decisionhealth Newsletters, Coder Pink Sheets - 2019 Issue 2 (February)
Compliance: Avoid big fines for small HIPAA breaches
Subscribe or sign in to view the full article.
Article Overview
This article reviews HIPAA privacy enforcement for small and seemingly isolated breaches in physician practices. It discusses why minor disclosures can still draw OCR attention, what types of incidents may be considered reportable or incidental, and why practices should have policies for logging events, preserving records, responding to disclosures, and applying disciplinary measures. The piece is aimed at compliance staff, practice managers, and physicians who need to understand general HIPAA breach-response obligations and enforcement risk.
Why This Topic Matters
Small practices may assume minor privacy incidents will not attract scrutiny, but OCR can still investigate and penalize failures in policy, documentation, mitigation, and workforce discipline. Understanding the article helps organizations reduce regulatory risk and strengthen HIPAA compliance readiness.
Article Sections
-
Small fish not exempt
Discusses OCR attention to smaller breaches and the kinds of privacy incidents that can occur in everyday practice settings. The section frames the compliance risk for smaller organizations and highlights broader enforcement focus.
-
Many little breaches reportable
Explores how certain small disclosures may be viewed under HIPAA breach analysis and the kinds of mitigation steps organizations may consider. It also addresses the general shift toward presuming a disclosure is a breach unless an exception applies.
-
Do sanctions, no exceptions
Covers the importance of documenting incidents, retaining records, and using pre-established disciplinary policies after a privacy event. The section emphasizes having internal procedures and documentation ready for review during an investigation.
What You Will Learn
- How OCR may view smaller HIPAA privacy incidents involving limited disclosures
- Why documented HIPAA policies and workforce sanctions matter after a breach
- What general types of mitigation and response steps practices may consider
- Why recordkeeping and internal procedures are important in breach investigations
Who Should Read This
- Physician practices
- Practice managers
- HIPAA privacy officers
- Compliance professionals
- Healthcare attorneys
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com