When something goes wrong with resident information, the first questions are usually "Is this a breach?" and "How long do we have?" The HIPAA Breach Notification Rule answers both, but the language can feel dense. This post puts the main points in plain English. It is general information, not legal advice, and state laws may add their own requirements, so involve counsel early.
A breach is an impermissible use or disclosure of unsecured protected health information (PHI) that compromises its security or privacy. Examples include:
A laptop with unencrypted resident records is stolen
A fax or email goes to the wrong recipient
An employee looks at records of a neighbor with no job reason
Ransomware encrypts files containing PHI
A vendor mailbox is hacked and contains resident data
"Unsecured" generally means not encrypted or destroyed in a way HHS guidance recognizes. That is one reason encryption matters: properly encrypted data lost along with a device may fall outside the notification requirement.
An impermissible use or disclosure is presumed to be a breach unless you can show a low probability that the PHI was compromised. That conclusion rests on a documented assessment of at least four factors:
The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or received it
Whether the PHI was actually acquired or viewed
The extent to which the risk has been mitigated
Document this assessment every time, even when you conclude no notification is needed.
Certain situations are not breaches, including some unintentional, good-faith access by workforce members acting within their authority, and some inadvertent disclosures between authorized people within the same organization, as long as the information is not further misused. Have counsel confirm any exception.
Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a goal. Delay without good reason can itself be a violation.
A breach is treated as discovered on the first day it is known, or would have been known with reasonable diligence, to anyone in the organization other than the person who committed it.
500 or more individuals: notify HHS at the same time as individuals, no later than 60 days after discovery, through the OCR breach portal.
Fewer than 500 individuals: keep a log and report to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.
If a breach involves more than 500 residents of a single state or jurisdiction, you must also notify prominent media outlets serving that area, within the same 60-day limit.
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your agreements may require much shorter timelines, which is wise.
Written in plain language, sent by first-class mail or email if the person agreed to electronic notice, and including:
What happened and when, including dates of the breach and discovery
The types of information involved
Steps individuals should take to protect themselves
What you are doing to investigate, mitigate harm and prevent recurrence
How to contact you, including a toll-free number, email, website or postal address
For residents who lack capacity, notice goes to the personal representative. If contact information is outdated for ten or more people, substitute notice such as a website posting or major media notice is required.
If a law enforcement official states that notification would impede a criminal investigation, you may delay notification for the time specified, with proper documentation.
Oklahoma, Texas, Arkansas and other states have their own breach notification statutes with different definitions and timing. Some set shorter deadlines or require notice to the state attorney general. Compare requirements early.
Contain the issue and preserve evidence.
Notify your privacy officer and counsel right away.
Start the four-factor assessment.
Calendar the 60-day limit from the discovery date.
Prepare notice letters and call-center scripts in advance.
Document everything, including why a breach was or was not reportable.
UnityCare IT supports healthcare organizations with the technical side of incident investigation, including determining what systems and data were affected, which informs the breach assessment. If you want to practice, we can run a tabletop exercise with your team.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172