What return does an employer get on its investment in complying with the HIPAA rules?
The costs of ignoring the rules could be high, given the significant sanctions and other legal risks associated with improperly released medical information. At the same time, employers may be able to take steps to reduce the costs of compliance. Some policy analysts are optimistic that the rules will ultimately lower (or slow increases in) health plan administrative and claims costs. These issues are summarized in the following table: Potential Liabilities for Noncompliance Severity of Compliance Costs Benefits of Compliance Severe civil penalties of up to $25,000 per year for violation of each standard or requirement in the privacy, security, or EDI rules. Criminal penalties that apply if a person violates the rules with malicious intent or for personal gain. Risk of being sued by individuals over improperly released PHI. For insured benefits, compliance costs are low if the employer has no access to PHI. For self-insured benefits, the compliance burden (and legal risks for violation