CIVIC ACADEMY · PLAIN LANGUAGE
HIPAA 101 — and what an accusation requires
≈ 14 min read · or listen, or skim the bold lines
C · Secondary explanation Federal regulations below are quoted from the eCFR and HHS guidance. This is education, not legal advice. If a decision matters — your job, a complaint, a deadline — talk to an attorney or advocate. How we verify →
HIPAA protects your medical records. Most people learn about it as a rule that gets employees fired. Fewer people know that when a hospital says a breach happened, the law creates duties for the hospital too.
First, the words — in plain terms
You do not need any of these to read this page. They are here so nothing below is a mystery.
| The word they use | What it means |
|---|---|
| HIPAA | The federal law that keeps your medical information private. |
| Covered entity | A hospital, clinic, or health plan that has to follow HIPAA. A 638 hospital is one. So is an IHS hospital. |
| PHI | Your medical information. Your chart, your diagnosis, your visits. |
| Unsecured | Not locked up. Not scrambled by a computer, not shredded. Most records are unsecured. |
| Breach | Somebody saw or shared your medical information who was not supposed to. |
| Risk assessment | A written check the hospital does to decide how bad it was. |
| Presumed | The law assumes it counts — unless the hospital shows otherwise. |
| Burden of proof | Whose job it is to prove it. Here, it is the hospital’s job. Not yours. |
| Willful neglect | They knew better and did not care. |
| Adverse action | Something bad done to you at work — fired, demoted, suspended, disciplined. |
| Just cause | A real reason they can actually prove. |
| OCR | The federal office that handles medical privacy complaints. Office for Civil Rights. Not the Navajo Nation. |
The whole page, in six sentences
- Your medical records are protected by a federal law. The Navajo Nation does not enforce it.
- A 638 hospital has to follow it, the same as any hospital.
- If someone looks at records to hurt a person, that can be a federal crime — up to ten years.
- When records are looked at wrongly, the law assumes it counts as a breach. The hospital has to show otherwise, in writing.
- So if a hospital says a breach was bad enough to fire someone, it had to either tell the patients and the government, or write down why it didn’t have to.
- One of those papers exists. Or somebody skipped a step.
What HIPAA is
Three things to know first
1. It is federal law. The Navajo Nation does not enforce it. The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) does.
2. A 638 facility is a covered entity — just like an IHS hospital, a clinic, or any hospital anywhere. Both are bound by HIPAA in full.
3. Employees can be prosecuted personally. Not just fined by their employer. Under 42 U.S.C. § 1320d-6, knowingly obtaining or disclosing someone’s health information without authorization is a federal crime.
When it is a crime
The Department of Justice prosecutes criminal HIPAA violations. The statute has three tiers, and the difference between them is why the person did it.
| Tier | What happened | Maximum |
|---|---|---|
| § 1320d-6(b)(1) | Knowingly obtaining or disclosing records without authorization | $50,000 · 1 year |
| § 1320d-6(b)(2) | Under false pretenses | $100,000 · 5 years |
| § 1320d-6(b)(3) | With intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm | $250,000 · 10 years |
“Malicious harm” is the statute’s own phrase
Congress wrote it into the top tier. Looking up someone’s records to hurt them — to embarrass them, to use against them, to retaliate — is the most serious form of this crime.
Courts have also read “personal gain” broadly. It does not require selling anything. Satisfying curiosity or workplace gossip has been held sufficient.
“Knowingly” means knowing the facts — not knowing that a law was broken. Not realizing it was illegal is no defense.
What counts as a “breach”
This is where most people, including many employees, have never been told the rules.
45 CFR § 164.402 — the presumption
If someone sees, takes, uses, or shares medical records when they were not supposed to — and those records were not locked up — the law assumes a breach happened.
The hospital can show otherwise. But only by writing down why the information probably was not really exposed, looking at four things:
- The nature and extent of the information involved
- Who the unauthorized person was
- Whether the information was actually acquired or viewed
- The extent to which the risk has been mitigated
And the law puts the job of proving it on the hospital (45 CFR § 164.414(b)) — either it told people, or it can show it did not have to. It is not the employee’s job to prove anything.
Three narrow exceptions
Some things are not a breach, even though records were seen:
- An honest mistake, on the job. A worker accidentally opens the wrong chart, and does not use it or tell anyone.
- Two people who were both allowed to see it. One shows the other by accident, at the same hospital, and it goes no further.
- The person could not have kept it. A good-faith belief that whoever saw it could not have held onto the information.
If a breach occurred, the employer has duties too
45 CFR §§ 164.400–414 — the Breach Notification Rule
When a breach of unsecured health information happens, the covered entity must:
- Notify the affected individuals — without unreasonable delay, and no later than 60 days after discovery.
- Notify HHS. If 500 or more people are affected, at the same time as the individuals — and it is posted on OCR’s public breach portal. If fewer than 500, in the annual report.
- Notify prominent media in the affected area, if 500 or more people are involved.
- Keep documentation — either of the notifications made, or of the risk assessment showing why notification was not required.
The hospital has to be able to show this. On paper.
So here is the question worth knowing
If an employer says a breach was serious enough to end someone’s employment, the law obliges that employer to have done something about the breach itself.
Either it notified the patients and HHS — or it documented a risk assessment explaining why it did not have to.
One of those records exists. Or a duty was missed.
And what protects the employee
Navajo Preference in Employment Act
On the Navajo Nation, an employer cannot fire, demote, or discipline you without a real reason they can prove. That is what “adverse action without just cause” means. It is a stronger protection than most states have. The NPEA also forbids prejudice, intimidation, and harassment.
An accusation is not a finding. Whether an accusation that cannot be substantiated is just cause is exactly the question the Office of Navajo Labor Relations and the Navajo Nation Labor Commission exist to decide.
The Labor Commission does not publish its decisions, so nobody can look up how “just cause” has been applied before.
⏰ If it happens more than once, the clock matters
Sometimes an adverse action is taken, contested, and then taken again on different grounds. Each event may start or reset a deadline — and each may need to be raised.
- One year from the event — or from the last event in a series — to file a charge with ONLR.
- The charge must raise every issue. A claim not raised within that year may not be asserted at all afterward. It can be amended — only inside the year.
- 360 days to reach the Labor Commission — counted from the day the ONLR charge was filed, not from any letter you receive.
If a second adverse action happens after you file, ask an attorney immediately whether it must be added to your existing charge, and by when.
Quick check
Check your understanding — private, no grades
Who enforces HIPAA at a 638 hospital on the Navajo Nation?
Right — HIPAA is federal. A 638 facility is a covered entity, and the Navajo Nation does not enforce HIPAA.
Looking up a co-worker’s medical record in order to hurt them could be…
Yes — 42 U.S.C. § 1320d-6(b)(3). “Malicious harm” is the statute’s own phrase, and it sits in the top tier: $250,000 and up to ten years.
“Knowingly” in the criminal HIPAA statute means the person knew…
Correct. Not realizing it was illegal is not a defense.
When unsecured health information is improperly accessed, the law…
Yes — 45 CFR § 164.402. It is presumed to be a breach unless the covered entity demonstrates a low probability of compromise using a four-factor risk assessment.
Who carries the burden of proving something was not a breach?
Right — 45 CFR § 164.414(b). The covered entity must show that notifications were made, or that what happened was not a breach.
A hospital says a breach happened. What must exist, in writing?
Yes. One of those records exists, or a duty was missed. This is a question to ask — not an accusation to make.
Under the NPEA, an employer on the Navajo Nation may take adverse action against an employee…
Correct — the rule eliminates at-will employment. An accusation is not a finding.
Must OCR investigate every HIPAA complaint it receives?
Right — 45 CFR § 160.306(c). And under § 160.312(b), if OCR decides no further action is warranted, it will tell the complainant in writing.
The 360-day deadline to reach the Navajo Nation Labor Commission is counted from…
Yes — and this surprises almost everyone. A person waiting for a letter can lose the case while waiting. All the deadlines →
Apply it — four situations
1. A nurse opens the wrong chart by accident, closes it, and tells no one else.
Probably not a breach. The first exception in 45 CFR § 164.402 covers unintentional access by a workforce member, in good faith and within the scope of authority, with no further use or disclosure.
The lens: the exception turns on good faith and no further use — not on whether the record was seen.
2. An employee looks up a relative’s record out of curiosity. Nothing is shared.
This is deliberate access outside the scope of authority. The good-faith exception does not apply. It is presumed to be a breach unless the entity documents a low probability of compromise.
And under 42 U.S.C. § 1320d-6, courts have read “personal gain” broadly enough to include satisfying curiosity. Nothing has to be sold.
The lens: “I didn’t share it” is not the same as “nothing happened.”
3. A worker is fired for a HIPAA breach. Nobody was ever notified, and no risk assessment was written.
The question is not whether the worker is guilty. The question is what the employer did.
If a breach of unsecured information occurred, 45 CFR §§ 164.400–414 obliged the entity to notify affected individuals and HHS — or to document a risk assessment explaining why notification was not required. The burden is on the entity (§ 164.414(b)).
What to ask, in writing: “Was this treated as a reportable breach? If so, when were individuals and HHS notified? If not, where is the risk assessment?”
The lens — prevention vs. damage control: a facility that fires an employee but does not address the breach has responded to the person, not the harm.
4. An employee contests a termination. Months later, they are terminated again on different grounds.
Each adverse action may be a separate event. Under the NPEA process, the ONLR charge must raise every issue — a claim not raised within the one-year window may not be asserted at all afterward. A charge can be amended, but only inside that year.
Meanwhile the 360-day clock to reach the Labor Commission runs from the day the original charge was filed — not from any later event, and not from any letter.
What to do: ask an attorney or advocate immediately whether the new action must be added to the existing charge, and by when.
The lens — who benefits from delay? A fair system freezes the harm until the case is heard.
Carry these questions
- Was this treated as a reportable breach? Where is the notification, or the risk assessment?
- Who did the facility say was harmed, and were they told?
- Is the accusation a finding, or an allegation?
- What is my deadline, and which section says so?
Where a HIPAA complaint goes
- HHS Office for Civil Rights — hhs.gov/ocr. Complaints must be in writing and name the person or entity. Generally within 180 days of when you knew; OCR may extend for good cause. Not HHS-OIG. Not the Navajo Nation.
- OCR must investigate when a preliminary review indicates a possible violation due to willful neglect (45 CFR § 160.306(c)(1)). Otherwise it may investigate.
- You are entitled to be told the outcome. If OCR decides no further action is warranted, it will inform the complainant in writing (45 CFR § 160.312(b)).
- OCR refers cases with criminal indicators to the Department of Justice.
Questions worth asking
- Do employees at our 638 facilities know that HIPAA is enforced by the federal government, and that the Navajo Nation cannot investigate it?
- When a facility says a breach occurred, where is the risk assessment, and where is the notification?
- Should the Navajo Nation have any authority here — and if not, who explains that to the people who work in these hospitals?
- Should the Labor Commission publish its decisions, so “just cause” can be read?
- Should the Nation pass a whistleblower act?
This is education, not legal advice
Protections and deadlines depend on facts this page cannot know. Before you report anything, or respond to an accusation, talk to an attorney or advocate. DNA-People’s Legal Services and the Navajo Nation Bar Association are listed in Resources.
Related: Who watches the money in health care? · Whistleblowing 101 · NPEA 101 · The Right Door · The Seams