Skip to content

HIPAA Fundamentals Training

Estimated Time: 45 minutes Audience: All Employees (mandatory for anyone who may encounter healthcare customer materials) Frequency: At hire + annually Prerequisite: Compliance Fundamentals


Course Overview

Lesson Topic Time
1 What Is HIPAA and Why Does It Apply to Us? 10 min
2 Recognizing PHI 10 min
3 Handling PHI at Scott Recycling 10 min
4 Breach Reporting — What to Do When Something Goes Wrong 10 min
5 Knowledge Check 5 min

After completing this course, you will understand what HIPAA requires of Scott Recycling, how to recognize and handle Protected Health Information, and what to do if a breach occurs.


Lesson 1: What Is HIPAA and Why Does It Apply to Us? (10 min)

Learning Objectives

  • Understand what HIPAA is and who it protects
  • Know why Scott Recycling is considered a Business Associate
  • Understand the consequences of HIPAA violations

What Is HIPAA?

HIPAA is the Health Insurance Portability and Accountability Act — a federal law that protects patient health information. It requires healthcare organizations to keep patient data private and secure, and it extends those requirements to any company that handles patient data on their behalf.

Why Does HIPAA Apply to a Recycling Company?

When Scott Recycling picks up, transports, or destroys materials from a healthcare customer — a hospital, clinic, medical group, dentist, pharmacy, or similar organization — we may encounter Protected Health Information (PHI). That makes us a Business Associate under HIPAA.

PHI can be on:

  • Hard drives and storage devices inside computers and servers
  • Paper records found inside or with equipment
  • Labels on equipment (patient names, medical record numbers)
  • USB drives, backup tapes, phones, tablets
  • Printed documents left inside printers and copiers

What Is a Business Associate Agreement (BAA)?

Before we can work with a healthcare customer, they require us to sign a Business Associate Agreement (BAA) — a legal contract that says we will protect any PHI we encounter and follow HIPAA rules.

What Happens If We Violate HIPAA?

This Is Serious

  • Company fines: $100 to $50,000 per violation, up to $1.5 million per year
  • Criminal penalties: Fines up to $250,000 and up to 10 years in prison
  • Individual liability: Employees can be held personally responsible
  • Loss of customers: Healthcare organizations will not work with a company that has had a HIPAA breach
  • Reputation damage: A breach makes the news and damages trust with all customers, not just healthcare

Key Takeaway

Every employee at Scott Recycling has a role in protecting patient information. HIPAA is not just a policy — it is federal law, and violations have real consequences for the company and for individuals.


Lesson 2: Recognizing PHI (10 min)

Learning Objectives

  • Define Protected Health Information (PHI)
  • Identify common places PHI appears in our work
  • Distinguish healthcare customer materials from general materials

What Is PHI?

Protected Health Information (PHI) is any information that:

  1. Relates to a person's health, healthcare, or payment for healthcare, AND
  2. Can identify the individual (or could reasonably be used to identify them)

18 HIPAA Identifiers

If any of these appear alongside health information, it is PHI:

# Identifier Examples You Might See
1 Names "Jane Smith" on a patient chart
2 Addresses (smaller than state) Street address on a billing record
3 Dates (except year) Date of birth, admission date, discharge date
4 Phone numbers Patient contact on a form
5 Fax numbers On a fax cover sheet
6 Email addresses In a patient file
7 Social Security numbers On insurance or billing records
8 Medical record numbers "MRN: 12345678" on a label or chart
9 Health plan beneficiary numbers Insurance member ID
10 Account numbers Patient account on a billing statement
11 Certificate/license numbers On professional records
12 Vehicle identifiers Patient file with car info
13 Device identifiers Serial numbers of implanted medical devices
14 Web URLs Patient portal links
15 IP addresses In system logs
16 Biometric identifiers Fingerprints, voiceprints
17 Full-face photos Patient photos in records
18 Any other unique identifier "Patient #4492"

Where Will You Encounter PHI at Scott Recycling?

Your Role Where to Watch for PHI
Drivers Paper records inside equipment, labels on computers, loose documents in boxes, labels on shipping containers
Warehouse / Receiving Paper records mixed in with equipment, labels on hard drives and devices, records inside printers and copiers
Processing / Hard Drive Team Data on hard drives and storage media (you cannot see it, but it is there — follow the destruction process for ALL devices)
Office / CSR Customer records in Odoo that include healthcare customer information

Practice: Is This PHI?

Think about each scenario:

Scenario PHI? Why?
A hard drive from a hospital labeled "Radiology Dept Server 3" Maybe — the drive likely contains patient images and records. The label itself is not PHI but the contents are. Treat as PHI. Contains health data + identifiers
A box of papers from a medical office with patient names and appointment dates Yes — patient names + dates of service = PHI Name + date + healthcare context
A Dell laptop from a law firm No — not from a healthcare customer No healthcare context
A sticky note on a hospital PC that says "Nurse Station 4" No — no patient-identifying information No identifiers
A printed page with patient names, diagnoses, and insurance numbers found inside a printer from a clinic Absolutely yes — this is PHI in multiple ways Names + diagnoses + insurance = PHI

Rule of Thumb

If materials come from a healthcare customer AND you can see any person's name, date, number, or medical information — treat it as PHI. When in doubt, treat it as PHI.


Lesson 3: Handling PHI at Scott Recycling (10 min)

Learning Objectives

  • Follow correct PHI handling procedures for your role
  • Understand the Minimum Necessary Standard
  • Know what you must NEVER do with PHI

The Minimum Necessary Standard

HIPAA requires that you only access or use the minimum amount of PHI necessary to do your job. In practice, this means:

  • Do not read patient records you find in equipment — you don't need to read them to destroy them
  • Do not browse files on hard drives before wiping them
  • Do not discuss specific patient information you happen to see
  • Do not copy or photograph PHI

What to Do — By Role

Drivers

Step Action
1 Know your healthcare customers — your route sheet identifies the customer. If it is a hospital, clinic, or medical office, treat all materials as potentially containing PHI
2 Keep materials secure — do not leave healthcare customer materials unattended on the truck with doors open
3 Separate when feasible — keep healthcare customer materials distinct from other loads
4 Report loose PHI — if you see paper records with patient names or medical information, tell your supervisor. Do not throw them away or leave them
5 Do not photograph — never take pictures of patient records, labels, or documents

Warehouse and Receiving

Step Action
1 Check the customer — is this shipment from a healthcare customer?
2 Segregate data-bearing devices — move hard drives, storage media, phones, and tablets to the secure staging area immediately
3 Collect paper PHI — gather any paper records found with the equipment and route them to secure shredding (cross-cut)
4 Do not leave PHI on the open floor — healthcare materials go to secure areas, not general sorting
5 Do not read — collect and secure paper records without reading them

Processing / Hard Drive Team

Step Action
1 Follow chain of custody — every device from a healthcare customer must be tracked by serial number per the Data Destruction Procedures
2 Destroy to standard — NIST 800-88 Purge (minimum) for software wipe, or physical destruction
3 Verify destruction — confirm and document that the wipe or destruction was successful
4 Issue Certificate of Destruction — healthcare customers require this documentation
5 Report failures — if a drive cannot be wiped, escalate to physical destruction immediately

Office and CSR

Step Action
1 Do not email PHI — never send patient names, medical record numbers, or health information by regular email
2 Restrict access — only view healthcare customer records when needed for your job
3 Route requests — if a healthcare customer asks about patient rights, data access, or amendments, route to the IT Manager immediately
4 Secure documents — keep any paper BAAs or healthcare contracts in locked storage

Things You Must NEVER Do

Absolute Prohibitions

  • NEVER read patient records out of curiosity
  • NEVER take photos of PHI or share it on social media
  • NEVER discuss specific patient information with coworkers, friends, or family
  • NEVER take PHI home or remove it from the facility (except during authorized transport)
  • NEVER throw paper PHI in regular trash or recycling — it must be cross-cut shredded
  • NEVER email PHI in plain text
  • NEVER ignore PHI you find — secure it and report it

Lesson 4: Breach Reporting — What to Do When Something Goes Wrong (10 min)

Learning Objectives

  • Recognize a potential breach
  • Know exactly what to do if you suspect a breach
  • Understand the notification timeline

What Is a Breach?

A breach is when PHI is accessed, used, or disclosed in a way that is not permitted. Examples:

  • A hard drive from a hospital is lost or stolen before it was destroyed
  • Paper patient records are found in the regular trash instead of secure shredding
  • Healthcare customer materials fall off the truck during transport
  • An employee reads patient records that were found in equipment
  • An unauthorized person accesses the secure staging area
  • Healthcare customer data is emailed to the wrong person

What to Do If You Suspect a Breach

Follow these steps immediately — do not wait:

Step 1: STOP the breach if you can
         → Secure the PHI, restrict access, recover materials

Step 2: REPORT to your supervisor — RIGHT NOW, verbally
         → Do not wait until the end of your shift
         → Do not assume someone else will report it

Step 3: DOCUMENT what you observed
         → What happened? When? What PHI might be involved?
         → Who was involved? What did you do?

Step 4: DO NOT try to investigate on your own
         → The HIPAA Security Officer (IT Manager) leads the investigation
         → Just report what you know

Time Is Critical

Scott Recycling must notify the healthcare customer within 5 business days of ANY employee becoming aware of the breach. That clock starts when you notice something wrong — not when management finds out. Report immediately.

What Happens After You Report

  1. Your supervisor escalates to the IT Manager (HIPAA Security Officer) within 1 hour
  2. The IT Manager investigates and determines if it is a reportable breach
  3. If it is a breach, management is notified and the healthcare customer is contacted within 5 business days
  4. Corrective actions are implemented to prevent it from happening again
  5. The incident is documented and retained for 6 years

You Will NOT Be Punished for Reporting

Scott Recycling will not discipline any employee for reporting a suspected breach in good faith. Even if you were involved in the incident, reporting it promptly will always be viewed more favorably than concealing it.

Remember

See something? Say something. Reporting a suspected breach — even if it turns out not to be one — is always the right call.


Lesson 5: Knowledge Check (5 min)

Answer these questions to confirm your understanding. Discuss any incorrect answers with your supervisor.

Question 1

A driver picks up 20 desktop computers from a medical clinic. Inside one of the towers, he finds a folder of papers with patient names, dates of birth, and insurance information. What should he do?

Answer

Do not read the papers. Secure them with the rest of the healthcare customer's materials on the truck. Report the loose PHI to his supervisor as soon as possible. At receiving, ensure the papers are routed to secure cross-cut shredding.

Question 2

A warehouse employee is sorting materials from a hospital pickup and notices that two hard drives from the shipment are missing compared to the receiving log. What should he do?

Answer

Report it to his supervisor immediately. This is a potential breach — two data-bearing devices from a healthcare customer are unaccounted for. The supervisor must escalate to the IT Manager (HIPAA Security Officer) within 1 hour. Do not wait to see if the drives "turn up."

Question 3

A CSR gets a phone call from someone claiming to be a patient at Java Medical Group. They want to know if their old computer was destroyed and ask for the serial number. What should the CSR do?

Answer

Do not provide any information to the caller. Patient requests for information about their PHI must go through the healthcare customer (Covered Entity), not directly through Scott Recycling. Politely explain that you cannot release that information and suggest they contact Java Medical Group directly. Route the inquiry to the IT Manager.

Question 4

A processing employee is wiping hard drives from a hospital and one drive fails the wipe verification. He figures it is probably fine and marks it as complete. Is this OK?

Answer

Absolutely not. A failed wipe means the data has not been destroyed. The employee must flag the drive as "wipe failed," escalate it to physical destruction, and update the tracking record. Marking it as complete when the wipe failed is a serious violation that could result in a breach.

Question 5

An employee accidentally drops a box of hard drives from a clinic in the parking lot. None of the drives appear damaged, and he picks them all up. Does he need to report this?

Answer

Yes. Even though the drives appear undamaged, they were briefly in an unsecured area. Report it to a supervisor, who can assess whether any drives are missing or if the incident needs to be escalated. It may not be a breach, but it must be documented.


Training Completion

After completing this course:

  1. Sign the training acknowledgment form confirming that you have read and understood this material
  2. Ask your supervisor if you have any questions about PHI handling in your specific role
  3. Review the reference card posted in the break room (summary of PHI dos and don'ts)

Training Record

Field Details
Employee Name ______
Date Completed ______
Trainer ______
Employee Signature ______

Training records are retained for a minimum of 6 years per HIPAA requirements.


Quick Reference Card

Print this and post it in work areas:

┌─────────────────────────────────────────────────┐
│          HIPAA QUICK REFERENCE — PHI             │
├─────────────────────────────────────────────────┤
│                                                  │
│  PHI = Patient names, DOB, SSN, medical record   │
│  numbers, diagnoses, insurance info, or anything │
│  that identifies a patient + their health data   │
│                                                  │
│  DO:                                             │
│  ✓ Treat all healthcare customer materials       │
│    as potentially containing PHI                 │
│  ✓ Secure PHI immediately — locked area only     │
│  ✓ Follow chain of custody for all devices       │
│  ✓ Cross-cut shred paper PHI                     │
│  ✓ Report suspected breaches IMMEDIATELY         │
│                                                  │
│  DON'T:                                          │
│  ✗ Read patient records                          │
│  ✗ Photograph PHI                                │
│  ✗ Discuss patient info with anyone              │
│  ✗ Email PHI in plain text                       │
│  ✗ Throw paper PHI in regular trash              │
│  ✗ Ignore missing devices from a healthcare      │
│    customer                                      │
│                                                  │
│  BREACH? → STOP → REPORT → DOCUMENT             │
│  Tell your supervisor RIGHT NOW                  │
│  5 business day notification deadline            │
│                                                  │
└─────────────────────────────────────────────────┘

What's Next?


Questions? Contact the IT Manager (HIPAA Security Officer) or your supervisor.