decisionhealth Newsletters, Part B News - 2018 Issue 12 (December)
Make sanction policy, hit other marks to avoid big fines for small HIPAA breaches
Subscribe or sign in to view the full article.
Article Overview
This article discusses HIPAA privacy breach handling for physician practices, with emphasis on how even limited disclosures can draw regulatory scrutiny. It covers breach recognition, reportability considerations, documentation expectations, and the need for consistent disciplinary policies and corrective action procedures. The piece is aimed at compliance officers, practice managers, physicians, and other covered entity staff who handle protected health information.
Why This Topic Matters
Small practices may assume minor incidents are unlikely to trigger enforcement, but the article shows that regulators may still expect formal policies, documentation, and sanctions. It matters because having the right internal procedures can affect compliance readiness and response to OCR review.
Article Sections
-
Case example and enforcement context
Introduces a HIPAA privacy incident involving a physician practice and summarizes why the matter drew regulatory attention. It frames the article’s focus on compliance expectations for smaller organizations.
-
Small fish not exempt
Discusses how smaller breaches and routine privacy mistakes can still become compliance issues. It also addresses OCR’s focus on lower-volume breach investigations and general concerns for small practices.
-
Little breach reportable
Reviews general considerations around whether a privacy incident should be treated as reportable and what kinds of situations may fall into broader breach-assessment discussions. It also mentions mitigation efforts and documentation-related caution.
-
Do sanctions, no exceptions
Covers the need for incident logging, retention, and employee discipline policies after a breach or privacy violation. It also emphasizes the importance of having written procedures and consistent internal enforcement.
What You Will Learn
- How HIPAA breach issues can affect small medical practices
- What general factors influence whether a privacy incident may be reportable
- Why documentation and record retention matter after a privacy incident
- Why practices need pre-established disciplinary and corrective action policies
- How compliance expectations can apply across different staff roles
Who Should Read This
- Physician practices
- Practice managers
- HIPAA privacy officers
- Compliance officers
- Healthcare administrators
- Covered entity staff
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com