<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.limswiki.org/index.php?action=history&amp;feed=atom&amp;title=Template%3AHIPAA_Compliance%3A_An_Introduction%2FAdditional_compliance_guidance</id>
	<title>Template:HIPAA Compliance: An Introduction/Additional compliance guidance - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.limswiki.org/index.php?action=history&amp;feed=atom&amp;title=Template%3AHIPAA_Compliance%3A_An_Introduction%2FAdditional_compliance_guidance"/>
	<link rel="alternate" type="text/html" href="https://www.limswiki.org/index.php?title=Template:HIPAA_Compliance:_An_Introduction/Additional_compliance_guidance&amp;action=history"/>
	<updated>2026-04-05T09:39:07Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>https://www.limswiki.org/index.php?title=Template:HIPAA_Compliance:_An_Introduction/Additional_compliance_guidance&amp;diff=46312&amp;oldid=prev</id>
		<title>Shawndouglas: /* Disposal of PHI */ Added image</title>
		<link rel="alternate" type="text/html" href="https://www.limswiki.org/index.php?title=Template:HIPAA_Compliance:_An_Introduction/Additional_compliance_guidance&amp;diff=46312&amp;oldid=prev"/>
		<updated>2022-02-10T23:02:44Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Disposal of PHI: &lt;/span&gt; Added image&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:02, 10 February 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Additional compliance guidance==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Additional compliance guidance==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Disposal of PHI===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;===Disposal of PHI===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In the previous section, we learned that HIPAA requires covered entities to apply appropriate administrative, technical and physical safeguards to protect the privacy of PHI in any form. This means that covered entities must implement reasonable safeguards to limit incidental and avoid prohibited uses and disclosures of PHI, including in connection with its disposal.&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot;&amp;gt;{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/faq/575/what-does-hipaa-require-of-covered-entities-when-they-dispose-information/index.html |title=What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health information? |author=Office for Civil Rights |publisher=U.S. Department of Health &amp;amp; Human Services |date=06 November 2015 |accessdate=10 February 2022}}&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[File:Paper shredder news.jpg|right|350px]]&lt;/ins&gt;In the previous section, we learned that HIPAA requires covered entities to apply appropriate administrative, technical and physical safeguards to protect the privacy of PHI in any form. This means that covered entities must implement reasonable safeguards to limit incidental and avoid prohibited uses and disclosures of PHI, including in connection with its disposal.&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot;&amp;gt;{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/faq/575/what-does-hipaa-require-of-covered-entities-when-they-dispose-information/index.html |title=What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health information? |author=Office for Civil Rights |publisher=U.S. Department of Health &amp;amp; Human Services |date=06 November 2015 |accessdate=10 February 2022}}&amp;lt;/ref&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, the HIPAA Security Rule requires that covered entities implement policies and procedures to&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In addition, the HIPAA Security Rule requires that covered entities implement policies and procedures to&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key limswiki:diff::1.12:old-46304:rev-46312 --&gt;
&lt;/table&gt;</summary>
		<author><name>Shawndouglas</name></author>
	</entry>
	<entry>
		<id>https://www.limswiki.org/index.php?title=Template:HIPAA_Compliance:_An_Introduction/Additional_compliance_guidance&amp;diff=46304&amp;oldid=prev</id>
		<title>Shawndouglas: Created as needed.</title>
		<link rel="alternate" type="text/html" href="https://www.limswiki.org/index.php?title=Template:HIPAA_Compliance:_An_Introduction/Additional_compliance_guidance&amp;diff=46304&amp;oldid=prev"/>
		<updated>2022-02-10T22:45:41Z</updated>

		<summary type="html">&lt;p&gt;Created as needed.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Additional compliance guidance==&lt;br /&gt;
===Disposal of PHI===&lt;br /&gt;
In the previous section, we learned that HIPAA requires covered entities to apply appropriate administrative, technical and physical safeguards to protect the privacy of PHI in any form. This means that covered entities must implement reasonable safeguards to limit incidental and avoid prohibited uses and disclosures of PHI, including in connection with its disposal.&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot;&amp;gt;{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/faq/575/what-does-hipaa-require-of-covered-entities-when-they-dispose-information/index.html |title=What do the HIPAA Privacy and Security Rules require of covered entities when they dispose of protected health information? |author=Office for Civil Rights |publisher=U.S. Department of Health &amp;amp; Human Services |date=06 November 2015 |accessdate=10 February 2022}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In addition, the HIPAA Security Rule requires that covered entities implement policies and procedures to&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
* address the final disposition of electronic PHI and/or the hardware or electronic media on which it is stored; and&lt;br /&gt;
* implement procedures for removal of electronic PHI from electronic media before the media are made available for re-use, per 45 CFR 164.310(d)(2)(i) and (ii). &lt;br /&gt;
&lt;br /&gt;
Failing to implement reasonable safeguards to protect PHI in connection with disposal could result in impermissible disclosures of PHI, which exposes the risk of fines and other sanctions.&lt;br /&gt;
&lt;br /&gt;
Additionally, workforce members must receive training on and follow those disposal policies and procedures, as necessary and appropriate for each workforce member, per 45 CFR 164.306(a)(4), 164.308(a)(5), and 164.530(b) and (i). Therefore, any workforce member involved in disposing of PHI, or who supervises others who dispose of PHI, must receive training on disposal. This includes any volunteers.&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These requirements are not met if covered entities simply abandon PHI or dispose of it in dumpsters or other containers that are accessible by the public or other unauthorized persons. However, the Privacy and Security Rules do not require a particular disposal method. Covered entities must review their own circumstances to determine what steps are reasonable to safeguard PHI through disposal, and develop and implement policies and procedures to carry out those steps. In determining what is reasonable, covered entities should assess potential risks to patient privacy, as well as consider such issues as the form, type and amount of PHI to be disposed. For instance, the disposal of certain types of PHI such as name, social security number, driver’s license number, debit or credit card number, diagnosis, treatment information or other sensitive information may warrant more care due to the risk that inappropriate access to this information may result in identity theft, employment or other discrimination, or harm to an individual’s reputation.&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In general, examples of proper disposal methods may include, but are not limited to&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
* shredding, burning, pulping or pulverizing PHI on paper records so that PHI is rendered essentially unreadable, indecipherable and otherwise cannot be reconstructed&lt;br /&gt;
* clearing (using software or hardware products to overwrite media with non-sensitive data), purging (degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains), or destroying (disintegration, pulverization, melting, incinerating, or shredding) PHI on electronic media&lt;br /&gt;
* maintaining labeled prescription bottles and other PHI in opaque bags in a secure area and using a disposal vendor as a business associate to pick up and shred or otherwise destroy the PHI&lt;br /&gt;
&lt;br /&gt;
For more information on proper disposal of e-PHI, see the HHS [https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/physsafeguards.pdf HIPAA Security Series 3 Security Standards: Physical Safeguards]. Additionally, for practical information on how to handle sanitization of PHI throughout the information lifecycle, you can consult [https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization].&lt;br /&gt;
&lt;br /&gt;
Other methods of disposal also may be appropriate, depending on the circumstances. Covered entities are encouraged to consider the steps that other prudent healthcare and health information professionals are taking to protect patient privacy in connection with record disposal. Resources like [https://www.limsforum.com/ LIMSforum] provide useful information and experience exchange. In addition, if a covered entity is closing a business, it may wish to consider giving patients the opportunity to pick up their records prior to any disposition (however, keep in mind that many states may impose requirements on covered entities to retain and make available for a limited time, as appropriate, medical records after dissolution of a business).&amp;lt;ref name=&amp;quot;HHSWhatDo&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Enforcement and penalties===&lt;br /&gt;
As discussed in the prior section, the OCR may impose a penalty on a covered entity for a failure to comply with a requirement of the Privacy or Security Rules. Penalties will vary significantly depending on factors such as the date of the violation, whether the covered entity knew or should have known of the failure to comply, or whether the covered entity’s failure to comply was due to willful neglect. Penalties may not exceed a calendar year cap for multiple violations of the same requirement.&amp;lt;ref name=&amp;quot;HHSSummaryHIPAA&amp;quot;&amp;gt;{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html |title=Summary of the HIPAA Privacy Rule |author=Office for Civil Rights |publisher=United States Department of Health and Human Services |date=26 July 2013 |accessdate=09 February 2022}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Current penalties and cap include&amp;lt;ref name=&amp;quot;HHSSummaryHIPAA&amp;quot; /&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
* Penalty amount: $100 to $50,000 or more per violation&lt;br /&gt;
* Calendar year cap: $1,500,000&lt;br /&gt;
&lt;br /&gt;
A penalty will not be imposed for violations in certain circumstances, such as if&amp;lt;ref name=&amp;quot;HHSSummaryHIPAA&amp;quot; /&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
# the failure to comply was not due to willful neglect, and was corrected during a 30-day period after the entity knew or should have known the failure to comply had occurred (unless the period is extended at the discretion of OCR); or&lt;br /&gt;
# the Department of Justice has imposed a criminal penalty for the failure to comply.&lt;br /&gt;
&lt;br /&gt;
Additionally, OCR has the option to reduce a penalty if the failure to comply was due to reasonable cause and the penalty would be excessive given the nature and extent of the noncompliance. Before OCR imposes a penalty, it will notify the covered entity and provide the them with an opportunity to submit written evidence of those circumstances that would reduce or avoid a penalty. This evidence must be submitted to OCR within 30 days of receipt of the notice. In addition, if OCR states that it intends to impose a penalty, a covered entity has the right to request an administrative hearing to appeal the proposed penalty.&amp;lt;ref name=&amp;quot;HHSSummaryHIPAA&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Criminal penalties====&lt;br /&gt;
A person who knowingly obtains or discloses individually identifiable health information in violation of the Privacy Rule may face a criminal penalty of up to $50,000 and up to one-year imprisonment. The criminal penalties increase to $100,000 and up to five years imprisonment if the wrongful conduct involves false pretenses, and to $250,000 and up to 10 years imprisonment if the wrongful conduct involves the intent to sell, transfer or use identifiable health information for commercial advantage, personal gain or malicious harm. The Department of Justice is responsible for criminal prosecutions under the Privacy Rule.&amp;lt;ref name=&amp;quot;HHSSummaryHIPAA&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;HIPAASecurity&amp;quot;&amp;gt;{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html |title=Summary of the HIPAA Security Rule |author=Office for Civil Rights |publisher=U.S. Department of Health and Human Services |date=26 July 2013 |accessdate=10 February 2022}}&amp;lt;/ref&amp;gt;&lt;/div&gt;</summary>
		<author><name>Shawndouglas</name></author>
	</entry>
</feed>