HIPAA: Safeguard Practice Property to Avoid Theft-Related Violations

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article discusses HIPAA security compliance with a focus on physical safeguards, device protection, and facility security. It uses a reported breach involving stolen property and encrypted laptops as context for why practices should maintain policies, monitoring, access controls, and technical protections alongside office security measures. The piece is intended for healthcare compliance staff, practice managers, and others responsible for protecting protected health information and electronic systems.

Why This Topic Matters

The article is relevant because theft, unauthorized access, and weak physical controls can create HIPAA risk just as much as technical attacks. It helps readers understand the broader security posture expected of covered entities and why documented safeguards matter when incidents are reviewed by regulators.

Article Sections

  1. Background

    Provides context for a reported breach and discusses the types of information and property affected. It frames the security issues that follow in the article.

  2. Follow Federal Requirements to Avoid Problems

    Summarizes the HIPAA Security Rule’s physical safeguard requirements and describes broad categories of facility, workstation, and device protections. It also touches on the role of policies and risk management.

  3. Don’t Be Fooled — Physical Security Is Still Important

    Addresses common misconceptions about breach risk and emphasizes the importance of physical security alongside network protection. It broadens the discussion to practical security priorities for healthcare settings.

What You Will Learn

  • How HIPAA physical safeguards fit into overall security compliance
  • Why facility security and device protection are both important
  • What broad categories of controls are discussed for protecting PHI and ePHI
  • Why documented policies and monitoring can matter after an incident
  • How theft and physical access risks relate to privacy and security violations

Who Should Read This

  • Healthcare compliance professionals
  • Practice managers
  • Privacy and security officers
  • Medical office administrators
  • Covered entity staff responsible for HIPAA compliance

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?