This policy establishes the sanctions that EMStool LLC ("the Organization") will apply to members of its workforce who fail to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), its implementing regulations (45 CFR Parts 160 and 164), and the Organization's HIPAA policies and procedures.
This policy applies to all workforce members of EMStool LLC, including but not limited to:
| Term | Definition |
|---|---|
| PHI | Protected Health Information — individually identifiable health information transmitted or maintained in any form or medium. |
| ePHI | Electronic Protected Health Information — PHI stored or transmitted in electronic form. |
| Workforce Member | Employees, volunteers, trainees, and other persons whose conduct is under the direct control of the Organization. |
| Security Incident | The attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI. |
| Sanctions | Disciplinary actions taken against workforce members who violate HIPAA policies. |
EMStool LLC is committed to protecting the privacy and security of all Protected Health Information. All workforce members are required to comply with HIPAA regulations and all related organizational policies. Violations will result in sanctions proportionate to the nature, severity, and circumstances of the violation.
Sanctions will be applied consistently regardless of the workforce member's position, tenure, or relationship to the Organization.
Violations are classified into three tiers based on severity, intent, and impact.
| Tier | Description | Examples | Sanctions |
|---|---|---|---|
| Tier 1 — Minor | First-time, unintentional violation with no evidence of bad intent and minimal or no patient harm. |
|
|
| Tier 2 — Moderate | Repeated or more serious violation, or a single violation with potential for patient harm or reputational damage. |
|
|
| Tier 3 — Severe | Intentional, malicious, or grossly negligent violation; violation resulting in confirmed patient harm; violation involving theft or sale of PHI. |
|
|
All workforce members have an obligation to report known or suspected HIPAA violations. Reports may be made to:
Retaliation against any workforce member who reports a HIPAA violation in good faith is strictly prohibited and will itself be treated as a Tier 2 or Tier 3 violation depending on severity.
A workforce member who believes a sanction was applied unfairly may submit a written appeal to the Security Officer within 10 business days of receiving the sanction notice. The appeal must:
The Security Officer will review the appeal and issue a written response within 15 business days. The Security Officer's decision is final.
All sanctions, investigations, training records, and related documentation will be:
This policy will be reviewed annually and updated as necessary to reflect changes in law, regulation, or organizational operations. The Security Officer is responsible for maintaining and distributing this policy.