How personal health information can impact your business

Vimeo Staff
A high-level view of HIPAA and how Vimeo can help you mitigate noncompliance.

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that requires privacy and security safeguards for protected health information (PHI). It ensures that individuals' health information is adequately protected while providing and promoting high-quality health care. The US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces the law.


Why focusing on HIPPA matters

HIPAA violations are not just a legal issue — they can have significant financial and reputational repercussions. According to the HHS and The HIPAA Journal, a staggering $124 million in financial penalties have been imposed in the past decade, with an average of over $300,000 per entity in 2023 alone. As of mid-2024, nearly $5 million in penalties have been imposed as the OCR continues to work through its investigations backlog. These numbers underscore the importance of maintaining HIPAA compliance to safeguard your organization's reputation and financial standing.

Find out if you're a covered entity

If you’re unsure if your organization is a covered entity or business associate impacted by these regulations, the US Government has created a Covered Entity Decision Tool to help you find out.


Ignorance isn't an excuse for noncompliance

It's crucial to understand that each entity (including hospitals, insurance companies, healthcare clearinghouses, and business associates who might come into contact with PHI) is responsible for being aware of and adhering to HIPAA regulations.

Not all fines are due to poor handling of PHI. Many past violations resulted from inadequate training or failure to conduct a proper risk assessment. Instances like these underscore the urgency for covered entities to take a proactive approach in their compliance efforts rather than waiting for a violation to occur as the OCR conducts periodic audits of HIPAA-covered entities and their business affiliates.

Most violations are reported directly as complaints to the OCR, often by responsible employees (note that entities can not retaliate against who filed the complaint) or self-reporting after an internal audit. When it comes to these complaints, the most common issues, according to the US Dept. of Health and Human Services, include:

  • Impermissible use and disclosure of PHI
  • Lack of safeguards
  • Lack of patient access to their Personal Health Information
  • Disclosing or using more protected health information than necessary

In cases like this, the OCR will review the information to determine if the covered entity violated the HIPAA Privacy or Security Rule. If the covered entity is not compliant, the OCR will attempt to resolve the issue through voluntary compliance, corrective action, and/or a resolution agreement.


Data breaches are on the rise

Proactively safeguarding Protected Health Information has become even more critical as data breaches have become more common. In fact, 725 data breaches, exposing more than 133 million records, were reported to the OCR in 2023 — nearly 80% due to hacking incidents.

Protecting customers' data is critical to maintaining a good relationship with them as well as building brand affinity. It takes time to forge trust, but a single leak can undermine that trust in a second.


All the benefits of video, with less risk

From interactive training to live and on-demand communication to education, video is a powerful tool for healthcare professionals trying to serve patients and communities. However, being in a HIPAA-regulated industry adds a layer of complexity to video management and third-party tooling. 

As part of our commitment to helping these organizations, Vimeo completed the US Department of Health and Human Services (HHS) security risk analysis, validating Vimeo's compliance with HIPAA's administrative, physical, and technical safeguards as outlined in the HIPAA Security Rule. Additionally, we follow industry-wide best practices for security and compliance and have SOC 2 and ISO 27001 certifications.

Want to learn more about Vimeo's HIPAA-compliant video solutions for healthcare companies? Check out the additional resources below or request a demo.

Vimeo for Healthcare →

What healthcare providers need to know about video and HIPAA →

HIPAA Information Hub →

Filed under:

Photo of Vimeo Staff

Vimeo Staff

More from the Vimeo blog

Two people speaking to each other overlaid by a screen that says stream health showing a good quality video stream in progress

How AI streaming tools are reshaping streaming services

2K, 4K, HD, and SD video resolutions of the same video still of a hummingbird

Unlisted vs. private videos: What you need to know when uploading your content

How Vimeo is approaching AI, plus a call for feedback from our community.

A note on AI from our new CEO

Hear from the curators behind Staff Picks, and a handful of the filmmakers who have been given one, about three significant innovations within the film industry.

15 years of Vimeo Staff Picks: Tracing its innovative history and future

In this week’s Staff Pick Premiere, forgotten folk singer Lena Black discovers her fifty-year-old song “Charlotte” has been remade into a hit pop song.

Staff Pick Premiere: "Charlotte" by Zach Dorn

Live streaming music concerts can help you reach more fans. Learn what equipment you need to get started and tips to promote your next gig.

What you need to know about live streaming music concerts

Here are 7 creative ways to make more money with fitness. Scale your fitness business with online videos, social media, and more.

7 ways to make money in the fitness industry

An expertly crafted stop motion animation in which a clay figure questions the role he was created to play.

Staff Pick Premiere: "Framed" by Marco Jemolo