It holds violators accountable, with civil and criminal penalties that can be imposed if they violate patients' privacy rights And it strikes a balance when public responsibility supports disclosure of some forms of data - for example, to protect public health.