Medical Billing and Coding · Coding foundations

HIPAA and Compliance

32 min read
This is independent educational material for learning about medical billing and coding. It is not medical, legal, coding, billing, reimbursement, compliance, employment, or financial advice for a specific situation. For real decisions, follow the applicable employer policy, official guidance, current licensed references, and qualified professionals. Information can change, including credential requirements, code sets, guidelines, payer and government policies, and labor information. Check the controlling official source before acting. This resource is not affiliated with, endorsed by, sponsored by, or approved by any credentialing organization, coding-system publisher, government agency, testing vendor, or training provider; names are used for identification only. This resource does not promise an exam result, employment, salary, remote work, or advancement. It supports continuing learning and refreshers, not approved continuing-education credit, accredited training, credential-renewal credit, or mandatory-training compliance. Practice content is original educational material, not official exam content. Examples are fictional and do not describe real patients, claims, employers, or organizations. External links, when a reviewed page includes them, are for verification and reference; they are not endorsements and may change. To report a possible error, follow the correction process in the Editorial Policy.
On this page 3 sections
  1. In 30 seconds
  2. The college version
  3. Study tools

In 30 seconds

The Habits That Start Before Your First Job

The college version

Before You Start

This page is for everyone, at any stage, including people who have never worked in healthcare. Nothing needs to be read first. It works as a first lesson if compliance is new to you, and as an awareness refresher if you already work in the field — with one honest limit stated up front: it is awareness only. It is not a substitute for the training your employer must provide on its own policies, and it is not legal advice about any real situation.

Difficulty: Beginner. The ideas here are approachable. The hard part is not the concepts; it is the discipline of pausing when you are unsure and sending real questions to the people and sources that actually control the answer, instead of deciding on your own.

One sentence to carry through the whole page: "I am not sure whether I may access or share this" is answered by asking. Asking is not a sign that you are behind. Asking is the professional behavior this field expects, and this page is built to make asking your first instinct.

What this is and why it matters

You are learning the privacy, security, and compliance awareness that billing and coding work depends on: what health information is protected, who may see it and why, how it is kept safe, and what the words fraud, waste, and abuse actually mean. You will not leave this page qualified to interpret the law or to make a compliance decision for an employer. You will leave it able to recognize a risky situation and route it correctly.

The reason this comes early is simple: the habits that protect information start during study, long before a first job. Learners bring real records into study groups, post screenshots, look up a relative's chart "just to learn," and treat a coding shortcut as harmless because no one seems to be hurt. Those same habits, carried into a workplace, become privacy breaches and fraud, waste, and abuse problems. Three confusions do most of the damage — treating privacy and security as one thing, treating an honest error as fraud (or fraud as a harmless error), and treating interesting as if it were the same as permitted. This page exists to make one reflex automatic before any practice or career page asks you to apply it: pause, verify, follow policy, document appropriately, and escalate.

What you will be able to do

  • Explain, at an awareness level and with attribution to official sources, what HIPAA is, which federal office administers its privacy and security rules, and that state laws and employer policies may add requirements.
  • Define protected health information and tell it apart from general health information, de-identified information, and employer-confidential information.
  • Distinguish privacy (who may use and see information, and why) from security (how information is protected), and describe the three kinds of safeguards as concepts.
  • Explain the minimum-necessary idea and permitted uses for treatment, payment, and operations in plain terms, and recognize curiosity access as a violation.
  • Tell an honest error from fraud, waste, and abuse; recognize the federal laws commonly named in compliance training; and say why documentation integrity is a compliance matter.
  • Spot secure-device, secure-workspace, remote-work, and social-media risks in fictional scenarios and choose the escalation response.
  • State the boundary between educational awareness and legal advice, and name where a real question goes.

The simple version

Picture a locked filing room with a sign-in sheet. Privacy is the set of rules about who is allowed to open which folder and why — only the people whose job needs a folder, and only the pages they actually need. Security is the physical protection around those folders: the lock on the door, the policy about who holds a key, the camera in the hallway, and the rule against propping the door open. Inside this picture live the real terms. The folders hold protected health information. Minimum necessary is the rule that you take only the pages your task needs. Safeguards are all the protections that keep the room secure.

Now the limits, because they matter more than the picture. A filing room is physical, but most protected health information today is electronic, and electronic information can leak through a screen in a coffee shop, a text message, a photo, or a home printer — so "locking the room" has to include devices, networks, and everyday habits, not just a door. The rules also come from more than one place at once: federal law, possibly stricter state law, and your employer's own policies. Your job is not to decide which one applies. Your job is to follow all three and ask when you are unsure. The security rules focus on electronic information, while paper records are protected through the privacy rules' safeguard requirement and employer policy (verify the specifics against official materials). Keep the picture for intuition, and keep the limits for real work.

What HIPAA is — awareness level

HIPAA is a federal law. Its rules cover the privacy of health information, the security of electronic health information, and notification when a breach occurs. The Privacy Rule, the Security Rule, and the Breach Notification Rule are the common names for those rule sets. The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) administers and enforces the privacy and security rules (attribute to official HHS/OCR materials; verify).

The rules apply to covered entities — health plans, health care clearinghouses, and health care providers that transmit certain information electronically — and to their business associates, the contractors that handle protected information on their behalf. The people who work for these organizations are the workforce, and workforce members have compliance duties no matter their title. State laws may add stricter requirements, and an employer's policies may be stricter still. HIPAA also sets administrative-simplification standards for electronic transactions and code sets, which are administered by the Centers for Medicare and Medicaid Services (CMS) (attribute; verify) — that is the reason the diagnosis and procedure code sets you meet on the coding pages are called standard code sets.

This section is orientation, not legal interpretation. Notice what is deliberately absent: no dates, no penalty amounts, no thresholds, and no ruling on any situation. Those belong to official sources and qualified counsel, not to an awareness page.

Stop and Verify: This detail can depend on a current rule, code year, payer, employer, setting, or document. Check the controlling official source and the applicable policy before acting. Confirm the rule names, the administering offices, and the covered-entity description against current HHS/OCR materials (and CMS materials for the transaction and code-set standards).

See ICD-10-CM Basics — Related, whose "standard code set" framing rests on these administrative-simplification standards.

What counts as protected health information

Protected health information (PHI) is individually identifiable health information that a covered entity or business associate holds or transmits, in any form — electronic, paper, or spoken (concept, attributed to HHS/OCR; verify). Read that definition slowly, because two words do the heavy lifting. Identifiable means the information can be tied to a specific person. Health information includes information about care, conditions, or payment for care. Put those together and it becomes clear that PHI is not only the medical chart. A claim, a remittance advice, a billing statement, and an appointment schedule all carry PHI, because each ties an identifiable person to their care or the payment for it.

Two neighboring ideas are easy to confuse with PHI. De-identified information is health information from which identifiers have been removed under a defined standard so that it no longer identifies a person; it is a specific concept, not the casual act of "I took the name off." Employer-confidential information — an office's fee schedule, its internal policies, its software details — is protected by employer policy, but it is a different category from PHI. Sort the fictional items below to see the lines.

Fictional itemCategoryWhy
A claim for Patient A that Clinic X sends to Health Plan Y, showing a member ID and the services billedPHIAn identifiable person tied to care and payment, held by a covered entity
A remittance advice naming Patient A and what Health Plan Y paidPHIPayment information tied to an identifiable person
Clinic X's appointment schedule listing Patient A's name and visit timePHIAn identifier plus the fact that a specific person is receiving care
"Clinic X billed 400 wellness visits last quarter," with no identifiers and not tied to any individualNot individually identifiable health informationNo identifiable person; it may still be employer-confidential
A data set stripped of identifiers under the defined de-identification standardDe-identified informationNot PHI once the standard is met — but simply deleting a name does not meet it
Clinic X's internal fee schedule and billing-software vendor detailsEmployer-confidential informationProtected by employer policy; a business category, not PHI
The general statement "diabetes is common," attached to no oneNot health information about an individualNothing identifiable, nothing about a specific person

Text alternative: claims, remittances, statements, and schedules are PHI because they tie an identifiable person to care or payment; a true no-identifier count is not individually identifiable; de-identified information must meet a defined standard rather than just losing a name; and internal business information is employer-confidential, a separate category from PHI.

Two misreadings this table is built to stop: "PHI is only the medical chart" (it is not — billing documents carry it too), and "removing the name de-identifies it" (it does not — de-identification is a defined standard). For any specific term here, see the Glossary — Definition.

Privacy vs. security

These two words are used interchangeably in everyday speech, and that habit hides a distinction that matters at work. Privacy is about uses and disclosures — who may use or see information, what they may see, and for what purpose — along with individuals' rights in their own information (such as the right to access it, as a concept). Security is about protection — specifically, how electronic protected health information is kept safe from being seen, changed, or lost by the wrong people. Both apply to the same information at the same time. A claim in a billing system is governed by privacy rules (who may open it and why) and by security protections (how the system keeps it safe) simultaneously.

PrivacySecurity
Governs uses and disclosures: who, what, and whyGoverns protection of electronic PHI
Answers "may I use or share this, and for what purpose?"Answers "how is this information kept safe?"
Includes individual rights in one's own information (concept)Works through three kinds of safeguards
The reason curiosity access is a violation even if nothing leaves the buildingThe reason a locked screen and a secure network are your responsibility, not only the IT department's

Text alternative: privacy is the rulebook for who may use or see information and why, including a person's rights in their own information; security is the set of protections that keep electronic protected health information safe. They cover the same information at once, so a single claim is subject to both.

Security works through three kinds of safeguards, which are worth knowing as words: administrative safeguards (policies, training, and workforce procedures), physical safeguards (locked spaces, device and screen controls, secure disposal), and technical safeguards (access controls, passwords, and protections on electronic systems). You do not implement these as a beginner, but you live inside them every day, and recognizing that your screen habits and your network are physical and technical safeguards in action is the point of this section: security is not somebody else's job.

Minimum necessary and permitted uses — in plain terms

The everyday privacy rule you will feel most often is minimum necessary: use or disclose only the information the task actually needs, not everything you could reach. The rule has exceptions that it defines (some treatment disclosures, for example), so treat this as a plain-language concept and rely on the official HHS/OCR summary for the boundaries rather than stating it as an absolute (concept; attributed; verify). In practice, minimum necessary shows up as role-based access: a biller sees what billing requires, a coder sees what coding requires, and neither has a general license to browse.

Certain uses are permitted in ways the rules define — for treatment, for payment, and for health care operations (concept; the details belong to official materials). "Work-related" is not the test; the permitted-use categories and your role are. And one behavior is out of bounds everywhere: curiosity access — opening information you have no job reason to see. That includes a neighbor's record, a coworker's record, a family member's record, and a public figure's record. Curiosity access is prohibited by employer policy in every healthcare workplace, and for covered entities and business associates it is an impermissible use under the Privacy Rule (attribute to HHS/OCR; verify). It is one of the behaviors most frequently cited in disciplinary and enforcement actions — stated here as a concept, with no figures and no case details.

Sort these three fictional access situations:

Fictional situationClassificationWhat to do
Biller C opens Patient A's claim to correct a member ID before resubmitting it to Health Plan YJob-necessaryProceed; this is the task the role exists to do
On a break, Coder B opens the record of a neighbor who was just hospitalized, out of concern and curiosityNot necessary — curiosity accessDo not open it; this is prohibited everywhere and is an impermissible use where the rules apply
A staff member is asked to pull a record for a purpose they are not sure falls within their roleUnclear — therefore askPause, check policy, and ask a supervisor or privacy officer before acting

Text alternative: opening a record to do your assigned billing task is job-necessary; opening a neighbor's, family member's, or public figure's record out of curiosity is a violation; and when you are unsure whether a purpose is within your role, the answer is to ask before acting, not to decide on your own.

The misconception this section exists to break is the quiet one: "if I can open it, I may read it." Technical access is not permission. Permission comes from having a job reason, and when the job reason is unclear, asking is the professional move.

Documentation integrity

Compliance expectations reach beyond privacy into the accuracy of the record itself. The billing and coding record is expected to be accurate, complete, attributable to the right person, and unaltered except through a proper amendment process. Coders and billers do not alter documentation, do not backdate, and do not "clean up" a note to make it read better. When information seems to be missing, the answer is the employer's query process, not a guess. (The Privacy Rule also recognizes an individual's right to request an amendment to their own information — noted here only as a pointer, not as something you carry out.)

This is where a rule you meet elsewhere becomes a compliance rule, not just an accuracy rule: do not infer undocumented detail. Reading a meaning into a record that the documentation does not support is both an accuracy problem and a documentation-integrity problem. See Anatomy for Coders — Related for the do-not-infer habit and ICD-10-CM Basics — Related for specificity that is bounded by what the documentation actually says. The compliance point they share is this: the record leads, and the coder or biller follows the record — never the other way around.

Fraud, waste, and abuse — concepts and the laws named for them

You will see the phrase fraud, waste, and abuse (FWA) in job postings and employer training, so learn the concepts and the vocabulary now. As concepts: fraud is intentional deception for gain; waste is the overuse or misuse of resources; abuse is practices inconsistent with accepted standards that result in unnecessary cost. Several federal laws are commonly named in compliance training, and it is worth recognizing them by name for identification only — the False Claims Act, the Anti-Kickback Statute, the physician self-referral law, and exclusion authorities. This page names them and stops there; the descriptions belong to the HHS Office of Inspector General (OIG) educational materials, and this awareness page offers no legal interpretation, no penalty figures, and no case details.

The distinction that keeps beginners steady is error vs. fraud. An honest mistake is not fraud. A transposed member ID, a claim that rejects because of a typo, a genuine misunderstanding corrected as soon as it is noticed — these are handled through normal correction processes. What crosses into fraud is knowingly submitting false claims. Learners need both halves of that sentence: you do not have to be terrified of every mistake, and you do not get to treat a knowing shortcut as "just a mistake."

Compare two fictional situations:

Fictional situationWhat it isThe response
Biller C transposes Patient A's member ID; the claim to Health Plan Y rejects, and Biller C corrects it through the normal processHonest errorCorrect it through the employer's process; document appropriately; no cover-up
A coworker suggests adding a modifier "just to get it paid," with nothing in the documentation to support itAn FWA concern (misrepresentation)Do not do it; do not change codes to force payment; pause, verify against policy and official guidance, and escalate

Text alternative: an honest error, such as a mistyped identifier that causes a rejection, is corrected through the normal process; a suggestion to add an unsupported modifier or otherwise misrepresent a claim to force payment is a fraud, waste, and abuse concern, and the correct response is to refuse, verify, and escalate rather than to comply or to quietly change codes.

Typical FWA patterns, named as concepts only, include billing for services not rendered, upcoding, unbundling, misuse of modifiers, altering documentation, and kickbacks. Notice that "fix" is never the response to any of them — a modifier reports a documented circumstance and is never a payment lever, and a denial is reviewed and escalated, never made to disappear by changing a code. See Modifiers — Related, whose whole compliance boundary is that modifiers report supported circumstances, never adjust payment. Employers build compliance programs — a structure of policies, training, reporting channels, and oversight — and every workforce member participates in that structure (elements attributed to official OIG guidance; verify). Compliance is not only the compliance department's job.

Secure devices, secure workspaces, and remote work

Privacy and security become real at the level of daily habits. Each risk below is a category, paired with the habit that addresses it at a concept level; your employer's policy defines the specific requirement, and remote work does not lower the standard.

  • Screens visible to others — position screens away from view; use privacy filters where required; lock the screen when you step away.
  • Unlocked or shared devices — lock devices; do not let household members or others use a work device; use only approved equipment.
  • Personal email or messaging for PHI — never send PHI through personal channels; use only employer-approved systems.
  • Unsecured networks — use the network and connection method your employer requires, not open public Wi-Fi for work.
  • Printed PHI and disposal — minimize printing; secure any printed material; dispose of it through the required secure method, never household recycling.
  • Household members and video calls — keep PHI off screens during calls others can see; be aware of who is within earshot or eyeshot.

Walk through a fictional remote day. Biller C works from home for Clinic X and hits three risk points:

Risk pointThe compliant habit
Biller C opens Patient A's claim while sitting in a co-working space where the screen faces the roomReposition the screen, use a privacy filter, and lock it when stepping away — visible-screen risk addressed at the physical-safeguard level
A quick claim question about Patient A comes up, and personal messaging is the fastest way to ask a coworkerUse only the employer-approved system; keep PHI out of personal email and messaging
A statement is printed at home and would be easy to toss in the household recyclingFollow the employer's secure-disposal requirement; do not treat home as an exception

Text alternative: a remote billing worker faces a visible screen in a shared space, the temptation to use personal messaging for a PHI question, and a printed statement that could be discarded insecurely; the compliant habits are to protect and lock the screen, to use only approved systems, and to dispose of printed material as the employer requires — because remote work does not lower the standard.

For how remote work and workplace expectations show up in real job hunting, see Entry-Level Job Reality — Career connection.

Social media, messaging, and public discussion

This is a common and specific way good intentions cause a breach. Keep PHI out of posts, group chats, forums, and study groups — even when you leave the name out. An "interesting case" story is a known breach pattern precisely because the person telling it believes removing the name makes it safe.

Consider a fictional group-chat message from Coder B: "Had the wildest chart today — a 34-year-old cyclist hit by a car on Elm Street last Tuesday, ended up needing a spleen removed." There is no name in it. It is still a problem. The combination of age, event, date, and location can identify a person, and the record was never permitted to be shared outside the workplace to begin with. Removing the name did not de-identify anything; it just hid the most obvious identifier while leaving the rest.

Employer-confidential information belongs in the same "keep it internal" bucket: fee schedules, internal policies, and software details stay inside the organization. The safe default for anything work-related is to ask before sharing.

Study privacy — habits that start now

The rules apply to how you learn, not only to how you work. Keep real records out of your notes, screenshots, practice work, portfolios, and any AI tools — use synthetic examples only, the way this page uses Patient A, Clinic X, and Health Plan Y. Classroom cases and clinical-placement records stay in the classroom or the placement; they are not study material to copy home. When you build a portfolio to show what you can do, use invented material — see Building Experience After Certification — Career connection. And respect intellectual property while you study: no pirated references and no shared or leaked exam content. See Compliance, Trademark, and Non-Affiliation Rules — Standard. The habit you build in study is the habit you bring to work.

Escalation and the advice boundary

Here is the reflex the whole page is building. When you are unsure whether an access, a use, a disclosure, or a coding or billing practice is permitted, run the same five steps every time:

  1. Pause. Do not act on the uncertain thing.
  2. Verify. Check your employer's policy and the relevant official materials.
  3. Follow policy. Do what the applicable policy directs.
  4. Document appropriately. Record what you did through the proper process — never alter or backdate anything.
  5. Escalate. Raise the concern to a supervisor, privacy officer, or compliance officer. Reporting channels exist by design, and using them is expected.

Text alternative: the five-step ethical response is pause, verify, follow policy, document appropriately, and escalate — applied to any situation where you are unsure whether an access, use, disclosure, or billing or coding practice is permitted.

Notice the shape of that workflow: it never ends in a workaround, and it never ends in you deciding a legal question on your own. That is the boundary of this page. This page and this resource are awareness material — not legal advice, not your employer's training, and not a compliance determination for any real situation. A real question goes to your employer's policies and its privacy or compliance officer, to official HHS/OCR and OIG materials, and, where a legal judgment is needed, to qualified counsel.

Understand, memorize, look up, verify

Use this approachWhat belongs here
UnderstandWhat PHI is; privacy vs. security; minimum necessary and role-based access; error vs. fraud, waste, and abuse; why documentation integrity is compliance; why remote work does not lower the standard; why escalation is the professional response.
Memorize carefullyThe rule names and the administering office (attributed); the three safeguard categories as words; the FWA law names for identification; the five-step ethical response.
Look upAny specific rule text; your employer's policy details; the definition of de-identification; the reporting channels at a specific workplace.
Verify officiallyEvery statement about HIPAA scope, rules, and enforcement (HHS/OCR); FWA law descriptions and compliance-program guidance (HHS-OIG); state-law additions (state sources); employer policy (the employer); and any real situation (a compliance officer or qualified counsel).

Common misconceptions

BeliefWhy it is temptingThe correction
"If I can open it, I may read it."Access feels like permission, and curiosity about family, coworkers, or public figures is natural.Permission requires a job reason. Curiosity access is prohibited everywhere and is an impermissible use where the rules apply — see the three-situation table.
"Removing the name makes it safe to share."The name is the obvious identifier.De-identification is a defined standard with many identifiers; the "34-year-old cyclist on Elm Street" post shows how a story without a name still identifies.
"Privacy and security are the same thing."Both sound like "protecting information."Privacy governs who may use or see information and why; security governs how electronic information is protected. Your screen and network habits are security duties, not only IT's.
"A billing mistake is fraud" — or "a coding shortcut is just a mistake."The words are used loosely, and fear or rationalization pushes in both directions.Honest errors are corrected through process; knowingly submitting false claims is fraud. Both halves matter.
"Compliance is the compliance department's job."Dedicated roles exist.Every workforce member has duties and reporting channels, and "everyone does it" is not a defense.
"Working from home means the office rules do not apply."Home feels private, and remote work is marketed as flexible.Screens, devices, networks, household members, and printouts are all breach vectors; employer policy applies fully at home.
"Reading this page counts as HIPAA training."It covers the topics training covers.Employers must train their own workforce on their own policies. This page is awareness only — see Educational and Certification Disclaimers — Standard.

Check yourself

  • Say what PHI is, and give two examples that are not a medical chart.
  • Sort four fictional items into PHI, de-identified, not health information, and employer-confidential.
  • State the difference between privacy and security in one sentence each, and name the three safeguard categories.
  • Classify three fictional access situations as job-necessary, not necessary, or ask-first.
  • Tell an honest error from a fraud, waste, and abuse concern, and say how each is handled.
  • Reconstruct the five-step ethical response from memory.

Teach it back: explain to a new coworker why a claim is PHI even though it is "just billing." Include one distinction (privacy vs. security), one professional-context point (role-based access and curiosity access), and one thing you would ask a privacy or compliance officer rather than decide yourself. There is no model answer.

Ready to move on?

  • I can say what PHI is and why claims and statements count.
  • I can tell privacy from security and name the three safeguard categories.
  • I know that access requires a job reason and that curiosity access is prohibited by policy everywhere.
  • I can tell an honest error from fraud, waste, or abuse concepts, and I know both are handled through process.
  • I know the remote-work and social-media risks and the habits that address them.
  • I know this page is awareness, not training or legal advice, and where a real question goes.

This page does not satisfy any employer's training requirement and does not provide legal advice. It is awareness only.

If you got something wrong

MistakeReviewTry again
Blurred privacy and security"Privacy vs. security" and the Glossary — RemediationIn a later session, restate each in one sentence and name the three safeguards.
Assumed access equals permission, or name removal equals safe"Minimum necessary and permitted uses" and "What counts as PHI"In a later session, re-sort the fictional access situations and PHI items.
Treated a shortcut as harmless, or an honest error as fraud"Fraud, waste, and abuse" and Modifiers — RemediationIn a later session, classify fictional practices as error or FWA concept, then route each.
Assumed home rules are looser, or that this page is training"Secure devices… and remote work" and "Escalation and the advice boundary"In a later session, hunt the three risk points in the remote-day example.
Trusted a forum or a coworker's memory over policy"Check the source yourself" and Source Verification Standards — StandardIn a later session, pick the controlling source before deciding.

If two ideas stay tangled, place them side by side and compare before more practice. If you leaned on a non-authoritative source, review the source challenge before continuing.

In the profession

Every role that touches health information is workforce under the rules and under employer policy — registration, scheduling, billing, coding, patient accounts, records, compliance, and providers. Billing and coding staff handle PHI on every claim and are central to preventing fraud, waste, and abuse. Employers train their workforce, designate privacy and compliance officers, and define reporting channels. Employer policy, official rules, and those designated officers control real decisions — not a coworker's memory and not "how we have always done it."

In certification

Privacy, compliance, and ethics appear as domains in billing and coding credentials alike, and every credential this resource reviews carries a code of conduct or ethics that candidates and holders agree to. For privacy on claims within a claims-lifecycle model and a code-of-conduct item, see the CBCS Certification Review — Certification connection. For their code-of-conduct and ethics items, see the CPC Certification Review and the CCA Certification Review — Certification connection. Domains are described as broad public-outline areas only; verify each issuer's current exam-content outline and current code of conduct. This page does not align to any exam.

In careers

Job postings phrase this as "HIPAA compliance," "maintains confidentiality," or "adheres to compliance policies," and remote postings often specify secure-workspace expectations. This page gives you awareness; the training that satisfies an employer's requirement comes from the employer, and no employment outcome is implied here. The same pause-and-verify habit also protects you from job scams — an unverified "employer" asking for sensitive personal information is answered the same way any uncertain request is. See Entry-Level Job Reality — Career connection.

For continuing learning

Returning learners refresh PHI, privacy vs. security, and the escalation workflow first, then check what may have changed: official HHS/OCR and OIG guidance updates, state-law changes (verified with state sources), and their own employer's current policies. A six-month return needs the FWA and remote-work sections; a years-away return needs the full page, then the career pages. This resource provides no continuing-education or renewal credit, and it does not replace the training your employer provides.

Study options

  • 5-Minute Review: the PHI definition and the curiosity-access rule.
  • 15-Minute Study: privacy vs. security, plus minimum necessary with the three-situation example.
  • Full Lesson: every section, including documentation integrity, fraud, waste, and abuse, devices and remote work, social media, study privacy, and escalation.
  • Refresher or Deep Dive: the FWA concepts with official OIG materials, and the remote-work habits.

No plan is the "right" one; use the short review when time is short and the full lesson when you can give it attention.

If you remember only five things: claims and statements are PHI, not just charts; privacy is who-and-why while security is how-it-is-protected; access needs a job reason and curiosity access is never allowed; an honest error is fixed by process while a knowing shortcut is fraud, waste, or abuse; and when unsure, pause, verify, follow policy, document appropriately, and escalate.

Check the source yourself

Not every source that talks about HIPAA controls what you may do at work. Ask three questions of any source: is this the official HHS/OCR or OIG material, is it my employer's policy, or is it just someone's summary? When was it last updated? Does my state add requirements? Official rules and guidance are periodically updated; employer policy is context-dependent and set by your workplace; the underlying concepts on this page are stable.

Freshness note: treat statements about rules, enforcement, and official guidance as periodically updated and verify them against current official materials; treat employer policy as context-dependent; treat the concepts (what PHI is, privacy vs. security, error vs. FWA) as stable.

Source challenge: you need to know whether a particular disclosure of Patient A's information is permitted at Clinic X. You have four sources: Clinic X's privacy officer and its current written policy; the official HHS/OCR HIPAA materials; a forum thread where people share their experiences; and a coworker's memory of how it was handled once before. Which source controls the answer you can act on at work, which is acceptable only for background study, and which controls neither? See Official Resources and Study Tools — Official resource for where the official materials live.

Frequently asked questions

What counts as PHI?

Protected health information is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. It is not only the medical chart — a claim, a remittance advice, a billing statement, and an appointment schedule all carry PHI because each ties an identifiable person to their care or its payment. Verify the definition against current HHS/OCR materials.

What is the difference between the Privacy Rule and the Security Rule?

As a concept: privacy governs uses and disclosures — who may use or see information and why — while security governs how electronic protected health information is kept safe through administrative, physical, and technical safeguards. Both apply to the same information at once. Verify the specifics against official HHS/OCR materials.

Can I look at a record if I am careful?

No. Being careful is not the test; having a job reason is. Opening information you have no work reason to see — including a family member's or a public figure's record — is curiosity access, which is prohibited by employer policy everywhere and is an impermissible use where the rules apply.

Is a billing mistake fraud?

No. An honest error is corrected through the normal process. Fraud is the knowing submission of false claims. You do not have to fear ordinary mistakes, and you also do not get to treat a knowing shortcut as "just a mistake" — when a practice looks like misrepresentation, pause, verify, and escalate.

Does HIPAA apply when I work from home?

Yes. Remote work does not lower the standard. Screens, devices, networks, household members, and printouts are all breach vectors, and your employer's policy defines the specific requirements that apply to your home setup.

Does reading this count as HIPAA training?

No. Employers must train their own workforce on their own policies, and this page does not do that. It is awareness only — useful background, not a substitute for your employer's training or for legal advice.

Where to go next

Sources to verify before relying on this page

  • HHS Office for Civil Rights (OCR) official HIPAA materials — control the scope of HIPAA, the rule names (Privacy, Security, Breach Notification), the administering office, the covered-entity and business-associate descriptions, the PHI and de-identification concepts, minimum necessary, the permitted-use categories, and the safeguard categories.
  • HHS Office of Inspector General (OIG) official educational materials — control the fraud, waste, and abuse concepts, the law names used for identification (False Claims Act, Anti-Kickback Statute, physician self-referral law, exclusion authorities), and the compliance-program elements.
  • CMS official fraud, waste, and abuse educational materials — corroborate the FWA concept framing where applicable.
  • CMS official administrative-simplification materials — control the statement that HIPAA also sets electronic transaction and code-set standards administered by CMS.
  • State-law sources — control any statement that your state adds requirements; this page says only that state law may add requirements and points you to verify with state sources.
  • Employer policy — never reproduced here; referenced throughout as the controlling source for the specifics of access, disposal, remote work, and reporting channels.

Keep learning

Ready to build on this? Continue to the next lesson.

Practice Medical Billing and Coding

This lesson has no separate scored set. Practice draws from the subject’s question bank.

Study tools & related lessonsRelated

Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.