. Generic training fails. Match training content to the actual PHI your staff handles.
  • Test your breach response plan. Run a tabletop exercise. Time your response. Document the results.

The Real Cost of Getting the HIPAA Privacy and Security Rules Wrong

The financial penalties grab headlines. But the real damage is operational. I've seen practices lose referring physicians because of a publicized breach. I've watched health systems spend 18 months under a corrective action plan that consumed their compliance team's entire bandwidth.

Getting the HIPAA privacy and security rules right isn't about perfection. It's about documented, ongoing effort. OCR doesn't expect you to be breach-proof. They expect you to have tried — genuinely, with evidence — to protect the PHI your patients trusted you with.

That effort starts with knowing what the rules actually say, training your workforce to follow them, and building a culture where compliance isn't a department — it's a reflex. Explore our full HIPAA training catalog to find the right program for your team.