HIPAA Compliance for HR Departments
HIPAA compliance for HR departments consists of determining whether HIPAA applies to any of the department’s activities and, if so, implementing policies and procedures to safeguard Protected Health Information (PHI) from impermissible disclosures and unauthorized access. Employers must also provide HIPAA training for HR professionals.
HIPAA does not apply to employers in their role as employers except when an employer self-administers a self-insured health plan or acts as an intermediary between employees, health plans, and healthcare providers. In such circumstances, the employer is considered to be a “partial covered entity” for HIPAA purposes.
Partial covered entities must isolate health, treatment, and payment information used to conduct HIPAA covered transactions from other personnel data. When HR departments are involved in the administration of a self-insured health plan, this means isolating Protected Health Information (PHI) from employee records.
When PHI is isolated from employee records, policies and procedures must be implemented to safeguard the information from impermissible disclosures and unauthorized access. It is also necessary to provide HIPAA training for HR professionals and implement a security awareness training program for all other members of the workforce.
The Importance of HIPAA Compliance for HR Departments
The importance of HIPAA compliance for HR departments is that sets of PHI are highly sought by criminals to obtain healthcare, prescription drugs, and medical equipment they are not entitled to. Criminals that steal large numbers of record sets can sell those they do not use themselves or give to family members for vast sums on the dark web.
The value of PHI is higher than other types of information because it has a long shelf life. In some cases it can take years for an individual to realize their PHI has been misused. Between the time of the theft and the discovery of the theft, criminals can obtain treatments worth thousands of dollars – paid for by the employer’s self-insured health plan.
In addition to the financial cost, victims of medical identity theft often report inaccuracies in their medical records due to the treatments obtained by imposters. A survey conducted in 2013 found the most common consequences of the inaccuracies are the misdiagnosis of an illness, a delay in receiving medical treatment, and the mistreatment of an illness.
The survey also found that – regardless of who was to blame for an impermissible disclosure or facilitating unauthorized access – 56% of respondents lost confidence in their healthcare provider. The consequences for employers are that employees are less likely to share sensitive data with their healthcare provider, leading to an increased likelihood of misdiagnoses, longer recovery periods, readmissions, and more time off sick from work.
HIPAA Training for HR Professionals
To minimize the likelihood of impermissible disclosures and unauthorized access to PHI, employers who qualify as partial covered entities for HIPAA purposes are required to implement policies and procedures to safeguard PHI and train members of the workforce “as necessary and appropriate for the members of the workforce to carry out their functions”.
When an HR department is involved in the administration of a self-insured health plan, employers must provide HIPAA training for HR professionals relative to their functions. The training should include an explanation of what PHI is, why it needs protecting, and what the consequences are of impermissibly disclosing or facilitating unauthorized access to PHI.
In addition, it will be necessary to implement a security awareness and training program for all workforce members regardless of their access to PHI. The reason for training all workforce members on security awareness is that cybercriminals will look for any point of access to a network, and then move laterally through the network in order to access databases containing PHI.
Because security awareness training courses have to be implemented in accordance with the General Rules of the HIPAA Security Rule (§164.306), it is also advisable to provide all members of the workforce with HIPAA awareness training. This will help members of the workforce understand why it is necessary to comply with the employer’s security policies and not to circumnavigate access controls or download unsanctioned software “to get the job done”.
Where to Find HIPAA Training Materials
The Department for Health and Human Services’ (HHS) Office for Civil Rights and Centers for Medicare and Medicaid Services have published multiple web pages dedicated to HIPAA training. Some of these web pages can be used by employers to support HIPAA compliance for HR departments. However, when reviewing these sources it is important to be aware that some have not been updated since the April 2024 changes to the HIPAA Privacy Rule to strengthen HIPAA protections for reproductive health information.
It may also be important to be aware that HHS’ guidance materials tend to be “standard specific” inasmuch as they focus on a specific element of the HIPAA Rules rather than on HIPAA compliance as a whole. Employers that require more general HIPAA awareness training to support HIPAA compliance for HR departments are advised to subscribe to an accredited online HIPAA training course that provides sufficient information to prevent inadvertent HIPAA violations due to a lack of HIPAA knowledge.
