A Single Fax Changed Everything for This Hospital
In 2018, a hospital employee in Tennessee faxed a patient's psychiatric records to the wrong number. The pages landed at a local gym. The gym owner called the patient directly to let her know. Within eighteen months, the Office for Civil Rights had opened an investigation, and the hospital faced a corrective action plan that consumed thousands of staff hours.
That's the kind of scenario most people never think about when they ask what HIPAA laws protect. The answer isn't abstract. It's your therapy notes sitting on a stranger's fax machine. It's your HIV test results accessible to an employee who has no business seeing them. It's your billing records exposed in a data breach because a covered entity skipped basic encryption.
HIPAA laws protect something deeply personal: your health information — and by extension, your dignity, your employment prospects, and sometimes your physical safety. If you work in healthcare, understanding exactly what falls under that protection isn't optional. It's the foundation of everything you do.
What Exactly Do HIPAA Laws Protect?
At its core, HIPAA protects protected health information (PHI) — any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That covers paper records, electronic records (ePHI), and even verbal conversations.
PHI includes 18 specific identifiers defined by HHS. Names, dates of birth, Social Security numbers, medical record numbers, email addresses, biometric data — if it can be linked to a person's health condition, treatment, or payment history, HIPAA laws protect it.
The 18 Identifiers You Need to Know
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs and comparable images
- Any other unique identifying number or code
Strip all 18 of these from a dataset, and you have de-identified information that falls outside HIPAA's scope. Leave even one attached to a diagnosis or treatment note, and you're handling PHI that demands full HIPAA safeguards.
The Three Rules That Form the Shield
HIPAA's protection framework rests on three interlocking rules. I've seen organizations obsess over one while ignoring the other two — and that's exactly how breaches happen.
The Privacy Rule
The HIPAA Privacy Rule establishes national standards for when and how PHI can be used or disclosed. It gives patients rights: the right to access their records, the right to request corrections, and the right to know who has seen their information. Covered entities — health plans, healthcare clearinghouses, and most healthcare providers — must comply. You can review the full Privacy Rule on the HHS Privacy Rule page.
The Security Rule
The Security Rule focuses specifically on ePHI. It requires administrative, physical, and technical safeguards. Think access controls, audit logs, encryption, and facility security. If your organization stores any patient data electronically — and in 2026, that means every organization — the Security Rule applies to you.
The Breach Notification Rule
When protections fail, the Breach Notification Rule kicks in. Covered entities must notify affected individuals, HHS, and in some cases the media, within 60 days of discovering a breach. I've watched organizations try to quietly sweep incidents under the rug. OCR does not look kindly on that approach.
The $4.3 Million Mistake: What Happens When Protections Fail
In 2016, Advocate Medical Group settled with OCR for $5.55 million after multiple breaches affecting roughly 4 million patients. The issues included unencrypted laptops stolen from vehicles and an office break-in that exposed paper records. The technical failures were bad, but the real problem was systemic: insufficient risk analysis and a lack of physical safeguards for devices containing ePHI.
More recently, in 2023, Banner Health paid $1.25 million to settle potential HIPAA violations after a 2016 cyberattack exposed the ePHI of nearly 2.81 million individuals. OCR found that Banner had failed to conduct an adequate risk analysis — a foundational requirement of the Security Rule. You can see the full list of enforcement results on the OCR Resolution Agreements page.
These aren't edge cases. They're what happens when organizations treat HIPAA protections as paperwork instead of practice.
Who Must Follow These Rules?
HIPAA laws protect PHI by placing obligations on specific types of organizations:
- Covered entities: Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
- Business associates: Any organization that handles PHI on behalf of a covered entity — billing companies, IT vendors, cloud storage providers, shredding services, even law firms.
If you're a business associate, you're directly liable under HIPAA since the 2013 Omnibus Rule. I still encounter vendors who believe they're somehow exempt. They're not.
What HIPAA Does NOT Protect
Here's where confusion multiplies. HIPAA laws protect PHI held by covered entities and business associates. They do not cover:
- Health data in fitness apps or wearables (unless connected to a covered entity)
- Employment records held by an employer in its role as employer
- Student health records covered by FERPA
- Data shared voluntarily on social media
- Information held by life insurers, workers' compensation carriers, or most schools
I've had patients contact me furious that their employer accessed health information — only to discover the data came from an occupational health form outside HIPAA's jurisdiction. Knowing the boundaries of what HIPAA laws protect is just as important as knowing what falls inside them.
Your Patients' Rights Under HIPAA: A Quick-Reference Answer
What rights do patients have under HIPAA? Patients have the right to access and obtain copies of their PHI, request amendments to inaccurate records, receive an accounting of disclosures, request restrictions on certain uses of their PHI, request confidential communications (such as calling a cell phone instead of a home number), and file complaints with OCR if they believe their rights have been violated. These rights are enforceable, and covered entities face penalties for ignoring them.
State Laws Add Another Layer
HIPAA sets the federal floor, not the ceiling. Many states impose stricter requirements. Texas, for instance, enforces the Texas Medical Records Privacy Act (HB 300), which in some areas exceeds federal HIPAA standards — particularly around training requirements and unauthorized disclosure penalties. If your workforce operates in Texas, you need targeted training on those state-specific obligations. Our Texas Medical Records Privacy Act (HB 300) Training covers exactly that.
California, New York, and several other states have their own overlapping frameworks. The rule of thumb: when state law is more protective than HIPAA, state law wins.
Workforce Training: The Protection That Actually Works
I've reviewed hundreds of breach investigations over the years. The technical failures get the headlines, but the root cause is almost always human. An employee who didn't know the rules. A manager who never completed workforce training. A front-desk coordinator who shared a password because "it was faster."
HIPAA requires covered entities to train every member of their workforce — not just clinicians. That includes volunteers, interns, and contractors with access to PHI. Training must be documented, and it must be refreshed when policies change or new risks emerge.
If your training program hasn't been updated since 2023, it's already outdated. Cyber threats evolve quarterly, and OCR expectations evolve with them. Browse our full HIPAA training catalog to find role-specific courses that meet current requirements.
How to Verify Your Organization's Protections Right Now
Here's a five-point check I give every client:
- Risk analysis: Have you completed a thorough, documented risk analysis in the last 12 months? Not a checklist — a genuine assessment of threats to ePHI.
- Access controls: Can every employee access only the minimum necessary PHI for their job function?
- Encryption: Is ePHI encrypted at rest and in transit on every device, including mobile phones and laptops?
- Business associate agreements: Do you have current, signed BAAs with every vendor that touches PHI?
- Incident response plan: Does your team know exactly what to do in the first 24 hours after discovering a potential breach?
If you hesitated on any of those, you have work to do. OCR doesn't grade on a curve.
The Bottom Line on What HIPAA Laws Protect
HIPAA laws protect the information that patients trust you with during the most vulnerable moments of their lives. A cancer diagnosis. A mental health crisis. A child's medical history. That data deserves more than a policy binder on a shelf.
It demands encryption, training, accountability, and a culture that treats privacy as a professional obligation — not an IT problem. Every breach of that trust carries consequences: financial penalties from OCR, reputational damage you can't undo, and real harm to real people.
Your next step is straightforward. Audit your safeguards. Train your workforce. Close the gaps before OCR finds them for you. The HHS Security Rule guidance page is a solid starting point for technical requirements. Then make sure every person in your organization who touches PHI understands exactly what they're protecting — and why it matters.