Free guidee-book
HIPAA Compliance: An Introduction
A free LabLynx e-book on HIPAA compliance for healthcare and lab staff, from covered entities and protected health information to the Privacy and Security Rules.

Get your free copy
- e-book
- Instant download
"*" indicates required fields
We also email you the link.
HIPAA compliance is how healthcare providers, health plans, clearinghouses and their business associates meet the Health Insurance Portability and Accountability Act of 1996: protecting patients' health information, respecting their rights over it and training every workforce member to handle it. This LabLynx guide is a training introduction to the Privacy Rule, the Security Rule, protected health information and who must comply.
What you will learn
- What HIPAA covers. The Privacy Rule, the Security Rule, and who oversees them.
- Whether it applies to you. Covered entities, business associates and when an agreement between them is required.
- What counts as PHI. The 18 identifiers, and the two approved ways to de-identify patient data.
- When PHI may be shared. Permitted uses and disclosures, authorizations, the minimum necessary standard and patients' rights.
- How to protect it. Administrative, physical and technical safeguards, safe disposal and workforce training.
What is inside the guide
From why training matters to how to dispose of PHI safely: here is what the guide covers, section by section.
Why HIPAA training matters
HIPAA itself requires covered entities to train every workforce member, from employees to volunteers and trainees, on their privacy policies and procedures. The guide was written because too many HIPAA courses fall short in scope, clarity and accuracy, and it draws almost entirely on first-hand material from HHS and the law itself.
What HIPAA is
Where CLIA sets standards for clinical testing, HIPAA protects patients' personal information, and it applies to almost any entity that handles it. The guide explains its two main areas, the Privacy Rule and the Security Rule, and the oversight role of HHS and its Office for Civil Rights.
Go deeper: HIPAA compliance in the laboratory
Who needs to comply
Covered entities are health plans, healthcare clearinghouses and any provider that transmits health information electronically in a standard transaction, such as a claim. Business associates that handle PHI on their behalf are covered too, and the guide sets out what a business associate agreement must contain and when none is needed, as when a hospital lab sends PHI to a reference lab for a patient's treatment.
Protected health information
PHI is individually identifiable health information held or transmitted by a covered entity or business associate, whether electronic, paper or oral. The guide lists the 18 identifiers that make data PHI and the two approved ways to de-identify it: the Safe Harbor method and a qualified expert's statistical determination.
Go deeper: Laboratory data privacy
Use and disclosure
When PHI may be used or disclosed without a patient's authorization, from treatment, payment and healthcare operations to 12 national priority purposes, and when written authorization is required. The guide covers the minimum necessary standard, role-based access, patients' rights to notice, access, amendment and an accounting of disclosures, and who can act as a patient's personal representative.
Go deeper: Need-to-know access in the lab
Administration
The guide lists what a covered entity must have in place: written privacy policies, a privacy official, workforce training and sanctions, mitigation, data safeguards, a complaints process and documentation. It also explains organizational options such as hybrid and affiliated entities, and the standards for electronic transactions, code sets and identifiers.
Security
The Security Rule protects electronic PHI and asks covered entities to keep it confidential, intact and available. It does not dictate specific measures, so the guide explains risk analysis, the administrative, physical and technical safeguards, and why an "addressable" specification is not optional.
Go deeper: Lab cybersecurity
Additional compliance guidance
How to dispose of PHI safely, from shredding and pulping paper records to clearing, purging or destroying electronic media, and why everyone who handles disposal needs training on it. The guide ends with an overview of enforcement and penalties as they stood when it was compiled in 2022.
Key takeaways
- HIPAA has two main parts. The Privacy Rule covers patients' rights over their health information and what covered entities must do to support them; the Security Rule covers the administrative, physical and technical protection of that data.
- It reaches beyond healthcare providers. Health plans and clearinghouses are covered entities too, and since the HITECH Act their business associates, and those associates' subcontractors, are subject to HIPAA as well.
- PHI is defined by whether it can identify a patient. The guide lists 18 identifiers, from names and dates to IP addresses and photographs, and two approved ways to de-identify data.
- Share the minimum necessary. Outside treatment and a few other exceptions, use, disclose and request only the PHI a purpose needs, and limit staff access to PHI by role.
- Training is part of the law. Every workforce member, including volunteers and trainees, must be trained on privacy policies as their job requires, and sanctions applied when they are broken.
Administrative requirements and recommendations
Policies and a privacy official
Written privacy policies and procedures consistent with the Privacy Rule, an official responsible for them, and a contact for complaints and questions.
Workforce training and sanctions
Train every workforce member as their role requires, and apply sanctions to those who violate the policies or the Privacy Rule.
Data safeguards
Administrative, technical and physical measures, such as shredding documents that hold PHI and locking medical records away.
Mitigation and complaints
Lessen any harm from a use or disclosure that breaks the rules, give individuals a way to complain, and never retaliate against them.
Documentation
Keep the privacy policies, notices, complaint records and other documentation the Privacy Rule requires, which the guide says must be kept for six years after they were created or last in effect.
Who it is for
Lab and healthcare staff
who handle patient information every day and need an accurate, plain grounding in what HIPAA asks of them.
Privacy and security officials
who write their organization's policies and procedures and want the rules summarized from HHS's own material.
Managers who run HIPAA training
who must train every workforce member, from employees to volunteers, and want a course that is thorough and clear.
Written for Clinical, hospital and reference laboratories, alongside hospitals, clinics, physician and dental practices, nursing homes and pharmacies.
Who does the guide say has to comply with HIPAA?
What does the guide count as protected health information?
How does the guide explain de-identifying patient data?
How does the guide explain the minimum necessary standard?
What does the guide say the Security Rule requires?
What does the guide say about training staff on HIPAA?

Free guide
HIPAA Compliance: An Introduction
e-book
- What HIPAA covers
- Whether it applies to you
- What counts as PHI



