SynfraCore
Synfracore
Start Learning
Navigation

Academies

Platform

RoadmapsLabsCertificationsInterviewPYQsAI AssistantCareer
Start Learning Free Learning Roadmaps

Healthcare AdministrationFundamentals

Core concepts and foundational knowledge

📄
Last updated Jul 2026
Expert Content

Healthcare Administration Fundamentals

Analogy — The healthcare stakeholder map below works like the different parties in a home sale — the buyer (patient), the buyer's bank (payer), the seller (provider), and the county/regulatory bodies that record and enforce the rules of the transaction (regulators). Confusing "who pays" with "who provides care" with "who enforces the rules" is a common early mistake, and this page exists specifically to keep those three categories distinct.

Overview of Healthcare Settings

TYPES OF HEALTHCARE ORGANIZATIONS:
  Hospitals: acute care, critical access, specialty (psychiatric, rehabilitation)
  Physician Practices: solo, group, multi-specialty, academic medical centers
  Ambulatory Surgery Centers (ASC): outpatient procedures only
  Long-Term Care: skilled nursing facilities (SNF), assisted living
  Home Health Agencies: nursing, therapy, aide services at home
  Hospice: end-of-life care (comfort-focused, not curative)
  Behavioral Health: psychiatric hospitals, outpatient counseling
  Federally Qualified Health Centers (FQHC): safety-net clinics

OWNERSHIP TYPES:
  Not-for-profit (501c3): most hospitals, community mission
  For-profit: investor-owned, shareholder returns (HCA, Tenet, Steward)
  Government: VA, county hospitals, public health departments

Healthcare Stakeholders

PAYERS:
  Medicare: federal, age 65+ | disability | ESRD
    Part A: hospital, SNF, hospice
    Part B: physician, outpatient, DME
    Part C: Medicare Advantage (private plans)
    Part D: prescription drugs
  
  Medicaid: state/federal, low income
    Each state administers differently
    CHIP: children's health insurance program
  
  Commercial: employer-sponsored or individual market
    Blue Cross Blue Shield, Aetna, UnitedHealth, Cigna, Humana
    PPO: freedom to choose any provider
    HMO: must use network, PCP referral needed
    HDHP: high deductible health plan + HSA

PROVIDERS:
  MD/DO: physicians (medical doctors / doctors of osteopathy)
  NP: nurse practitioners (can practice independently in many states)
  PA: physician assistants (require physician supervision)
  RN: registered nurses | LPN: licensed practical nurses
  PT/OT/SLP: physical, occupational, speech therapists

REGULATORS:
  CMS: Centers for Medicare & Medicaid Services (federal)
  State health departments: licensure, Medicaid oversight
  Joint Commission (TJC): voluntary accreditation
  OSHA: workplace safety for healthcare workers
  OCR: HIPAA enforcement under HHS

HIPAA Basics

HIPAA PRIVACY RULE:
  Protects PHI (Protected Health Information)
  PHI = any information that identifies patient + relates to health
  18 identifiers: name, DOB, SSN, address, phone, email, etc.
  Minimum necessary standard: share only what is needed
  Patient rights: access, amendment, accounting of disclosures

HIPAA SECURITY RULE:
  Applies to electronic PHI (ePHI) only
  Administrative safeguards: policies, training, access management
  Physical safeguards: workstation security, device controls
  Technical safeguards: access controls, audit logs, encryption, MFA

HIPAA BREACH:
  Unauthorized acquisition/access/use/disclosure of unsecured PHI
  Risk assessment: determine if it is a breach requiring notification
  Notification: patient (60 days) + OCR (60 days) + media if 500+ in state
  Penalties: $100-$50,000 per violation, up to $1.9M/year per category

Try It (2 Minutes)

A hospital reports a breach affecting 800 patients' records.

1.Using the HIPAA Breach section above, does this trigger media notification, based on the 500-person threshold mentioned?
2.Within how many days must affected patients be notified?
3.Which HIPAA rule (Privacy or Security) governs the breach itself, versus which one defines what counts as PHI in the first place?

You should land on: yes — 800 exceeds the 500-in-state threshold, so media notification is required alongside patient and OCR notification; 60 days for both patient and OCR notification; and the Security Rule governs breaches of electronic PHI specifically, while the Privacy Rule is what defines PHI and patients' rights over it in the first place — two related but distinct rules.

Study Resources

ACHP Healthcare Administration Guide — free overview
CMS website (cms.gov) — all federal healthcare programs
ACHE.org — American College of Healthcare Executives resources
AHIMA Body of Knowledge — health information management
Share:
Join our Community
Health & wellness tips, coding Q&A — join learners growing together
Up Next
Healthcare AdministrationIntermediate
Applied knowledge and worked examples
Also Worth Exploring
← Back to all Healthcare Administration modules
OverviewIntermediate