You seem to like to make a lot of unwarranted assumptions about my skills and emotional state. Who said I was angry? I made a decision and moved on. I don't waste time on idiocy I can't change. There is plenty of non-medical IT work as I am sure you know, I just didn't want to take on the risks.
FYI, you might want to look into the laws which are just now starting to be enforced. If you are in IT then you are now a covered entity and can be fined directly for HIPPA failures. You also have a legal obligation to document any contact with PHI and you have a legal obligation to report your doctor if you even observe any HIPPA violation, IT related or not. I could not work under these terms so stick to non-medical IT work.
Rather than looking into the laws yourself, you should have consulted a lawyer. You would have learned how the rules actually apply to service providers of health institutions instead of developing a serious misunderstanding of how HIPPA works.
As other others have pointed out HIPPA is an old law. But what most people do not realize is that it has not been enforced (for 10 years?) because no bureaucracy had responsibility for enforcement. This has led to a high level of complacency regarding the seriousness of the HIPPA law. HIPPA now has an "owner" (i.e. enforcer) at the HHS in the Dept. of Civil Rights and they are spooling up to start cracking down and auditing and fining healthcare providers and their business associates. This process has already begun so things are about to change.
For years, under advice of my lawyer, I operated under a signed contract with all my healthcare customers that included a disclaimer that HIPPA was not my responsibility and I had no HIPPA responsibilities. Recent decisions by the DCR have ruled such disclaimers invalid and defined Business Associates as providers to healthcare providers that have access to PHI and thus to which the HIPPA regulations apply directly. My lawyer said he can no longer limit my liability or responsibility for HIPPA with a disclaimer and advised me to implement full HIPPA compliant policies, procedures and documentation or drop my healthcare customers.
Please feel free to ignore reality if you want to get blind-sided by this.
FYI, you might want to look into the laws which are just now starting to be enforced. If you are in IT then you are now a covered entity and can be fined directly for HIPPA failures. You also have a legal obligation to document any contact with PHI and you have a legal obligation to report your doctor if you even observe any HIPPA violation, IT related or not. I could not work under these terms so stick to non-medical IT work.