This document provides an overview of patient privacy and confidentiality requirements under HIPAA. It discusses how confidential patient information should only be accessible to authorized medical professionals and defines examples of privacy violations. Consequences for violations include fines ranging from $100 to $50,000 depending on the nature of the violation. The document recommends ways for medical staff to avoid violations such as not discussing private patient information in public areas, logging off computers properly, and only sharing information with authorized individuals. Employers are responsible for implementing security procedures and training staff annually on confidentiality policies.