The Health Insurance Portability and Accountability Act (HIPAA) was enacted for the purpose of protecting the privacy of a client 's personal and health information.¹ Under HIPAA, protected health information (PHI) includes but is not limited to the following: a person 's name, address, date of birth, age, phone and fax numbers, e-mail address, medical records, diagnosis, x-rays, photos, prescriptions, lab work, or test results.¹ In this particular case scenario, a healthcare employee not only breached