A Nurse, a Waiting Room, and a $4.3 Million Problem

In 2016, a nurse at a New York hospital mentioned a patient's HIV status within earshot of a waiting room full of people. The patient filed a complaint. The investigation snowballed. And by the time the Office for Civil Rights finished with Memorial Hermann Health System — a different but equally instructive case — the organization paid $2.4 million to settle Privacy Rule violations that stemmed from impermissible disclosures of protected health information.

So what is the purpose of HIPAA privacy rule? It exists to prevent exactly this kind of harm — and the answer goes much deeper than most people realize.

If you work in healthcare, you've probably sat through a training that reduced the Privacy Rule to a single slide: "Don't share patient info." That's not wrong, but it misses almost everything that matters. The Privacy Rule is a federal framework that governs how covered entities and business associates use, disclose, and safeguard protected health information (PHI). It gives patients enforceable rights over their own health data. And it gives the U.S. Department of Health and Human Services the authority to impose real consequences when organizations get it wrong.

The Privacy Rule Isn't Just About Secrecy — It's About Balance

Here's something I tell every client in the first five minutes: the HIPAA Privacy Rule was never designed to lock down health information entirely. It was designed to strike a balance between protecting patient privacy and allowing the flow of information needed to deliver quality care.

The rule establishes the minimum necessary standard — the idea that you should only access, use, or disclose the minimum amount of PHI required to accomplish the task at hand. A billing clerk doesn't need psychotherapy notes. A lab technician doesn't need your patient's home address. The Privacy Rule draws these lines.

It also sets the conditions under which PHI can be disclosed without patient authorization — for treatment, payment, and healthcare operations (known as TPO). This is where the balance lives. Without these provisions, hospitals would grind to a halt.

What Exactly Does the Privacy Rule Protect?

The Privacy Rule protects all individually identifiable health information held or transmitted by a covered entity or its business associate, in any form — electronic, paper, or oral. This is PHI. It includes names, dates of birth, Social Security numbers, diagnoses, treatment records, billing records, and even IP addresses when linked to health information.

The rule applies to three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically. It also extends to business associates — the IT vendors, billing companies, shredding services, and cloud platforms that handle PHI on behalf of covered entities.

Six Patient Rights You're Probably Underenforcing

One of the most overlooked purposes of the Privacy Rule is that it grants patients a set of concrete, enforceable rights. In my experience, most covered entities are weakest here. They focus on "don't disclose" and forget about "must provide."

Here are the six rights patients hold under the Privacy Rule:

  • Right to access their own PHI, including electronic copies
  • Right to request amendments to their records
  • Right to an accounting of disclosures made outside of TPO
  • Right to request restrictions on certain uses and disclosures
  • Right to confidential communications — for example, asking that appointment reminders go to a different phone number
  • Right to receive a Notice of Privacy Practices that explains how their PHI will be used

OCR has made patient access a top enforcement priority. In its Right of Access Initiative, the agency has settled more than 45 cases with penalties ranging from $3,500 to $240,000 — all because organizations failed to provide patients with timely access to their own records.

The $1.9 Million Lesson Most Dental Offices Haven't Learned Yet

Small practices often assume HIPAA enforcement is aimed at large hospital systems. That assumption is dangerously wrong.

In 2019, OCR settled with a dental practice management company, Dental Associates, for violations that included lack of proper workforce training and failure to implement adequate Privacy Rule safeguards. The settlements in similar small-to-mid-size cases have ranged from tens of thousands to well over a million dollars.

Here's what I see in the field: small practices skip training, use outdated Notice of Privacy Practices forms, and never update their policies. They assume compliance is a one-time checkbox. The Privacy Rule requires ongoing workforce training, regular policy reviews, and documented procedures for every standard it establishes.

If your staff handles PHI — and they do — investing in role-specific training is essential. Our HIPAA training for nurses and clinical workflow course covers exactly how clinical staff should apply Privacy Rule requirements in daily practice.

Verbal Disclosures: The Biggest Blind Spot

Most people think of the Privacy Rule in terms of electronic records. But remember — the rule covers PHI in any form, including oral disclosures. This is where most frontline violations happen.

I've watched check-in staff call out full names and appointment reasons in crowded lobbies. I've heard nurses discuss patient conditions in elevators. I've seen therapists leave detailed voicemails on shared family phone lines. Each one of these is a potential Privacy Rule violation.

Verbal disclosures are hard to audit, easy to make, and almost impossible to undo. That's why we built an entire course around them: Verbal Disclosures: Watch What You Say. It covers real scenarios your staff will recognize — because the Privacy Rule doesn't just govern what's in the EHR. It governs what comes out of your mouth.

What Is the Purpose of HIPAA Privacy Rule? The Direct Answer

The purpose of the HIPAA Privacy Rule is to establish national standards that protect individuals' medical records and other individually identifiable health information. It requires appropriate safeguards to protect the privacy of PHI. It sets limits and conditions on the uses and disclosures of PHI without patient authorization. And it gives patients rights over their health information, including the right to examine and obtain a copy of their health records and to request corrections.

This framework is codified at 45 CFR Part 164, Subpart E — the regulatory text that every compliance officer should have bookmarked.

How OCR Actually Enforces the Privacy Rule

OCR enforces the Privacy Rule through a tiered penalty structure based on the level of negligence involved. Penalties fall into four categories:

  • Tier 1: The covered entity didn't know and couldn't have known — $137 to $68,928 per violation
  • Tier 2: Reasonable cause, not willful neglect — $1,379 to $68,928 per violation
  • Tier 3: Willful neglect, corrected within 30 days — $13,785 to $68,928 per violation
  • Tier 4: Willful neglect, not corrected — $68,928 per violation, with an annual cap of $2,067,813

These numbers are adjusted annually for inflation. And they stack. A single breach affecting 10,000 patients can produce penalties in the millions.

Beyond financial penalties, OCR can impose corrective action plans that require years of external monitoring — a costly, disruptive process that consumes leadership attention and IT resources.

Mental Health Records Get Extra Protection — And Extra Scrutiny

The Privacy Rule carves out additional protections for psychotherapy notes. These are the personal notes a mental health provider keeps separate from the medical record. They cannot be disclosed for treatment, payment, or healthcare operations without explicit patient authorization — a higher bar than standard PHI.

If your organization provides behavioral health services, your staff needs to understand where this line falls. A progress note in the chart is not the same as a psychotherapy note. Mixing them up can create both Privacy Rule violations and trust breakdowns with vulnerable patient populations. Our HIPAA training for mental and behavioral health course breaks down these distinctions with practical, real-world scenarios.

Three Things You Should Do This Week

If you've read this far, you already care about compliance. Here's where to channel that energy:

  • Audit your Notice of Privacy Practices. When was it last updated? Does it reflect current uses of PHI, including telehealth and patient portals? If it still references pre-2013 language, you're overdue.
  • Spot-check your access request process. Submit a test request as if you were a patient. Time how long it takes to fulfill. If it exceeds 30 days (or 60 with an extension), you're outside the Privacy Rule's requirements.
  • Schedule role-specific Privacy Rule training. Generic annual HIPAA training isn't enough. Nurses face different privacy scenarios than billing staff. Front desk workers face different risks than IT administrators. Browse our full training catalog and match courses to the roles on your team.

The Privacy Rule Is a Living Obligation

The HIPAA Privacy Rule isn't a document you read once during onboarding. It's a living regulatory framework that touches every department, every workflow, and every conversation in your organization. It protects patients. It constrains staff. And when violated, it triggers enforcement actions that can reshape your organization's future.

Understanding what the Privacy Rule actually requires — not just the surface-level "don't share PHI" version — is the difference between genuine compliance and a settlement agreement with your name on it.