Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
  • Certification
    back
    Certification
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • How to Get Certified
      • Eligibility Criteria
      • Exam Fees & Options
      • SHRM-CP
      • SHRM-SCP
      • Which Certification is Best for Me?
      • Recertification
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      PMQ

      Gain a deeper understanding and develop critical skills.

  • Events & Education
    back
    Events & Education
    • India Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • SHRM Unconference
      • Tech Conference
      • India Annual Conference
      MENA Events
      • MENA Annual Conference
      Global Events
      • US Annual Conference
      Webinars
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Compliance
      • HR Research
      • Legal & Compliance
      • Latest News & Trends
      • Tools & Guides
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Compensation & Benefits
      • Inclusion & Diversity
      • Talent Acquisition
      • Workplace Technology
      • Workplace Violence Prevention
  • SHRM Connect
  • Shop
    back
    Shop
    • SHRM Store

      Shop for HR certifications, credentials, learning, events, merchandise and more.

      Workplace Essentials
      • SHRM Memberships
      • SHRM Certification
      • Specialty Credentials
      • HR Tools & Tech
      Education
      • Seminars
      • eLearning
      • Books
      Merchandise
      • Accessories
      • Apparel
      • Office & Home
Become a Member
Renew
Rejoin Now
Renew
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Workplace News & Trends
  3. Protecting PHI Should Be Priority for HR
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Protecting PHI Should Be Priority for HR

March 13, 2015 | Deena Coffman



Ensuring the privacy of protected health information (PHI) isn’t a top priority for many HR departments. They have so many other pressing concerns—such as attracting and retaining talent, managing disciplinary issues, and controlling costs—that maintaining security around employees’ PHI often plays second fiddle. But the latest round of changes to the Health Insurance Portability and Accountability Act (HIPAA) and the related Health Information Technology for Economic and Clinical Health (HITECH) Act should make HR departments sit up and take notice.

The HIPAA final rule, released in 2013, primarily focuses on organizations within the health care sector, such as providers and those who process data for them. But sponsors of health and wellness plans may also fall under HIPAA guidance, and HR departments need to ensure they’re in compliance with the privacy, security and breach notification requirements. Following the “minimum necessary” advice and other guidelines contained in the final rule is just the beginning when developing a strong data privacy program.

Know Where Security Gaps Lurk

Assessing your organization’s risks is the first step in developing a stronger security posture. A HIPAA risk assessment, conducted by an experienced information security professional, provides a window into any potential security weaknesses within the HR department as well as the company as a whole. It will uncover areas where technology tools may be lacking and where potential risks might exist because of outdated or ineffective policies and procedures. A risk assessment will also reveal if security measures used by partner organizations—third-party benefits administrators, payroll processors, etc.—may be putting your group’s data at risk.

“One gap that such assessments routinely find relates to termination of employees,” said Dan Berger, CEO of Redspin, a provider of penetration testing services and IT security audits. “Whether the end of employment is voluntary or involuntary, policies must be in place to cover the removal of the former employee’s access to all IT systems within hours of termination. Even if adequate policies exist, it is critical to show that they work in practice. There must be documented procedures in place and, most importantly, regular audits to show that the process is being followed.”

An assessment also provides an opportunity to discover where risk factors exist outside the typical IT-related activities. Physical security of data storage areas, from file cabinets to mobile devices, may be ineffective. Confidential discussions that involve PHI may be held where they can easily be overheard. These all represent gaps where data exposures can occur, either inadvertently (such as through the loss of a smartphone that wasn’t protected with a strong password) or through deliberate action (hackers and other malicious threats).

Shore Up Your Defenses

Addressing the liabilities and potential dangers identified in the risk assessment is the next step in developing effective PHI safeguards. Technology solutions, such as network security appliances and data encryption, will play a large role in complying with HIPAA’s mandates. Improving users’ security practices should also be a priority, since something as simple as sharing passwords can create an enormous security gap.

A written information security plan (WISP) will bring all these components together into a workable and effective strategy. This is where the organization lists the practices and protocols it plans to leverage to maintain privacy around PHI. Policies covering employee training should be included in the WISP, as should the details of any anticipated changes to the existing technology infrastructure that might impact data privacy efforts.

Next comes the incident response plan (IRP), which is exactly what its name implies—a document that walks the organization through what’s required and expected of the various teams if PHI is exposed. Within the IRP will be outlined those groups and individuals who will take action in the event of a breach, and what their specific role will entail. A comprehensive IRP will also include any outside resources that will be needed in the event of a breach, such as forensic investigation services or public relations expertise to augment the internal teams.

An All-Inclusive Approach to Protection

Nurturing a culture that makes data privacy a priority requires an all-hands-on-deck strategy. Not only must the organization’s top leadership be ready to lend their full support to the endeavor, but several internal groups will also play pivotal roles in developing and maintaining a strong security posture.

The IT department will be instrumental in achieving compliance, as will legal counsel. But forming the framework of any privacy effort will be the information security team. Their expertise is crucial in bringing together the various regulatory mandates, technology tools and internal practices that will form an effective privacy program.

Through these coordinated efforts, HR groups will be in a position to fulfill their HIPAA and HITECH Act responsibilities and maintain the privacy of the PHI within their organization.

Deena Coffman is CEO of IDT911 Consulting, a consultative provider of identity and data risk management, resolution and education services.

HR Technology
Total Rewards

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • SHRM India Advisory Council
  • Careers at SHRM
  • Press Room
  • Contact SHRM India
  • Book a SHRM Executive Speaker
  • Ask an Advisor
  • SHRM Newsletter
  • Post a Job
  • Find an HR Job
  • Advertise with us
  • Copyright & Permission
Contact Us


Email: shrmindia@shrm.org
Phone: (1)800.103.2198
WhatsApp: +919810503727

SHRM India Corporate Information

© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now