A Nurse, a Hallway, and a $387,200 Penalty
In 2019, the Office for Civil Rights settled with a medical center in Tennessee after staff discussed a patient's HIV status within earshot of other patients. It wasn't a cyberattack. It wasn't a lost laptop. It was a conversation. That single verbal disclosure cost the organization $387,200 in a settlement with HHS.
So what are the privacy rules of HIPAA, and how do they reach into something as everyday as a hallway conversation? If you're a covered entity — a health plan, healthcare clearinghouse, or healthcare provider who transmits health information electronically — the answer touches every workflow in your organization.
I've spent years consulting with clinics, hospitals, and behavioral health practices that thought they understood HIPAA's privacy requirements. Most of them had blind spots big enough to drive an OCR investigation through. This post breaks down the actual rules, the real penalties, and the practical steps that keep your organization on the right side of compliance.
The HIPAA Privacy Rule: What It Actually Requires
The HIPAA Privacy Rule — formally 45 CFR Part 160 and Part 164, Subparts A and E — establishes national standards for protecting individually identifiable health information, known as protected health information (PHI). You can read the full Privacy Rule summary on HHS.gov.
Here's the short version: PHI includes any information that can identify a patient and relates to their past, present, or future health condition, treatment, or payment. That means names, dates of birth, Social Security numbers, medical record numbers, and even photographs — when linked to health information.
The Privacy Rule applies to covered entities and their business associates. It governs how PHI is used, disclosed, stored, and transmitted in any form — paper, electronic (ePHI), or verbal.
The Six Core Requirements You Can't Ignore
- Notice of Privacy Practices (NPP): Every covered entity must provide patients a clear notice explaining how their PHI may be used and their rights regarding that information.
- Minimum Necessary Standard: You can only use or disclose the minimum amount of PHI needed to accomplish the task. Not the whole chart. Not the full history. Just what's needed.
- Patient Rights: Individuals have the right to access their records, request amendments, receive an accounting of disclosures, and request restrictions on certain uses.
- Authorization Requirements: Uses of PHI beyond treatment, payment, and healthcare operations generally require written patient authorization. Marketing and sale of PHI always require it.
- Workforce Training: Every member of your workforce — including volunteers, trainees, and contractors under your direct control — must receive training on your privacy policies and procedures.
- Safeguards: You must implement administrative, physical, and technical safeguards to protect PHI from unauthorized access, use, or disclosure.
Treatment, Payment, and Operations: The Exceptions That Trip People Up
The Privacy Rule permits use and disclosure of PHI without patient authorization for three core purposes: treatment, payment, and healthcare operations (TPO). This is where I see the most confusion.
Treatment means sharing information between providers for patient care. A referring physician sending records to a specialist? That's treatment. Payment covers activities like billing, claims management, and utilization review. Healthcare operations include quality assessment, training programs, and compliance activities.
But TPO doesn't mean open season. The minimum necessary standard still applies to payment and operations disclosures. And here's the part most organizations miss: it does not apply to disclosures for treatment purposes between providers. That distinction matters in daily clinical workflow.
When Authorization Is Non-Negotiable
Outside of TPO, public health activities, law enforcement requests, and a few other carved-out exceptions, you need a valid written authorization from the patient. This is especially critical in behavioral health settings, where substance use disorder records carry additional federal protections under 42 CFR Part 2.
If your staff works in mental or behavioral health, the stakes are even higher. Our HIPAA training for mental and behavioral health professionals covers exactly these layered requirements — because getting it wrong in this space carries both regulatory and clinical consequences.
The $1.9 Million Lesson Most Organizations Haven't Learned Yet
In 2020, OCR settled with Premera Blue Cross for $6.85 million after a breach affecting over 10.4 million individuals. But you don't need a massive breach to draw OCR's attention. In 2022, OCR settled with Dr. Allison Dermatology for $25,000 — a small practice — over impermissible disclosures of patient PHI on a social media page.
The pattern I see across enforcement actions is consistent: organizations that lack documented policies, skip workforce training, or fail to conduct risk assessments get caught. OCR's resolution agreements page tells the story clearly — the penalties range from tens of thousands to millions, and practice size doesn't protect you.
Your risk assessment isn't a one-time checkbox. It's an ongoing process that must identify where PHI lives, who accesses it, and what threats exist. Skip it, and you've handed OCR the evidence they need.
Verbal Disclosures: The Privacy Violation Hiding in Plain Sight
I've walked through hospital corridors and heard patient names, diagnoses, and medication details discussed at full volume. Every single one of those conversations is a potential privacy rule violation.
The Privacy Rule doesn't just govern electronic records and paper files. It covers verbal disclosures of PHI — what your staff says, where they say it, and who might overhear. Nurses' stations, shared offices, elevator conversations, and phone calls in public spaces are all risk points.
Reasonable safeguards for verbal disclosures include lowering voices, moving to private areas, using closed doors, and avoiding speakerphone in shared spaces. These aren't suggestions — they're requirements under the Privacy Rule. If you want a deep dive on this specific risk area, our course on verbal disclosures and PHI walks your team through realistic scenarios and practical solutions.
What Are the Privacy Rules of HIPAA? A Quick-Reference Answer
The HIPAA Privacy Rule establishes national standards that protect individuals' medical records and personal health information. It applies to covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and their business associates. The rule gives patients rights over their health information, sets limits on who can access and receive PHI, requires covered entities to implement safeguards, mandates workforce training, and requires a Notice of Privacy Practices. Violations can result in civil monetary penalties from $141 to over $2 million per violation category per year, with criminal penalties reaching up to $250,000 and ten years imprisonment for knowing misuse of PHI.
Breach Notification: What Happens When the Privacy Rule Fails
When a privacy violation involves an impermissible use or disclosure that compromises the security or privacy of PHI, the Breach Notification Rule kicks in. Covered entities must notify affected individuals, HHS, and in some cases the media, within 60 days of discovering the breach.
I've seen organizations delay notification because they weren't sure a breach had occurred. That's the wrong move. The rule presumes an impermissible disclosure is a breach unless you can demonstrate — through a documented risk assessment — a low probability that PHI was compromised. Document everything. Assume the worst. Move fast.
The Four-Factor Risk Assessment for Breaches
- The nature and extent of the PHI involved
- The unauthorized person who used or received the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which risk has been mitigated
If your risk assessment can't demonstrate low probability of compromise across all four factors, you have a reportable breach. Period.
Training Isn't Optional — And Annual Isn't Enough
The Privacy Rule at 45 CFR § 164.530(b) requires workforce training on your organization's privacy policies and procedures. New workforce members must be trained within a reasonable period after joining. And when you change policies or procedures, you must retrain affected staff.
In my experience, organizations that treat training as a once-a-year checkbox end up with staff who can't identify a minimum necessary violation when it's standing right in front of them. Clinical teams need scenario-based training grounded in the workflows they actually use.
Our HIPAA training for nurses and clinical staff is built around exactly this approach — real situations, real decision points, real accountability. Because the Privacy Rule doesn't care whether your nurse "meant well." It cares whether your organization trained them to do better.
Five Steps to Lock Down Your Privacy Rule Compliance in 2026
1. Conduct a Fresh Risk Assessment
Map every location where PHI exists — paper, electronic, verbal. Identify who has access. Document the threats and vulnerabilities. Do this at least annually.
2. Update Your Notice of Privacy Practices
HHS has proposed changes to the Privacy Rule. Make sure your NPP reflects current requirements and any new amendments. Post it visibly and hand it to every new patient.
3. Audit Your Business Associate Agreements
Every vendor that touches PHI on your behalf needs a current, signed BAA. I've seen organizations with agreements that haven't been updated since 2013. That's a compliance gap with teeth.
4. Implement Role-Based Access Controls
The minimum necessary standard means your front desk staff shouldn't see psychotherapy notes. Your billing team doesn't need clinical narratives. Configure your EHR to enforce this.
5. Train Your Workforce — Then Train Them Again
Document every training session. Track attendance. Test comprehension. When someone fails to follow procedure, retrain and document that too. OCR looks for evidence of ongoing commitment, not a dusty binder from three years ago.
The Bottom Line on HIPAA's Privacy Rules
The privacy rules of HIPAA aren't abstract regulatory language. They're the standards that determine whether your patient's diagnosis stays between them and their provider — or ends up overheard in a hallway, posted on social media, or exposed in a data breach.
Every enforcement action I've studied has the same root cause: someone decided the rules didn't apply to their situation. They were wrong, and HHS made them pay for it — literally.
Your organization can do better. Start with understanding what the Privacy Rule actually demands, train your workforce to meet those demands, and build a culture where protecting PHI isn't a burden. It's the baseline. Explore our full HIPAA training catalog to find the right course for every role in your organization.