Skip to Content
  • Craft’s easy-to-use platform simplifies supply chain resilience and speeds time to value with new enhanced capabilities

    Learn More
Craft Logo
  • Platform
  • Solutions
    • Supplier Intelligence

      Conduct checks in hours instead of weeks with comprehensive supplier intelligence you can trust.

    • Supplier Risk Management

      Stay alerted to changes in supplier health to understand threats and avoid disruption.

    • Supply Chain Risk Management

      Gain insights into supplier dependencies and risks to predict and prevent disruption.

  • Risk and Compliance
    • Risk and Compliance Solutions

    • Compliance Hub

      Navigate complex regulatory landscapes

    • Cybersecurity

      Defend against cyber threats.

    • ESG

      Empower sustainable practices with ESG insights.

    • Financial

      Identify and navigate financial risks.

    • Geopolitical

      Navigate geopolitical risks with confidence.

  • Industries
    • Aerospace and Defense

      Simplify risk management in this complex and crucial sector.

    • Federal Government

      Enhance risk visibility and mitigation in federal government.

    • Financial Services

      Navigate challenges within the financial services sector.

    • Manufacturing

      Optimize risk management in manufacturing.

  • Resource Center
    • Resources

      Learn more about Craft, our vision, and what we’re doing to strengthen global supply chain resilience.

    • Blog

      Explore Craft thought leadership from our technology and supply chain experts.

    • Events

      Get the latest industry news, topics, and trends from Craft experts.

  • Company
    • About Us

      Learn about our mission, world-class technology, and esteemed investors.

    • Culture & Careers

      Learn about our culture and check out our current job postings.

    • Newsroom

      Stay up to date on our latest news and announcements.

    • Contact Us

      Learn more about the Craft platform and how we can mitigate risk to your supply chain.

  • Request a Demo
Quick GuidesRegulatory & Compliance

Understanding the Health Insurance Portability and Accountability Act (HIPAA)

Share


What is the Health Insurance Portability and Accountability Act (HIPAA)?

The Health Insurance Portability and Accountability Act (HIPAA) was enacted by the U.S. Congress in 1996. It sets national standards for the protection of sensitive patient health information, ensuring that personal health information is properly safeguarded while allowing the necessary flow of health information to provide high-quality healthcare and protect public health.

Why was HIPAA created?

HIPAA was created to improve the efficiency and effectiveness of the healthcare system by standardizing the electronic transmission of administrative and financial transactions. Additionally, it aims to protect the privacy and security of patients’ medical information and reduce healthcare fraud and abuse.

Who has to comply with HIPAA?

HIPAA compliance is mandated for:

  • Health plans, including insurers, HMOs, and employer-sponsored health plans.
  • Healthcare clearinghouses that process nonstandard health information they receive from another entity into a standard format.
  • Healthcare providers that conduct certain transactions in electronic form.
  • Business associates of these covered entities who have access to patient information and provide support in treatment, payment, or operations.

How will the HIPAA affect businesses?

Businesses affected by HIPAA are required to adopt significant measures to ensure the confidentiality, integrity, and availability of protected health information. They must implement safeguards that protect the information, train their workforce on privacy and security policies, and manage potential risks proactively.

What are the penalties for noncompliance with HIPAA?

Civil Penalties:

  • Tier 1: For violations where the entity was unaware and could not have realistically avoided, minimum fines start at $100 per violation up to $50,000.
  • Tier 2: For violations due to reasonable cause and not willful neglect, fines start at $1,000 per violation up to $50,000.
  • Tier 3: For violations due to willful neglect but corrected within a timely manner, fines start at $10,000 per violation up to $50,000.
  • Tier 4: For violations of willful neglect not corrected, fines are $50,000 per violation.

Criminal Penalties:

  • Tier 1: Up to $50,000 and one year in prison for obtaining or disclosing protected health information without authorization.
  • Tier 2: Up to $100,000 and up to five years in prison for obtaining protected health information under “false pretenses.”
  • Tier 3: Up to $250,000 and up to ten years in prison for obtaining or disclosing protected health information with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm.

How do you comply with HIPAA?

Compliance with HIPAA involves:

  • Conducting a thorough risk assessment to identify threats to the security of personal health information (PHI).
  • Implementing administrative, physical, and technical safeguards tailored to the entity’s needs.
  • Training staff on HIPAA regulations and the entity’s privacy and security policies.
  • Establishing a process for addressing patient rights requests regarding their health information.

How do you prepare for HIPAA?

Preparation for HIPAA compliance includes:

  • Developing and updating a set of privacy and security policies that comply with HIPAA standards.
  • Regularly training all employees on these policies and HIPAA’s general provisions.
  • Engaging in periodic audits and compliance reviews to ensure ongoing adherence to HIPAA requirements.

Action Plan for Complying with HIPAA

1. Conduct Comprehensive Risk Assessments:

  • Perform annual and as-needed risk analyses to identify vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). Implement measures to mitigate identified risks.

2. Implement Robust Safeguards:

  • Apply physical, administrative, and technical safeguards. This includes secure access controls, encryption of ePHI, and physical security measures to protect data and premises.

3. Employee Training and Management:

  • Provide ongoing, role-specific training on HIPAA compliance to all employees who handle PHI. Ensure that staff understands the importance of HIPAA and the specifics of your organization’s policies and procedures.

4. Develop and Enforce Policies and Procedures:

  • Regularly update and enforce policies and procedures that comply with HIPAA requirements. Include processes for managing data breaches, data access controls, and the use of secure communication channels.

5. Regular Auditing and Compliance Monitoring:

  • Schedule routine audits to assess the effectiveness of HIPAA compliance measures. Use audit results to refine policies and training, and address any compliance gaps immediately.

How can Craft help?

Craft’s supplier risk management solutions are designed to streamline compliance and enhance reporting. With our platform:

  • Identify risky suppliers with in-depth company profiles and easily scalable due diligence
  • Continuously monitor your supplier network for changes and potential violations
  • Document your efforts for proof of compliance
  • Collaborate and share information across teams for faster risk mitigation

Learn More

Related Regulations

  • General Data Protection Regulation (GDPR): Protects personal data and privacy for individuals within the European Union.
  • California Consumer Privacy Act (CCPA): Offers consumer privacy rights and affects all businesses that serve California residents.
  • Family Educational Rights and Privacy Act (FERPA): Governs the access to educational information and privacy.

Conclusion

Navigating HIPAA’s comprehensive requirements is crucial for any organization handling health-related information. Effective compliance not only protects patient data but also shields organizations from severe penalties. By leveraging strategic practices and advanced tools such as those provided by Craft, businesses can maintain robust compliance, ensuring both operational integrity and trust with clients and partners.

For further details on HIPAA compliance strategies, visit Craft’s compliance hub.

Share

In this article

  • What is the Health Insurance Portability and Accountability Act (HIPAA)?

  • Why was HIPAA created?

  • Who has to comply with HIPAA?

  • How will the HIPAA affect businesses?

  • What are the penalties for noncompliance with HIPAA?

  • How do you comply with HIPAA?

  • How do you prepare for HIPAA?

  • Action Plan for Complying with HIPAA

  • How can Craft help?

  • Related Regulations

  • Conclusion

  • Risk and Compliance Solutions

    Get the visibility and insights you need to identify and mitigate risk and build a more resilient supply chain.

    Learn More

Related Posts

View All
  • Procurement & Supply Chain

    The Risk Savvy Report: April 22 – May 12, 2025

    Read Now
  • Procurement & Supply Chain

    The Risk Savvy Report: April 1 – 21, 2025

    Read Now
  • Procurement & Supply Chain

    The Risk Savvy Report: March 18 – 31, 2025

    Read Now

Ready to learn more?

Schedule a risk assessment session with our team to learn more about Craft.

Get Risk Assessment
Craft.co

Craft provides organizations with the 360-degree visibility, timely insights, and agility needed to mitigate risk and build stronger supplier networks and more resilient supply chains.


Sign up for our newsletter

  • Platform
  • Solutions
    • Supplier Intelligence
    • Supplier Risk Management
    • Supply Chain Risk Management
  • Risk and Compliance
    • Risk and Compliance Solutions
    • Compliance Hub
    • Cybersecurity
    • ESG
    • Financial
    • Geopolitical
  • Industries
    • Aerospace and Defense
    • Federal Government
    • Financial Services
    • Manufacturing
  • Resource Center
    • Resources
    • Blog
    • Events
  • Company
    • About Us
    • Culture & Careers
    • Newsroom
    • Contact Us
  • Request a Demo
  • Facebook
  • LinkedIn
  • Twitter
  • Terms of Service
  • Privacy Policy
  • Security

© 2025 Craft.co. All rights reserved.

We value your privacy
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits.
By clicking “Accept”, you consent to the use of ALL the cookies.
Privacy Policy
In case of sale of your personal information, you may opt out by using the link Do not sell my personal information.
CustomizeAccept
Consent Preferences

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
Reject All Save My Preferences Accept All