HIPAA Fundamentals Training¶
Estimated Time: 45 minutes Audience: All Employees (mandatory for anyone who may encounter healthcare customer materials) Frequency: At hire + annually Prerequisite: Compliance Fundamentals
Course Overview¶
| Lesson | Topic | Time |
|---|---|---|
| 1 | What Is HIPAA and Why Does It Apply to Us? | 10 min |
| 2 | Recognizing PHI | 10 min |
| 3 | Handling PHI at Scott Recycling | 10 min |
| 4 | Breach Reporting — What to Do When Something Goes Wrong | 10 min |
| 5 | Knowledge Check | 5 min |
After completing this course, you will understand what HIPAA requires of Scott Recycling, how to recognize and handle Protected Health Information, and what to do if a breach occurs.
Lesson 1: What Is HIPAA and Why Does It Apply to Us? (10 min)¶
Learning Objectives¶
- Understand what HIPAA is and who it protects
- Know why Scott Recycling is considered a Business Associate
- Understand the consequences of HIPAA violations
What Is HIPAA?¶
HIPAA is the Health Insurance Portability and Accountability Act — a federal law that protects patient health information. It requires healthcare organizations to keep patient data private and secure, and it extends those requirements to any company that handles patient data on their behalf.
Why Does HIPAA Apply to a Recycling Company?¶
When Scott Recycling picks up, transports, or destroys materials from a healthcare customer — a hospital, clinic, medical group, dentist, pharmacy, or similar organization — we may encounter Protected Health Information (PHI). That makes us a Business Associate under HIPAA.
PHI can be on:
- Hard drives and storage devices inside computers and servers
- Paper records found inside or with equipment
- Labels on equipment (patient names, medical record numbers)
- USB drives, backup tapes, phones, tablets
- Printed documents left inside printers and copiers
What Is a Business Associate Agreement (BAA)?¶
Before we can work with a healthcare customer, they require us to sign a Business Associate Agreement (BAA) — a legal contract that says we will protect any PHI we encounter and follow HIPAA rules.
What Happens If We Violate HIPAA?¶
This Is Serious
- Company fines: $100 to $50,000 per violation, up to $1.5 million per year
- Criminal penalties: Fines up to $250,000 and up to 10 years in prison
- Individual liability: Employees can be held personally responsible
- Loss of customers: Healthcare organizations will not work with a company that has had a HIPAA breach
- Reputation damage: A breach makes the news and damages trust with all customers, not just healthcare
Key Takeaway¶
Every employee at Scott Recycling has a role in protecting patient information. HIPAA is not just a policy — it is federal law, and violations have real consequences for the company and for individuals.
Lesson 2: Recognizing PHI (10 min)¶
Learning Objectives¶
- Define Protected Health Information (PHI)
- Identify common places PHI appears in our work
- Distinguish healthcare customer materials from general materials
What Is PHI?¶
Protected Health Information (PHI) is any information that:
- Relates to a person's health, healthcare, or payment for healthcare, AND
- Can identify the individual (or could reasonably be used to identify them)
18 HIPAA Identifiers¶
If any of these appear alongside health information, it is PHI:
| # | Identifier | Examples You Might See |
|---|---|---|
| 1 | Names | "Jane Smith" on a patient chart |
| 2 | Addresses (smaller than state) | Street address on a billing record |
| 3 | Dates (except year) | Date of birth, admission date, discharge date |
| 4 | Phone numbers | Patient contact on a form |
| 5 | Fax numbers | On a fax cover sheet |
| 6 | Email addresses | In a patient file |
| 7 | Social Security numbers | On insurance or billing records |
| 8 | Medical record numbers | "MRN: 12345678" on a label or chart |
| 9 | Health plan beneficiary numbers | Insurance member ID |
| 10 | Account numbers | Patient account on a billing statement |
| 11 | Certificate/license numbers | On professional records |
| 12 | Vehicle identifiers | Patient file with car info |
| 13 | Device identifiers | Serial numbers of implanted medical devices |
| 14 | Web URLs | Patient portal links |
| 15 | IP addresses | In system logs |
| 16 | Biometric identifiers | Fingerprints, voiceprints |
| 17 | Full-face photos | Patient photos in records |
| 18 | Any other unique identifier | "Patient #4492" |
Where Will You Encounter PHI at Scott Recycling?¶
| Your Role | Where to Watch for PHI |
|---|---|
| Drivers | Paper records inside equipment, labels on computers, loose documents in boxes, labels on shipping containers |
| Warehouse / Receiving | Paper records mixed in with equipment, labels on hard drives and devices, records inside printers and copiers |
| Processing / Hard Drive Team | Data on hard drives and storage media (you cannot see it, but it is there — follow the destruction process for ALL devices) |
| Office / CSR | Customer records in Odoo that include healthcare customer information |
Practice: Is This PHI?¶
Think about each scenario:
| Scenario | PHI? | Why? |
|---|---|---|
| A hard drive from a hospital labeled "Radiology Dept Server 3" | Maybe — the drive likely contains patient images and records. The label itself is not PHI but the contents are. Treat as PHI. | Contains health data + identifiers |
| A box of papers from a medical office with patient names and appointment dates | Yes — patient names + dates of service = PHI | Name + date + healthcare context |
| A Dell laptop from a law firm | No — not from a healthcare customer | No healthcare context |
| A sticky note on a hospital PC that says "Nurse Station 4" | No — no patient-identifying information | No identifiers |
| A printed page with patient names, diagnoses, and insurance numbers found inside a printer from a clinic | Absolutely yes — this is PHI in multiple ways | Names + diagnoses + insurance = PHI |
Rule of Thumb
If materials come from a healthcare customer AND you can see any person's name, date, number, or medical information — treat it as PHI. When in doubt, treat it as PHI.
Lesson 3: Handling PHI at Scott Recycling (10 min)¶
Learning Objectives¶
- Follow correct PHI handling procedures for your role
- Understand the Minimum Necessary Standard
- Know what you must NEVER do with PHI
The Minimum Necessary Standard¶
HIPAA requires that you only access or use the minimum amount of PHI necessary to do your job. In practice, this means:
- Do not read patient records you find in equipment — you don't need to read them to destroy them
- Do not browse files on hard drives before wiping them
- Do not discuss specific patient information you happen to see
- Do not copy or photograph PHI
What to Do — By Role¶
Drivers¶
| Step | Action |
|---|---|
| 1 | Know your healthcare customers — your route sheet identifies the customer. If it is a hospital, clinic, or medical office, treat all materials as potentially containing PHI |
| 2 | Keep materials secure — do not leave healthcare customer materials unattended on the truck with doors open |
| 3 | Separate when feasible — keep healthcare customer materials distinct from other loads |
| 4 | Report loose PHI — if you see paper records with patient names or medical information, tell your supervisor. Do not throw them away or leave them |
| 5 | Do not photograph — never take pictures of patient records, labels, or documents |
Warehouse and Receiving¶
| Step | Action |
|---|---|
| 1 | Check the customer — is this shipment from a healthcare customer? |
| 2 | Segregate data-bearing devices — move hard drives, storage media, phones, and tablets to the secure staging area immediately |
| 3 | Collect paper PHI — gather any paper records found with the equipment and route them to secure shredding (cross-cut) |
| 4 | Do not leave PHI on the open floor — healthcare materials go to secure areas, not general sorting |
| 5 | Do not read — collect and secure paper records without reading them |
Processing / Hard Drive Team¶
| Step | Action |
|---|---|
| 1 | Follow chain of custody — every device from a healthcare customer must be tracked by serial number per the Data Destruction Procedures |
| 2 | Destroy to standard — NIST 800-88 Purge (minimum) for software wipe, or physical destruction |
| 3 | Verify destruction — confirm and document that the wipe or destruction was successful |
| 4 | Issue Certificate of Destruction — healthcare customers require this documentation |
| 5 | Report failures — if a drive cannot be wiped, escalate to physical destruction immediately |
Office and CSR¶
| Step | Action |
|---|---|
| 1 | Do not email PHI — never send patient names, medical record numbers, or health information by regular email |
| 2 | Restrict access — only view healthcare customer records when needed for your job |
| 3 | Route requests — if a healthcare customer asks about patient rights, data access, or amendments, route to the IT Manager immediately |
| 4 | Secure documents — keep any paper BAAs or healthcare contracts in locked storage |
Things You Must NEVER Do¶
Absolute Prohibitions
- NEVER read patient records out of curiosity
- NEVER take photos of PHI or share it on social media
- NEVER discuss specific patient information with coworkers, friends, or family
- NEVER take PHI home or remove it from the facility (except during authorized transport)
- NEVER throw paper PHI in regular trash or recycling — it must be cross-cut shredded
- NEVER email PHI in plain text
- NEVER ignore PHI you find — secure it and report it
Lesson 4: Breach Reporting — What to Do When Something Goes Wrong (10 min)¶
Learning Objectives¶
- Recognize a potential breach
- Know exactly what to do if you suspect a breach
- Understand the notification timeline
What Is a Breach?¶
A breach is when PHI is accessed, used, or disclosed in a way that is not permitted. Examples:
- A hard drive from a hospital is lost or stolen before it was destroyed
- Paper patient records are found in the regular trash instead of secure shredding
- Healthcare customer materials fall off the truck during transport
- An employee reads patient records that were found in equipment
- An unauthorized person accesses the secure staging area
- Healthcare customer data is emailed to the wrong person
What to Do If You Suspect a Breach¶
Follow these steps immediately — do not wait:
Step 1: STOP the breach if you can
→ Secure the PHI, restrict access, recover materials
Step 2: REPORT to your supervisor — RIGHT NOW, verbally
→ Do not wait until the end of your shift
→ Do not assume someone else will report it
Step 3: DOCUMENT what you observed
→ What happened? When? What PHI might be involved?
→ Who was involved? What did you do?
Step 4: DO NOT try to investigate on your own
→ The HIPAA Security Officer (IT Manager) leads the investigation
→ Just report what you know
Time Is Critical
Scott Recycling must notify the healthcare customer within 5 business days of ANY employee becoming aware of the breach. That clock starts when you notice something wrong — not when management finds out. Report immediately.
What Happens After You Report¶
- Your supervisor escalates to the IT Manager (HIPAA Security Officer) within 1 hour
- The IT Manager investigates and determines if it is a reportable breach
- If it is a breach, management is notified and the healthcare customer is contacted within 5 business days
- Corrective actions are implemented to prevent it from happening again
- The incident is documented and retained for 6 years
You Will NOT Be Punished for Reporting¶
Scott Recycling will not discipline any employee for reporting a suspected breach in good faith. Even if you were involved in the incident, reporting it promptly will always be viewed more favorably than concealing it.
Remember
See something? Say something. Reporting a suspected breach — even if it turns out not to be one — is always the right call.
Lesson 5: Knowledge Check (5 min)¶
Answer these questions to confirm your understanding. Discuss any incorrect answers with your supervisor.
Question 1¶
A driver picks up 20 desktop computers from a medical clinic. Inside one of the towers, he finds a folder of papers with patient names, dates of birth, and insurance information. What should he do?
Answer
Do not read the papers. Secure them with the rest of the healthcare customer's materials on the truck. Report the loose PHI to his supervisor as soon as possible. At receiving, ensure the papers are routed to secure cross-cut shredding.
Question 2¶
A warehouse employee is sorting materials from a hospital pickup and notices that two hard drives from the shipment are missing compared to the receiving log. What should he do?
Answer
Report it to his supervisor immediately. This is a potential breach — two data-bearing devices from a healthcare customer are unaccounted for. The supervisor must escalate to the IT Manager (HIPAA Security Officer) within 1 hour. Do not wait to see if the drives "turn up."
Question 3¶
A CSR gets a phone call from someone claiming to be a patient at Java Medical Group. They want to know if their old computer was destroyed and ask for the serial number. What should the CSR do?
Answer
Do not provide any information to the caller. Patient requests for information about their PHI must go through the healthcare customer (Covered Entity), not directly through Scott Recycling. Politely explain that you cannot release that information and suggest they contact Java Medical Group directly. Route the inquiry to the IT Manager.
Question 4¶
A processing employee is wiping hard drives from a hospital and one drive fails the wipe verification. He figures it is probably fine and marks it as complete. Is this OK?
Answer
Absolutely not. A failed wipe means the data has not been destroyed. The employee must flag the drive as "wipe failed," escalate it to physical destruction, and update the tracking record. Marking it as complete when the wipe failed is a serious violation that could result in a breach.
Question 5¶
An employee accidentally drops a box of hard drives from a clinic in the parking lot. None of the drives appear damaged, and he picks them all up. Does he need to report this?
Answer
Yes. Even though the drives appear undamaged, they were briefly in an unsecured area. Report it to a supervisor, who can assess whether any drives are missing or if the incident needs to be escalated. It may not be a breach, but it must be documented.
Training Completion¶
After completing this course:
- Sign the training acknowledgment form confirming that you have read and understood this material
- Ask your supervisor if you have any questions about PHI handling in your specific role
- Review the reference card posted in the break room (summary of PHI dos and don'ts)
Training Record¶
| Field | Details |
|---|---|
| Employee Name | ______ |
| Date Completed | ______ |
| Trainer | ______ |
| Employee Signature | ______ |
Training records are retained for a minimum of 6 years per HIPAA requirements.
Quick Reference Card¶
Print this and post it in work areas:
┌─────────────────────────────────────────────────┐
│ HIPAA QUICK REFERENCE — PHI │
├─────────────────────────────────────────────────┤
│ │
│ PHI = Patient names, DOB, SSN, medical record │
│ numbers, diagnoses, insurance info, or anything │
│ that identifies a patient + their health data │
│ │
│ DO: │
│ ✓ Treat all healthcare customer materials │
│ as potentially containing PHI │
│ ✓ Secure PHI immediately — locked area only │
│ ✓ Follow chain of custody for all devices │
│ ✓ Cross-cut shred paper PHI │
│ ✓ Report suspected breaches IMMEDIATELY │
│ │
│ DON'T: │
│ ✗ Read patient records │
│ ✗ Photograph PHI │
│ ✗ Discuss patient info with anyone │
│ ✗ Email PHI in plain text │
│ ✗ Throw paper PHI in regular trash │
│ ✗ Ignore missing devices from a healthcare │
│ customer │
│ │
│ BREACH? → STOP → REPORT → DOCUMENT │
│ Tell your supervisor RIGHT NOW │
│ 5 business day notification deadline │
│ │
└─────────────────────────────────────────────────┘
What's Next?¶
- Read the full HIPAA Compliance Policy for complete details
- Read the HIPAA Breach Response Plan for the full incident response procedure
- Review the Data Destruction Procedures for detailed destruction methods and chain of custody
Questions? Contact the IT Manager (HIPAA Security Officer) or your supervisor.