HCA 812: could self-regulation have replaced HIPAA?
A doctoral discussion post arguing whether more stringent self-regulation by health care professionals and related organisations could have eliminated the perceived necessity for external regulation such as the Health Insurance Portability and Accountability Act, and saying why or why not.
Editorial process
Last reviewed · August 13, 2026
Perceived, and eliminated
Two words in this prompt are doing more work than they appear to be, and reading past them produces the generic post. The first is perceived. The question is not whether HIPAA was necessary but whether the necessity was perceived, which invites you to ask who perceived it, on what evidence, and whether that perception was accurate. Congress acted on a particular reading of the situation in the mid-nineties, and you are entitled to examine that reading rather than accept it. The second is eliminated. Not reduced, not delayed, not made narrower in scope, but removed entirely. That is a strong counterfactual and a post that argues self-regulation would have helped somewhat has not answered it. Decide early whether you are defending the strong claim, rejecting it, or arguing that self-regulation could have changed the form of the law without preventing it. The third position is usually the most defensible and the least often taken.
The counterfactual needs historical grounding or it becomes an exchange of intuitions, which is what these threads tend to become. Professional self-regulation already existed when HIPAA passed: codes of ethics, licensure boards, accreditation standards and institutional policies all addressed confidentiality, and had done for a long time. So the honest question is why an existing self-regulatory apparatus did not prevent the perceived problem. Several answers are available and each supports a different conclusion. Self-regulation binds members of a profession and was never going to reach the clearinghouses, insurers, employers and vendors who increasingly held the data. It has no remedy for a patient whose record was disclosed by an organisation to which no professional body could apply a sanction. It cannot create the portability half of the statute at all. Naming which limitation you think decisive is the analysis. Say which one you think decisive and why the others are secondary to it.
HIPAA is also easy to misdescribe, and a doctoral marker will notice. The statute's original purpose was insurance portability and administrative simplification, with the privacy and security rules arriving through rulemaking rather than in the original text, and the enforcement structure strengthening later through subsequent legislation. That matters for this question in a specific way: the administrative simplification provisions responded to a coordination problem the industry had failed to solve voluntarily for decades, and coordination failures are exactly the kind of thing self-regulation handles badly, because no single actor gains by moving first. If you want a strong argument that self-regulation could not have sufficed, the standardisation story is more persuasive than the privacy story, since privacy norms genuinely did exist while a common transaction standard genuinely did not and could not emerge on its own. That argument also has the advantage of being checkable against the record.
The strongest post also states the case it is arguing against, and there is a real one. Self-regulation reaches conduct that law cannot specify, moves faster than legislation, is written by people who understand the work, and produces compliance that comes from professional identity rather than fear of penalty. Against that, external regulation supplies enforceable rights for patients, jurisdiction over non-professionals, and a floor that does not move when an institution finds it inconvenient. The interesting position is that these are complements rather than substitutes, and that the actual failure was not too little self-regulation but a self-regulatory system whose boundaries no longer matched where the data had gone. Argue whichever side you find more persuasive, but show that you have understood the other one properly. It is also the position the evidence best supports, which is worth saying explicitly. Doing so is also what turns a discussion post into an argument rather than a summary.
On execution, this is a doctoral discussion post and the expectations are correspondingly higher. Take a clear position in the first sentence rather than surveying the question, support the claim with sources rather than with plausibility, and prefer primary material where it exists: the statute, the regulatory text, the enforcement data, professional codes as they stood before the law. Keep the post to a defensible length and end with something your peers can respond to, which is usually a claim rather than a question. If your programme uses a rubric with a source minimum, meet it with current, credible sources rather than with textbook citations, and cite them properly in text. Avoid the closing move of saying both are needed without having said what each does that the other cannot. Say instead which function each mechanism performs that the other structurally cannot. A doctoral thread rewards a claim your peers can disagree with more than it rewards balance.
Likely learning objectives
Inferred from the brief — check these against your own rubric.
- 01Read the counterfactual as stated rather than softening it.
- 02Explain why existing self-regulation did not prevent the perceived problem.
- 03Describe HIPAA's original purpose and later privacy rulemaking accurately.
- 04Distinguish a coordination failure from a norms failure.
- 05State the strongest opposing case before rejecting it.
- 06Support the position with primary regulatory and professional sources.
Read the full question
Review every instruction before using the planning guidance that follows.
Turn the brief into deliverables
- 01A clear position on whether stricter self-regulation could have eliminated the perceived necessity for HIPAA.
- 02Reasons, supported by sources rather than by assertion.
- 03Accurate treatment of what the statute originally did and what came later by rule.
- 04Engagement with the opposing position.
- 05A close that peers can respond to.
Building the argument
Position
Your answer to the counterfactual, stated first.
What self-regulation already covered
Codes, licensure, accreditation and institutional policy before the statute.
What it could not reach
Clearinghouses, insurers, employers and vendors outside professional jurisdiction.
What the statute actually did
Portability and administrative simplification first, privacy and security by rule later.
Coordination versus norms
Why a common transaction standard could not emerge voluntarily.
The opposing case
Speed, expertise and internalised compliance as self-regulation's real advantages.
Close
What the perceived necessity was actually a perception of, stated as a claim.
Statute, codes and enforcement data
Recommended databases
- The statute and the Code of Federal Regulations
- Department of Health and Human Services guidance and enforcement data
- Professional association codes of ethics as they stood before 1996
- Health policy and law journals
Search sequence
- 1.Read what the statute's title and original sections actually cover before writing about it.
- 2.Find the date the privacy rule was issued and confirm it postdates the statute.
- 3.Locate professional confidentiality codes in force before the law, so the baseline is evidenced.
- 4.Look for enforcement data on who breaches and whether they are regulated professionals.
- 5.Search health policy literature for the administrative simplification rationale.
Reference shortlist
These are authoritative starting points, not a ready-made bibliography. A qualified reviewer must confirm that each source fits the assignment and supports the claim beside which it is cited.
Nothing here is cleared for citation until you have read it.
- 01
Health Insurance Portability and Accountability Act (HIPAA) Compliance
StatPearls, NCBI Bookshelf · 2023
What the statute and its rules actually require, which the post has to describe correctly before arguing the counterfactual.
- 02
Patient Confidentiality
StatPearls, NCBI Bookshelf · 2023
Confidentiality as a professional obligation independent of the statute, which is the self-regulation baseline.
- 03
HIPAA for Professionals
U.S. Department of Health and Human Services · 2025
Primary regulatory material on covered entities and business associates, which defines who self-regulation could never have reached.
- 04
Informed Consent
StatPearls, NCBI Bookshelf · 2023
A parallel case where professional norms and legal requirements coexist, useful for the complements-not-substitutes argument.
Review before submission
Common mistakes
- Answering that self-regulation would have helped, which does not address elimination.
- Treating HIPAA as a privacy statute from the outset.
- Assuming no self-regulation of confidentiality existed before the law.
- Ignoring the actors self-regulation cannot reach, such as clearinghouses and vendors.
- Concluding that both are needed without saying what each does uniquely.
- Supporting a doctoral post with textbook citations rather than primary sources.
- Surveying the question instead of taking a position.
Submission checklist
- A position is stated in the opening sentence.
- The word perceived is engaged, not passed over.
- The counterfactual is answered as elimination, not reduction.
- Pre-existing self-regulation of confidentiality is acknowledged.
- The limits of professional self-regulation over non-professionals are named.
- The statute's portability and administrative simplification purpose is stated correctly.
- The privacy and security rules are located in rulemaking, not the original text.
- The coordination-failure argument is distinguished from the norms argument.
- The strongest opposing case is stated fairly.
- Sources are current, credible and cited in text.
- The post closes with a claim peers can test.
Use this guide to plan and review your own work. Follow your institution's rules and read our academic-integrity policy.

Written by
Aaron Bishop
MA, Education
assignment interpretation and research-methods coaching across disciplines
Aaron leads the EssayCrackers editorial desk. He works on how assignment briefs are read — what a rubric is actually asking for, and where students most often answer a different question than the one set.

Reviewed by
Dr. Nathan Cole
PhD, Rhetoric & Composition
Argumentation and thesis development
Nathan teaches first-year composition and directs a university writing center. He reviews EssayCrackers guides for argumentative soundness and citation accuracy.