Privacy: More Than Just HIPAA

August 18, 2026

Privacy is about much more than HIPAA. While HIPAA is an important law that protects health information, it is only one part of our responsibility to safeguard confidential information. Every employee plays a role in protecting the privacy of the people we serve, our coworkers, and our organization. Maintaining privacy helps build trust, reduces the risk of harm, and supports our ethical and legal responsibilities.

HIPAA protects an individual’s Protected Health Information (PHI). This includes medical records, diagnoses, treatment plans, medications, insurance information, and other details that can identify a person’s health condition. HIPAA requires healthcare providers, health plans, and their business associates to use, disclose, and protect PHI appropriately. Employees should always follow the minimum necessary standard by accessing or sharing only the information needed to perform their job duties.

However, not all confidential information is protected by HIPAA. In our daily work, we may handle employee personnel files, payroll information, Social Security numbers, financial records, donor information, adoption records, passwords, contracts, strategic business plans, and proprietary organizational data. These types of information may be protected by other federal or state laws, contractual agreements, or organizational policies. Even when HIPAA does not apply, employees still have a responsibility to protect this information from unauthorized access or disclosure.

Protecting privacy requires good habits every day. Hold conversations involving confidential information in private areas whenever possible. Keep paper records secured when they are not being used. Lock your computer when stepping away from your workstation, and position screens so unauthorized individuals cannot view sensitive information. Share confidential information only through approved communication methods and with individuals who have a legitimate business need to know. Avoid discussing confidential information in elevators, hallways, cafeterias, or other public areas where conversations may be overheard.

Technology also creates new privacy risks. Text messaging, personal email accounts, social media, and artificial intelligence tools should never be used to share confidential information unless specifically approved by your organization and consistent with applicable policies. Always think before clicking “send.”

Protecting privacy is more than following regulations. It demonstrates respect for every individual, strengthens trust in our organization, and helps prevent costly privacy breaches. When you are unsure whether information can be shared, pause and ask your supervisor or Privacy Officer before taking action. When it comes to privacy, asking first is always the safest choice.

By Tracy Malloy, Compliance Specialist | AQORD Compliance Collaborative