Course Description
HIM2012 – Health Law Concepts and Practices is a 3-credit course of roughly 48
contact hours in Florida's Health Information Technology curriculum. It covers the legal and ethical
framework governing health information — who owns a health record, who may see it, how long it must be
kept, and what happens when those rules are broken.
The health information professional occupies a specific legal position: custodian of the record. That role
carries obligations that are enforced, and the course treats them as operational requirements rather than
background context.
HIPAA anchors the course. Students work through the Privacy Rule —
protected health information, permitted uses and disclosures, the minimum necessary standard, patient rights
of access and amendment, and valid authorization — and the Security Rule's
administrative, physical, and technical safeguards. Breach notification under HITECH, and
the civil and criminal penalties that attach, are covered concretely.
Beyond HIPAA, content covers the American legal system as it bears on health care; the
legal health record and what constitutes it; release of information
including subpoenas, court orders, and the difference between them; retention and destruction
requirements; consent and informed consent; negligence and malpractice
including the record's role as evidence; patient rights; compliance
programs and fraud and abuse enforcement; and e-discovery obligations for electronic
records.
Florida adds its own layer: Chapter 395, Florida Statutes and Florida Administrative Code
rules govern hospital licensure and medical record requirements, and Florida's retention periods and access
provisions differ in specifics from federal minimums.
Offered at approximately 18 Florida institutions with HIT programs, including Broward, College of Central
Florida, Daytona State, Florida Gateway, Florida State College at Jacksonville, Florida SouthWestern,
Lake-Sumter, Miami Dade, North Florida, Santa Fe, South Florida State, St. Johns River, St. Petersburg,
Seminole State, and State College of Florida.
Learning Outcomes
Required Outcomes
- Describe the American legal system and the sources of law affecting health care.
- Define the legal health record and identify what it comprises in paper and electronic environments.
- Apply HIPAA Privacy Rule requirements to uses and disclosures of protected health information.
- Apply the minimum necessary standard and identify permitted disclosures without authorization.
- Evaluate the validity of an authorization for release of information.
- Distinguish a subpoena from a court order and respond to each appropriately.
- Apply HIPAA Security Rule administrative, physical, and technical safeguards.
- Describe breach notification obligations under HITECH and the applicable penalties.
- Apply record retention and destruction requirements under federal and Florida law.
- Describe patient rights of access, amendment, and accounting of disclosures.
- Explain consent and informed consent and the documentation each requires.
- Describe negligence, malpractice, and the health record's role as evidence.
- Describe compliance programs, fraud and abuse laws, and the health information professional's role.
- Apply the AHIMA Code of Ethics to situations involving custody of patient information.
Optional Outcomes
- Describe e-discovery obligations and litigation holds for electronic records.
- Describe 42 CFR Part 2 protections for substance use disorder records.
- Describe minors' rights and parental access to records.
- Describe advance directives and end-of-life documentation.
- Describe risk management and incident reporting.
- Describe information governance and data stewardship.
Major Topics
Required Topics
- The legal system in health care — sources of law, courts, and the litigation process.
- The legal health record — definition, composition, ownership, and the designated record set.
- HIPAA Privacy Rule — PHI, covered entities, business associates, permitted uses, and minimum necessary.
- Patient rights — access, amendment, accounting of disclosures, and restriction requests.
- Authorization and release of information — validity elements, subpoenas, court orders, and special categories.
- HIPAA Security Rule — administrative, physical, and technical safeguards; risk analysis.
- Breach notification — HITECH requirements, timelines, and penalty tiers.
- Retention and destruction — federal minimums, Florida requirements, and destruction documentation.
- Consent — general and informed consent, capacity, and surrogate decision-making.
- Negligence and malpractice — elements, the standard of care, and documentation as evidence.
- Fraud and abuse — False Claims Act, Anti-Kickback Statute, Stark Law, and documentation integrity.
- Compliance programs — structure, auditing, and reporting.
- Florida requirements — Chapter 395, F.S. and AHCA rules on medical records.
- Professional ethics — the AHIMA Code of Ethics applied to record custody.
Optional Topics
- E-discovery and litigation holds.
- 42 CFR Part 2 substance use disorder records.
- Minors and parental access.
- Advance directives.
- Risk management and incident reporting.
- Information governance.
Resources & Tools
- Legal Aspects of Health Information Management or AHIMA's Fundamentals of Law for Health Informatics and Information Management — the standard texts.
- Health Information Management Technology: An Applied Approach (AHIMA Press) — the legal chapters, for programs using a single text across the curriculum.
- HHS Office for Civil Rights — authoritative HIPAA Privacy and Security guidance, plus the public breach portal.
- 45 CFR Parts 160 and 164 — the HIPAA rules themselves; freely available and worth reading directly.
- Chapter 395, Florida Statutes and Florida Administrative Code rules on medical records and hospital licensure.
- Florida Agency for Health Care Administration (AHCA) — state requirements and enforcement.
- AHIMA — Code of Ethics, practice briefs, and retention guidance.
- Sample authorization forms, subpoena response procedures, and retention schedules.
Career Pathways
- Medical Records Specialist / Health Information Technician (SOC 29-2072) — the core occupation.
- Release of Information Specialist — the role this course most directly prepares for.
- Privacy Officer or Privacy Analyst — required at every covered entity; a growing pathway.
- Compliance Officer (SOC 13-1041) — healthcare compliance is a substantial Florida field.
- Health Information Manager (SOC 11-9111) — typically requiring the RHIA.
- Risk Management and Audit roles in hospitals and insurers.
- Health Information Exchange and Data Governance roles.
Florida employers include AdventHealth, Orlando Health, BayCare, Baptist Health, Memorial Healthcare,
Tampa General, and Lee Health, along with physician practices, insurers, and release-of-information vendors.
Privacy and compliance roles have grown steadily as enforcement has increased.
Special Information
Course-title variation across Florida
The SCNS title is Health Law Concepts and Practices, but institutions publish it as
Health Records Law (Broward, 3 credits and 48 contact hours), Health Law and Compliance
(Santa Fe), and Legal Aspects of Health Information. Under SCNS the same number at the same level is
equivalent regardless of title; match on the number.
Prerequisites
Prerequisites vary. Broward lists none for the course itself; most institutions require admission to the
Health Information Technology program and completion of HIM1000 (Introduction to Health
Information Management), whose HIPAA orientation this course develops in depth. Verify locally.
Position in the curriculum
This is typically a second-term or second-year HIT course, following HIM1000 and running alongside coding
and healthcare statistics. Its content is substantially represented on the RHIT examination,
where privacy, security, and compliance form a significant domain.
Federal law sets a floor; Florida can set a higher one
A recurring practical point. HIPAA establishes minimum standards, and where state law is
more protective of patient privacy, state law governs. Florida has its own record retention periods,
access provisions, and requirements for particular record types. A health information professional working in
Florida must know both, and applying the federal minimum where Florida requires more is a compliance
failure.
The consequences are real and personal
Worth stating plainly for students: HIPAA violations carry civil penalties against the organization and
criminal penalties against individuals who knowingly obtain or disclose protected health
information improperly. The most common enforcement scenario is not a sophisticated breach — it is an
employee looking up the record of a relative, neighbor, or celebrity out of curiosity. That is a firing
offense at every health system and can be prosecuted. Instructors generally make this concrete early.