Module 05 · Free · 5:23
Real-World Breach Scenarios & Best Practices
Six real-world scenarios — lost unencrypted laptop, public discussion of patient info, misdirected email, improper record disposal, unauthorized employee access, unlocked workstation — and the specific workforce practices that prevent each one.
Most HIPAA violations happen in ordinary workflow moments that any workforce member would recognize. This module walks through six real-world scenarios — the specific ways breaches happen in daily practice — and the concrete workforce practices that prevent each one.
Regulatory anchors
- 45 CFR §164.312(a)(2)(iv)
- 45 CFR §164.310(d)(2)
- 45 CFR §164.502
- 45 CFR §164.530(c)
Hosted on the Patient Protect YouTube channel
6 HIPAA Violations That Happen in Every Healthcare Practice
Learning objectives
What the workforce should be able to do after this module.
- Identify real-world situations that may result in HIPAA violations
- Understand how breaches occur in everyday practice settings
- Learn how to prevent common HIPAA violations
- Apply best practices to maintain compliance and protect patient information
Assessment: 5 knowledge-check questions per module, 80% passing standard.
Module outline
Section-by-section walkthrough.
01
Scenario 1 — Lost unencrypted laptop
A staff member takes a work laptop home containing patient records. The laptop is not encrypted and is later stolen from their car. The device contained unsecured ePHI. Prevention: always use encrypted devices and avoid storing patient information on unsecured hardware.
02
Scenario 2 — Discussing patient information in public
Two staff members discuss a patient's diagnosis in a hallway where others can hear. Patient information was disclosed to unauthorized individuals, violating the Privacy Rule. Prevention: always have conversations about patient care in private, secure environments.
03
Scenario 3 — Email sent to the wrong patient
A staff member accidentally sends patient records to the wrong email address. PHI was disclosed to someone who was not authorized to receive it. Prevention: always verify recipient information before sending any patient-related communication.
04
Scenario 4 — Improper disposal of records
Paper records containing patient information are thrown in a regular trash bin instead of being securely destroyed. PHI was not properly disposed of according to HHS standards, making it unsecured and vulnerable to unauthorized access. Prevention: shredding or approved destruction methods.
05
Scenario 5 — Unauthorized access by an employee
An employee accesses the medical records of a friend or family member without a work-related reason. Accessing patient information without a legitimate job-related purpose violates HIPAA — even if the information is never shared. Prevention: only access patient information when it is necessary to perform your job duties. Patient Protect tracks and logs all access to patient records.
06
Scenario 6 — Unlocked workstation
A staff member leaves their computer unlocked at the front desk, allowing others to view patient information on the screen. Unauthorized individuals were able to view PHI due to a lack of basic security measures. Prevention: always log out or lock your workstation when stepping away, even briefly.
Sample knowledge check
A representative question from this module.
Sample question · 5 per module in the live series
A staff member takes their work laptop home to catch up on charting. The laptop contains patient records but is not encrypted. Overnight, the laptop is stolen from their car. Which statement about this situation under HIPAA is true?
- A.It is not a breach because the theft was not the practice's fault.
- B.It is not a breach unless the practice can confirm the thief actually opened the records.
- C.It is a breach because the device contained unsecured (unencrypted) ePHI that could be accessed by an unauthorized individual.
- D.It is only a breach if the laptop is not recovered within 60 days.
Show explanation
Correct answer: C. Unsecured PHI is patient information that has not been encrypted (or properly disposed of). An unencrypted laptop with patient records that is stolen exposes unsecured ePHI to an unauthorized individual — which triggers breach analysis and notification obligations under the Breach Notification Rule.
Module 05 of the HIPAA Foundations series
Every learner. Every module. One office price.
When you are ready to train the whole practice, the complete 19-module HIPAA Foundations series unlocks for up to 25 personnel at $39/office/month — with per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
