A $4.3 Million Penalty That Started with One Missing Rule

In 2016, Advocate Health Care Network paid $5.55 million to settle HIPAA violations involving unencrypted laptops and a lack of comprehensive risk analysis. The breaches affected over 4 million patients. When OCR investigators dug in, they didn't find a single catastrophic failure. They found a pattern — an organization that never fully understood the rules of HIPAA well enough to build real protections around patient data.

I've seen this pattern repeat for over a decade. Organizations know HIPAA exists. They know it involves patient privacy. But when I ask a practice manager or IT director to name the specific rules and what each one requires? Silence. That gap between awareness and understanding is where enforcement actions live.

This post breaks down every core rule, explains what each one demands of your organization, and shows you exactly where the penalties hit hardest.

What Are the Rules of HIPAA?

HIPAA isn't a single regulation. It's a framework built on several interlocking rules, each addressing a different dimension of protecting health information. Here's the short answer that every compliance officer should be able to recite:

The rules of HIPAA include the Privacy Rule, the Security Rule, the Breach Notification Rule, the Enforcement Rule, and the Omnibus Rule. Together, they govern how covered entities and business associates handle protected health information (PHI) — from collection to storage to disclosure to destruction.

Let's pull each one apart.

The Privacy Rule: Who Can See What, and When

The HIPAA Privacy Rule establishes national standards for when and how PHI can be used or disclosed. It applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically.

What the Privacy Rule Actually Requires

Your organization must limit PHI use and disclosure to the minimum necessary for the task at hand. You need a Notice of Privacy Practices that tells patients their rights. You must honor patient requests to access, amend, or receive an accounting of disclosures of their records.

In my experience, the minimum necessary standard trips up more organizations than anything else. A billing clerk who can see a patient's psychiatric notes because "the system gives everyone access" — that's a Privacy Rule violation waiting to become an OCR investigation.

Where Organizations Fail

I've walked into clinics where every employee, from the front desk to the janitor, had the same login credentials for the EHR. No role-based access. No audit logs worth examining. The Privacy Rule doesn't just say "protect PHI." It says limit access to the people who actually need it, for the specific purpose they need it.

The Security Rule: Protecting ePHI from Every Angle

If the Privacy Rule tells you what to protect, the Security Rule tells you how — specifically for electronic protected health information (ePHI). It mandates three categories of safeguards: administrative, physical, and technical.

Administrative Safeguards

These are the policies and procedures your organization puts in place. Risk analysis. Workforce training. Contingency planning. Designating a security official. This category represents over half of the Security Rule's requirements, and it's where OCR focuses most of its enforcement energy.

If you haven't conducted a thorough risk analysis in the past 12 months, your organization is already out of compliance. The HIPAA Fundamentals 2025 course walks through exactly what a compliant risk analysis looks like — and what happens when you skip it.

Physical Safeguards

Facility access controls. Workstation security. Device and media controls. If a laptop with ePHI can walk out the door without anyone noticing, you've got a physical safeguard failure. This is precisely what happened in the Advocate Health Care case — stolen laptops that were never encrypted, in facilities without adequate access controls.

Technical Safeguards

Access controls, audit controls, integrity controls, and transmission security. Encryption falls here. Multi-factor authentication falls here. The technical safeguards are where your IT team lives, but they can't build them in a vacuum — they need to understand the rules of HIPAA well enough to make smart architectural decisions.

The Breach Notification Rule: The Clock Is Already Ticking

When a breach of unsecured PHI occurs, the Breach Notification Rule dictates exactly what your organization must do — and how fast. Here's the timeline that catches people off guard:

  • Individual notification: Within 60 days of discovering the breach.
  • HHS notification: Within 60 days for breaches affecting 500+ individuals. For smaller breaches, you log them and report annually.
  • Media notification: Required for breaches affecting 500+ individuals in a single state or jurisdiction.

The 60-day window starts at discovery, not at the date of the breach itself. I've worked with organizations that didn't discover a breach for months. By the time they found it, they were already behind on notification requirements before they even started their investigation.

The Penalty for Delayed Notification

In 2017, Presence Health settled with OCR for $475,000 specifically for late breach notification. The breach itself was relatively small — paper operating room schedules affecting 836 individuals. The fine wasn't about what happened. It was about how long Presence took to report it.

The Enforcement Rule: How OCR Holds You Accountable

The Enforcement Rule gives OCR its teeth. It establishes investigation procedures, penalty structures, and hearing processes. It also created the tiered penalty system that determines how much a violation costs your organization.

The Four Penalty Tiers

  • Tier 1: The covered entity didn't know and couldn't have known. $137 to $68,928 per violation.
  • Tier 2: Reasonable cause, not willful neglect. $1,379 to $68,928 per violation.
  • Tier 3: Willful neglect, corrected within 30 days. $13,785 to $68,928 per violation.
  • Tier 4: Willful neglect, not corrected. $68,928 to $2,067,813 per violation.

These amounts are adjusted annually for inflation. The key word here is "per violation." A single systemic failure — like not conducting risk analyses for years — can generate hundreds of individual violations, each carrying its own penalty.

The Omnibus Rule: The Update That Changed Everything

The 2013 Omnibus Rule significantly expanded HIPAA's reach. It made business associates directly liable for Security Rule compliance. It tightened breach notification standards by replacing the old "harm" standard with a more objective risk assessment. And it strengthened patient rights to electronic copies of their records.

If your business associate agreements haven't been updated since the Omnibus Rule took effect, you're operating on outdated legal ground. I still encounter organizations using BAAs from 2010 or earlier. Those documents don't reflect current law.

How These Rules Work Together in Practice

Here's what I tell every client: don't think of these rules as separate checklists. They interlock. The Privacy Rule says you must limit PHI access. The Security Rule tells you how to enforce those limits technically. The Breach Notification Rule tells you what to do when those limits fail. The Enforcement Rule tells you what it costs when you don't comply.

Your workforce training program needs to reflect this interconnection. Staff don't need to memorize regulatory citations. They need to understand that every PHI decision they make sits at the intersection of multiple rules. The HIPAACertify training catalog builds this kind of practical, integrated understanding.

The $1.9 Million Lesson Most Small Practices Haven't Learned Yet

Small covered entities often assume OCR only goes after hospitals and health systems. That's dangerously wrong. In 2018, Cottage Health paid $3 million for a settlement involving unpatched systems and a flawed risk analysis. But smaller entities get hit too.

Children's Medical Center of Dallas paid $3.2 million in 2017 — a case that started with a lost BlackBerry in 2009 and an unencrypted laptop in 2013. The organization had known about its encryption gaps for years and failed to act.

Every one of these cases comes back to the same root cause: an incomplete understanding of the rules of HIPAA and a failure to implement the safeguards those rules require.

Your Next Step: Build Compliance from the Rules Up

If you've read this far, you already know more about HIPAA's structure than most people in your organization. The question is whether your team does too.

Workforce training isn't a box to check annually. It's the mechanism that translates regulatory requirements into daily behavior. Every person who touches PHI — from the surgeon to the scheduling coordinator — needs to understand why these rules exist and what they demand.

Start with a structured training program that covers all the core rules in practical terms. The HIPAA Fundamentals 2025 course is built to do exactly that — no legal jargon, no filler, just the knowledge your staff needs to keep your organization off OCR's enforcement page.

Because the rules of HIPAA aren't suggestions. They're the framework that keeps your patients safe, your data secure, and your organization out of seven-figure trouble.