FYI, you might want to look into the laws which are just now starting to be enforced. If you are in IT then you are now a covered entity and can be fined directly for HIPPA failures. You also have a legal obligation to document any contact with PHI and you have a legal obligation to report your doctor if you even observe any HIPPA violation, IT related or not. I could not work under these terms so stick to non-medical IT work.
For years, under advice of my lawyer, I operated under a signed contract with all my healthcare customers that included a disclaimer that HIPPA was not my responsibility and I had no HIPPA responsibilities. Recent decisions by the DCR have ruled such disclaimers invalid and defined Business Associates as providers to healthcare providers that have access to PHI and thus to which the HIPPA regulations apply directly. My lawyer said he can no longer limit my liability or responsibility for HIPPA with a disclaimer and advised me to implement full HIPPA compliant policies, procedures and documentation or drop my healthcare customers.
Please feel free to ignore reality if you want to get blind-sided by this.