Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.



What Is HIPAA Right of Access?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.


HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.


HIPAA Enforcement


HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.


In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.


Complying With the HIPAA Privacy Right of Access Rule


If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.


A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html


The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:


“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?


This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.


If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.


o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.

  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.


Resources to Comply With ROI and Right of Access


Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:


Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More
HIPAA Compliance
HIPAA

Allowing Workforce Members to Access Their Own Medical Records?

Written by: J. David Sims, CHITSP, CHMSP, Board Member of AIHC

J.David Sims is a Managing Partner at Security First IT, LLC; Speaker & HIPAA Instructor; Help Me with HIPAA Podcast Host; Contributor with the Federal HICP 405(d) Task Group & HIC-TCR Task Group; Founder & CEO of HIPAA for MSPs




The Health Insurance Portability & Accountability Act (HIPAA) has provisions to protect the contents of medical records. At a recent AIHC HIPAA training event, this topic came up. We would like to share some resources to the question that was asked. The information contained in this article is not consulting or legal advice and is provided for educational purposes only.


We have a problem with certain members of our workforce accessing their own medical records. These are people with fairly high levels of security and can access most records. I am a Certified HIPAA Compliance Officer (CHCO) through the AIHC organization and a compliance specialist. Our compliance committee wants the “industry standard” of this statement and evidence that this is industry standard. Do you have an idea of where I should look or any additional resource I can use to support that an employee should not access his/her own records? We want to institute a policy prohibiting this behavior.


Response

This is one of those areas that you won't find specifically mentioned (as HIPAA can't address every possible scenario). Therefore, we must look at what HIPAA does say and how does that fit into this scenario.


First, there should be a proper process for any patient (employee or otherwise) to request their medical records and have them presented within 30-days of request. Allowing employees to bypass this process could cause some issues. For example:

  • Do you have a current policy regarding restriction of access according to the employee’s work-related duties? Is accessing his/her own records outside of this policy? It most likely should be.
  • Will bypassing this process bypass documentation of the request, documentation of the records retrieval and documentation of the record controls?
  • Will they have access to notes that a "regular" patient would not and should not have access to?

Keep in mind that when I say documentation, I mean proof of the proper action that can stand up to an audit or investigation. So, if an entity is planning to allow this action, there should be a documented policy and procedure of how this will be handled.


Now, although it is possible that an employee can access and review their own medical records, let's look at two specific parts of HIPAA to see if this action will pass.

For uses of protected health information, the covered entity’s policies and procedures must identify the persons or classes of persons within the covered entity who need access to the information to carry out their job duties, the categories or types of protected health information needed, and conditions appropriate to such access.

  • I've underlined what I believe to be a key in this sentence. Would it be part of the employee's job duties to access their own records?

Let's assume the answer is "yes." Here's what else is given in this guidance: Where the entire medical record is necessary, the covered entity’s policies and procedures must state so explicitly and include a justification.


Another portion of the text identifies "non-routine disclosures or requests." I think a case could be made that an employee accessing their own records would be a non-routine disclosure. Here's what they say about this: “For non-routine disclosures and requests, covered entities must develop reasonable criteria for determining and limiting the disclosure or request to only the minimum amount of protected health information necessary to accomplish the purpose of a non-routine disclosure or request. Non-routine disclosures and requests must be reviewed on an individual basis in accordance with these criteria and limited accordingly.”


So, if your practice can make a case for this type of access, there must be a review of this activity every single time. I don't know about you, but it seems following the normal patient record request would be less strain on the practice at this point. But let's keep going.


We can wrap up with the Minimum Necessary Requirements portion. However, it is obvious that any PHI access has to be for the purposes of a job function or role. I do not see any way to interpret employee access to their own medical records as part of their job or role. But maybe some Covered Entities can make that case.

  • Next, let's look at Uses and Disclosures: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/disclosures-treatment-payment-health-care-operations/index.html

There are 3 distinct areas in which the use or disclosure of PHI is permitted... for treatment... for payment... for healthcare operations or “TPO” as we call it. If to this point a Covered Entity (CE) has determined that it is ok for an employee to access their own medical records, let's then pass this through the test of TPO.


The employee can access the PHI if the employee is involved in their own treatment. It would be unusual and rare that an employee is allowed to treat themselves and realize that Medicare and other insurances will not reimburse a provider when treating him/herself or a family member – so these circumstances cannot be billed. Aside from HIPAA, there can be other liabilities, risks, and legal problems if this is allowed.


The employee can access the PHI if the employee is involved in the payment activities. Allowing an employee to manage their own payments, adjustments, eligibility, coverage, claims, bills, justification of charges, utilization review, collections, etc., would likely not be recommended by most lawyers or accountants... not to mention insurers. In fact, it creates a “nightmare” from a compliance standpoint.


The employee can access the PHI if the employee is involved in Health Care Operations. “Health care operations” are certain administrative, financial, legal, and quality improvement activities of a covered entity that are necessary to run its business and to support the core functions of treatment and payment. These activities, which are limited to the activities listed in the definition of “health care operations” at 45 CFR 164.501.


Ok, now that we've taken our scenario and passed it through the filter of Minimum Necessary Requirements and TPO, your committee can determine how they would like to proceed with this decision.


Two final things I'll say about it:


First, if they choose to allow the action, I highly recommend a specific policy and procedure for it and a "mini" risk assessment to identify what the risks are to the CIA of the PHI and developing a risk management plan for things that are identified.


Second, this is such a low priority compliance matter that I would not necessarily spend a lot of time on it. I don't see OCR spending resources to investigate an employee accessing their own records, but I certainly can't say it won't happen. With all the activities and actions that carry a much higher likelihood and impact to the patient and the organization, this carries a very low probability of impact. Is the employee going to look at their records and then file a complaint with HHS that their PHI was improperly disclosed? People can be crazy, so maybe... lol.


This is one of those areas where technically you can make a case for or against it. Although, I see the case against it as being stronger. It really would be easier to just follow the same patient record request process for everyone. If you're a patient, you're a patient (even if you're an employee too). OCR investigators have a lot of leeway in their investigations so if this matter were to come up in an investigation, it can really depend on the investigator and whether they want to push this issue or make an example of the organization.


Personally, I just don't like taking the risk of potential issues that my organization can easily avoid. If there is a question of right or wrong, I'm going to lean toward what is easier to prove as being the right thing to do rather than fight like hell to make a case that the wrong thing was right.


Need HIPAA support? Contact J. David Sims, Managing Partner of Security First IT, LLC and Contributor with the Federal HICP 405(d) Task Group & HIC-TCR Task Group.

 

Want more great training information on HIPAA privacy and security compliance? Register for the online HIPAA course today! 


No classes to attend. Course materials are on-demand and available to you for 3 months. Training is for experienced health care consultants, business associates, HIPAA Privacy or Security Officers, IT Consultants, Practice Administrators, Office Managers, Compliance Officer Executives, and Administrators involved in developing and enforcing confidentiality and privacy and security as a Covered Entity or Business Associate.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More