A Single Fax to the Wrong Number Cost One Health System $4.3 Million
In 2016, Advocate Health Care Network agreed to a $5.55 million settlement with the Office for Civil Rights after multiple breaches exposed the electronic protected health information (ePHI) of roughly 4 million individuals. One incident involved unencrypted laptops. Another involved a business associate's unauthorized access. Every single violation traced back to the same root cause: the organization didn't fully understand — or fully implement — what the privacy rules of HIPAA actually demand.
I've spent years helping covered entities untangle this exact problem. Most organizations know HIPAA exists. Far fewer can articulate what the Privacy Rule specifically requires of them on a Tuesday afternoon when a patient's ex-spouse calls the front desk asking for lab results.
That's what this guide is for. Not a legal treatise. A working explanation of what the Privacy Rule covers, who it applies to, and where I see organizations trip up most often.
What Are the Privacy Rules of HIPAA, Exactly?
The HIPAA Privacy Rule is a set of federal standards published by the U.S. Department of Health and Human Services (HHS) that governs how covered entities and their business associates use and disclose protected health information — PHI. It was finalized in 2000 and has been amended several times since, most notably by the HITECH Act in 2009.
The Privacy Rule applies to three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit any health information electronically in connection with a HIPAA-covered transaction. If your organization bills electronically, you're almost certainly covered.
You can read the full regulatory text at HHS.gov's Privacy Rule page.
PHI: The Thing the Rule Protects
Protected health information includes any individually identifiable health information held or transmitted by a covered entity or its business associate. That means medical records, billing records, lab results, prescription histories, appointment schedules, and even verbal conversations. If it identifies a person and relates to their health condition, treatment, or payment — it's PHI.
A common mistake I see: organizations focus exclusively on electronic records and forget that PHI on paper or spoken aloud gets equal protection under the Privacy Rule. Our course on Verbal Disclosures: Watch What You Say walks through exactly how casual hallway conversations become compliance violations.
The Six Core Principles Hiding Inside the Privacy Rule
I break the Privacy Rule down into six working principles when I train staff. This isn't how HHS organizes the regulation, but it's how I've seen it stick in people's minds.
1. Minimum Necessary Standard
You disclose only the minimum amount of PHI needed to accomplish the purpose. A billing clerk doesn't need a patient's psychiatric notes to process a dental claim. This standard applies to internal uses, external disclosures, and requests for information. The only exception: treatment purposes, where clinicians can share what they need with other treating providers.
2. Patient Rights Over Their Own Information
Patients have a right to access their records, request amendments, get an accounting of disclosures, and request restrictions on how their PHI is used. They also have the right to receive a Notice of Privacy Practices before or at the first service encounter. OCR has enforced this aggressively — Cignet Health of Prince George's County was hit with a $4.3 million civil money penalty in 2011 partly because it refused to give 41 patients access to their medical records.
3. Permitted Uses and Disclosures
The Privacy Rule doesn't lock PHI in a vault. It specifies when disclosure is permitted without patient authorization: treatment, payment, and healthcare operations (TPO). Beyond TPO, certain disclosures are allowed for public health activities, law enforcement purposes, judicial proceedings, and other specific scenarios outlined in 45 CFR Part 164 Subpart E.
Everything outside those permitted categories requires a valid written authorization from the patient. Psychotherapy notes get even stricter protections — they generally require authorization even for TPO uses beyond the treating therapist.
4. Business Associate Agreements
If you share PHI with a vendor — a cloud hosting company, a billing service, an IT contractor — you need a signed Business Associate Agreement (BAA). The BAA isn't optional. It's a regulatory requirement, and the lack of one is a standalone HIPAA violation. I've seen organizations with airtight internal policies get cited because they never executed BAAs with their shredding companies.
5. Administrative Safeguards
The Privacy Rule requires covered entities to designate a Privacy Officer, develop and implement written privacy policies, train every member of their workforce, and establish sanctions for policy violations. "Workforce" under HIPAA includes employees, volunteers, trainees, and anyone under the organization's direct control — not just people on your payroll.
6. Documentation and Retention
Policies, authorizations, notices, and other Privacy Rule documentation must be retained for six years from the date of creation or the date it was last in effect, whichever is later. I've walked into audits where the organization had a solid privacy program but couldn't produce any documentation older than two years. That's a finding.
Where Most Organizations Actually Fail
After reviewing hundreds of privacy programs, I can tell you the failures cluster in three spots.
Workforce Training That Doesn't Exist — Or Doesn't Stick
OCR's enforcement actions tell a consistent story. When a breach occurs, one of the first questions investigators ask is: "Show me your training records." Not your training policy. Your actual training records — who completed what, and when.
In 2018, Allergy Associates of Hartford agreed to a $125,000 settlement after a physician disclosed a patient's PHI to a reporter. The root issue: the physician apparently didn't understand the Privacy Rule's requirements around media disclosures. Training wasn't just a box that needed checking — it was the frontline defense that failed.
If your workforce includes nurses and clinical staff, role-specific training matters. Our HIPAA Training for Nurses course is built around the actual clinical workflows where PHI exposure happens.
Verbal Disclosures in Public Spaces
This is the violation I see most often in the wild. Staff discussing patient information at nursing stations, in elevators, in cafeterias. The Privacy Rule doesn't require soundproof rooms for every conversation, but it does require reasonable safeguards. Speaking in lowered voices, moving conversations to private areas, and limiting the information shared are all expected.
Ignoring Mental Health PHI Protections
Behavioral health records carry additional sensitivities under both HIPAA and many state laws. Psychotherapy notes, substance use disorder records protected under 42 CFR Part 2, and certain mental health diagnoses all require extra handling. I've seen general acute-care hospitals violate these provisions because they applied their standard PHI policies to a behavioral health unit without adjustment. Our HIPAA Training for Mental & Behavioral Health addresses these exact scenarios.
What Happens When You Violate the Privacy Rule
OCR enforces the HIPAA Privacy Rule through investigations triggered by complaints and breach reports. Penalties follow a tiered structure based on the level of culpability:
- Tier 1 (Did Not Know): $137 to $68,928 per violation
- Tier 2 (Reasonable Cause): $1,379 to $68,928 per violation
- Tier 3 (Willful Neglect, Corrected): $13,785 to $68,928 per violation
- Tier 4 (Willful Neglect, Not Corrected): $68,928 to $2,067,813 per violation
These amounts are adjusted annually for inflation. The calendar-year cap for identical violations can reach over $2 million. You can review OCR's full enforcement results at the HHS Resolution Agreements page.
And penalties are just the financial piece. A breach triggers the Breach Notification Rule — you must notify affected individuals, HHS, and in some cases the media, within 60 days. The reputational damage often dwarfs the fine.
The Privacy Rule vs. the Security Rule: They're Not the Same Thing
I still encounter compliance officers who conflate the two. The Privacy Rule governs the use and disclosure of PHI in any form — paper, electronic, or oral. The Security Rule specifically addresses the technical, physical, and administrative safeguards for ePHI. You need both. But they solve different problems.
Think of it this way: the Privacy Rule tells you when you can share information. The Security Rule tells you how to protect the electronic version of that information from unauthorized access. A complete HIPAA compliance program addresses both.
A Quick Reference: Does the Privacy Rule Apply to You?
If you answer yes to any of these, the HIPAA Privacy Rule applies to your organization:
- You're a healthcare provider who transmits health information electronically for claims, referral authorizations, or other HIPAA transactions.
- You're a health plan — including employer-sponsored plans, health insurers, and government programs like Medicare and Medicaid.
- You're a healthcare clearinghouse that processes nonstandard health information into standard formats.
- You're a business associate that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
If none of those apply, the Privacy Rule likely doesn't govern your organization directly — though state privacy laws might.
Building a Privacy Program That Survives an OCR Investigation
Here's the practical checklist I give every client:
- Appoint a Privacy Officer with real authority and dedicated time.
- Conduct a PHI inventory. Map where PHI lives — every system, every filing cabinet, every shared drive.
- Write policies that match your operations. Boilerplate templates fail audits. Your policies must reflect how your organization actually handles PHI.
- Train every workforce member at hire and annually. Document completion. Make training role-specific.
- Execute BAAs before sharing PHI with any vendor. Audit existing vendors for gaps.
- Implement a complaint process. Patients and staff need a clear, non-retaliatory way to report concerns.
- Retain documentation for six years. Electronic storage with backup is your safest option.
Explore our full HIPAA training catalog for courses designed around every role in your workforce.
The Bottom Line on HIPAA's Privacy Rules
What are the privacy rules of HIPAA? They're federal standards that define who can access patient information, under what circumstances, and with what safeguards. They give patients real rights over their data. And they carry real penalties when organizations cut corners.
Every breach I've investigated had a moment where someone made a decision without understanding the Privacy Rule. A front-desk employee who released records to the wrong person. A clinician who texted PHI on an unsecured phone. A compliance officer who assumed the BAA was "probably somewhere in the files."
The rule isn't ambiguous. The failures are predictable. And the organizations that take privacy seriously — the ones that train, document, and actually follow their own policies — are the ones I never see on OCR's wall of shame.