
The U.S. 2013 Health Information Portability and Accountability Act (HIPAA) Omnibus Rule, which took effect in September 2013, ushers in enormous new liability that law firms with healthcare, medical malpractice, insurance and litigation practices areas will want to understand so as to avoid fines, prevent harm to your brand and protect client cases from breaches. Firms are now directly liable for parts of the Privacy Rule, the Security Rule and the updated breach notice requirements. This is a wake-up call to address the new regulatory requirements as business associates of health care organizations known as covered entities under HIPAA. In short, firms need to assess their risk management of protected health information (PHI), and build policies and procedures to safeguard uses of and access to that information.
The regulatory compliance processes that HIPAA pushes law firms to adopt are part of a larger law firm information governance framework built to manage and protect firm and client information. That's why we founded the Iron Mountain Law Firm Information Governance Symposium, a think tank where we convene law firms and experts to draft and publish emerging standards, definitions and best practices for governing information in the unique setting of law firms. The latest series of Symposium publications features a HIPPA Omnibus Task Force Report, authored by law firms and experts, which analyzes Omnibus Rule impacts to firms including non-compliant penalties up to $1.5 million and gives a roadmap on what law firms should do to comply.
As your firm charts its course for HIPAA compliance, here are few key ideas to keep in mind:
1. The Privacy Rule's new minimum necessary standard has one of the biggest impacts for firms. In a nutshell, the rule says law firms need to button down access to PHI, granting access to this private information only to those lawyers and employees who need the information to do their job. The good news is, most firms aren't starting from scratch, and therefore can leverage your existing ethical wall/conflicts and other sensitive information access policies and controls they already have in place. However, you will need to identify PHI in the firm and make sure there are guardrails up to meet this new HIPAA Omnibus standard.
2. The Security Rule requires safeguards to protect electronic PHI (ePHI). HHS guidance for this rule includes details on how to assess your risks, even for items such as digital copiers and file sharing applications. Firms that handle PHI are going to want to do some kind of security risk assessment and train your people on PHI security policies and procedures. Law firms can take a look at the Symposium Task Force Report to determine what you need to do to comply. You'll also want to be sure your service providers operate in accordance with these HIPAA requirements, especially if you store in the cloud or you or your clients use providers for scanning medical records.
3. Breach Notification. Law firms are directly liable for reporting breaches of unsecured protected health information to their covered entity, which in turn must report the breach to HHS, the affected individual, and in some instances, even the media. Needless to say, firms want to avoid the breach notification scenario. The potential for harm to the firm's brand, client cases and pocketbook is as big as a hippo. The Omnibus Rule includes a new presumption that an impermissible use or disclosure is a breach, unless the firm can prove otherwise. Another point to keep in mind is that HIPAA only requires notification of breaches of unsecured PHI meaning PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons. To meet this standard, HHS guidelines specify things like encrypting PHI, and clearing, purging or destroying electronic media in accordance with NIST standards. For paper and film, HHS looks at whether the media was shredded so that the PHI is unreadable and cannot be reconstructed. Firms will want to ensure that their own and their vendor methodologies meet these standards.
Don't let the HIPAA hippo overwhelm your firm - take advantage of the roadmap for compliance in the Symposium HIPAA Task Force Report today.
Founded by Iron Mountain, the Law Firm Information Governance Symposium is a community of industry thought leaders that provides common approaches and best practices for building law firm information governance enabling law firms and their clients to leverage common elements for governing and managing client information.
Most recent headlines
09/11/2025
Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...
13/10/2025
Spectrum Brings Selected L.A. Lakers Games to Apple Vision Pro With New Immersiv...
13/10/2025
Media Climate Accord aims to offer united approach to M&E industry sustainabilit...
13/10/2025
Riot Games streamlines production of Valorant Champions Paris with ST 2110 flypa...
13/10/2025
Feeling the NRG: Riot Games puts on a show for Valorant Champions Paris final By Jo Ruddock
Monday, October 13, 2025 - 09:17
Print This Story
After more t...
13/10/2025
FOX Sports MLB Postseason Audio Aims To Make Officials' Calls More AccurateA1 Joe Carpenter hopes to bring some baseball CSI' to the ABS ump-cam system...
13/10/2025
New SBS and NITV Original RECKLESS a Deadly Funny Thriller Straight Out of Fre...
13/10/2025
Regional sports network moves from satellite to IP to cut distribution costs by more than half and streamline broadcast and direct-to-consumer delivery
Mid-Atl...
13/10/2025
Delta Live, the award-winning audio supplier, has underlined its position at the forefront of live sound with significant investments in cutting edge audio syst...
13/10/2025
Abu Dhabi, UAE October 13, 2025: Space42 (ADX: SPACE42), the UAE-based AI-powe...
13/10/2025
Nick Blood and Saffron Hocking lead casting for Hit Point, brand new original drama series for U and U&Dave
Developed & Produced by Urban Myth Films (a STUDIOC...
13/10/2025
The series from A24 will land in the UK & Ireland in 2026Monday 13 October 2025
...
13/10/2025
Back to All News
Grand Galaxy Hotel' Open for Business: Netflix Confirms Production and Cast
Entertainment
13 October 2025
GlobalSouth Korea
Link copi...
13/10/2025
Back to All News
Netflix Partners with GOBELINS Paris and Guillermo del Toro to...
13/10/2025
Back to All News
Stories Set to Thrill, Move, and Entertain: Netflix Announces ...
13/10/2025
Fox Corporation Executives to Discuss First Quarter Fiscal 2026 Financial Result...
13/10/2025
At the OCP Global Summit, NVIDIA is offering a glimpse into the future of gigawa...
13/10/2025
Season 2 brings murder and West of Ireland humour - and rain - to our screens, with M ir ad Tyers joining the cast
Watch trailer here.
A small-town obituary w...
13/10/2025
The Katie Hannon Interview Live airs tonight & Wednesday night at 7pm
As part of RT 's comprehensive election campaign coverage, journalist Katie Hannon w...
11/10/2025
SVG New Sponsor Spotlight: TAB M Solutions' Joe Wire, Kevin Tucker on Guidin...
11/10/2025
By Jessica Herndon
One of the most exciting things about the Sundance Film Fest...
11/10/2025
STAMFORD, Conn. In a move that highlights the growing importance of streaming apps on pay TV platforms, Charter Communications' Spectrum operating brand has...
11/10/2025
Netflix is expanding its video game offerings from mobile into TV by launching party games that its subscribers can play on smart TVs....
11/10/2025
STAMFORD, Conn. Charter Communications' Spectrum News has reached an deal with Comcast to expand distribution of its local news channels to Xfinity TV cust...
11/10/2025
Professional podcasts are booming. They're an effective way to establish company executives as industry leaders, humanize a large organization, drill down o...
11/10/2025
PlayBox Neo, a leading provider of media playout and channel branding solutions, will present its PlayBox Neo Suite media platform for the first time in the U.S...
11/10/2025
As a testament to its commitment to the broadcast market, FOR-A America will bring several popular and future-facing technologies to the NAB Show New York, runn...
11/10/2025
European technology developer Profuz Digital reflects on another successful IBC Show in Amsterdam from 12 15 September after showcasing the latest version of ...
11/10/2025
Cobalt Digital, the leading designer and manufacturer of award-winning signal processing products, and a founding partner in the openGear initiative, is headin...
11/10/2025
Lightware, an industry leader in signal management, is at the center of a growing range of high-profile integrations with its UBEX platform. Built to deliver un...
11/10/2025
FOR-A Latin America and the Caribbean (LAC) will bring its industry-leading signal processing, frame rate conversion and graphics playout software to CAPER 2025...
11/10/2025
Clear-Com is happy to announce its latest collaboration with BNE Productions, a premier production company known for delivering world-class audio for live even...
11/10/2025
Dean's List: Tommy Neblett Shares His YouTube Top Five Boston Conservatory's dean of dance reveals his favorite student dance videos.
By
Sarah Godcher...
10/10/2025
SVG New Sponsor Spotlight: TAB M Solutions' Joe Wire, Jeff Tucker on Guiding...
10/10/2025
SVG Students To Watch: Vincent Macri, Monmouth University The Jersey local runs Camera 1 on Hawks games and is expanding into technical directing By Brandon Co...
10/10/2025
Flexible budgets: Inside the DFL's new customisable camera concepts for Bund...
10/10/2025
Facing the future: TVN on its technical services for the new Bundesliga season with remote production and all the bells and whistles By Heather McLean
Monday...
10/10/2025
Evolving in-house: Developing broadcast expertise and pushing the women's ga...
10/10/2025
Growing the game: The Deutscher Fu ball-Bund on pushing production innovation fo...
10/10/2025
Proximity and authenticity: DFL kicks off the new football season with more broa...
10/10/2025
Spectrum Brings Select L.A. Lakers Games to Apple Vision Pro With New Immersive ...
10/10/2025
From left, Scoot McNairy, Andrew Durham, Nessa Dougherty, and Emilia Jones attend the premiere of Fairyland at the 2023 Sundance Film Festival. Photo by Jemal...
10/10/2025
By Chuck Parker, CEO of Sohonet
If you work in film and television, you can feel it: anxiety is high. Budgets are tight, schedules are tighter, and AI is a c...
10/10/2025
L3Harris' WESCAM MX-Series EO/IR sensor systems have a long history of supporting complex missions in harsh environments, as seen here on a Kaplan-20 Next G...
10/10/2025
Cobalt Digital Booth # 607 // Journalists: Click to visit Cobalt
NAB NY 2025 Audio monitors join Cobalt's platform, including its latest routers, multiview...
10/10/2025
NEW YORK - October 9, 2025 - Nielsen, the global leader in audience measurement, data and analytics, today announced the release of The Marketing ROI Blueprint:...
10/10/2025
CHAMPAIGN, Ill. Cobalt Digital will feature its Aria series of audio solutions designed to simplify monitoring, embedding and routing at NAB Show New York, set ...
10/10/2025
LOS ANGELES and PONTE VEDRA BEACH, Florida Amazon's Prime Video has announced a new deal that will allow it to exclusively stream a revival of the PGA Tour&...
10/10/2025
ATLANTA Local Now, Allen Media Group's free streaming service, will add five channels from Fox to its growing lineup. The new offerings are Fox Sports, Fox ...
10/10/2025
WASHINGTON The National Association of Broadcasters is applauding a draft notice from the Federal Communications Commission that would potentially speed up the ...