A nurse faxes a resident's records to the wrong number. A laptop is stolen from a car. An employee opens a file she should not have. Each of these is a security or privacy incident, but is each one a breach that must be reported? The answer has real consequences, and HIPAA gives a specific method for working it out.
Understanding that method helps you respond with confidence rather than panic or guesswork.
An incident is any event that may compromise the confidentiality, integrity or availability of information. A breach, as defined in the HIPAA Breach Notification Rule, is an impermissible use or disclosure of protected health information (PHI) that compromises its security or privacy.
The rule presumes that an impermissible use or disclosure of PHI is a breach unless you can demonstrate, through a documented risk assessment, that there is a low probability that the PHI has been compromised. There are also a few narrow exceptions, such as certain unintentional, good-faith access by a workforce member acting within their authority, or inadvertent disclosures between authorized people at the same organization, provided the information is not further misused.
When no exception applies, you assess at least these four factors:
What types of information were exposed? Names alone are different from names with Social Security numbers, diagnoses, medications or financial details.
Who received it? A disclosure to another HIPAA-covered entity or someone obligated to protect it is lower risk than a disclosure to an unknown person, a journalist or a criminal.
Was the data actually looked at, or was there only an opportunity? A stolen laptop that is later recovered with forensic proof that files were never opened is different from one that disappeared. A misdirected email that was deleted unread, confirmed by the recipient, is different from one that was opened.
Did you get assurance, preferably in writing, that the recipient destroyed or returned the information and will not misuse it? Did you remotely wipe the device? Mitigation can lower the probability of compromise.
Consider a hypothetical: a staff member emails a spreadsheet with resident names and diagnoses to the wrong external address. The assessment might note that the information is sensitive (factor 1), that the recipient is an unknown individual at an unrelated company (factor 2), that it is unclear whether the message was opened (factor 3), and that you are awaiting a reply to your request for deletion (factor 4). Without solid evidence that the data was not accessed, you likely could not show a low probability of compromise, and notification would be required. Different facts could lead to a different result, and the reasoning must be written down.
HIPAA breach notification requirements include:
Individuals: notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. A breach is treated as discovered when it is known, or reasonably should have been known, to the organization.
HHS: for breaches affecting 500 or more individuals, notify HHS at the same time as individuals. For fewer than 500, log the breaches and report them to HHS within 60 days after the end of the calendar year.
Media: for breaches affecting more than 500 residents of a state or jurisdiction, notify prominent media outlets in that area.
Business associates: must notify the covered entity, which then handles notification to others unless the contract assigns the task differently.
State laws may impose additional or different requirements, so ask your attorney to check them for Oklahoma, Texas, Arkansas or wherever your residents live.
PHI that has been properly encrypted according to HHS guidance, so that it is unusable and unreadable to unauthorized persons, is not considered unsecured. Losing an encrypted laptop with a secure key can therefore be a very different event from losing an unencrypted one. This is a strong reason to encrypt every portable device.
Keep a record of each incident, the facts you gathered, the assessment of each factor, your conclusion and any notices sent. Retain the documentation for six years. Even incidents you decide are not reportable should have a written analysis.
UnityCare IT helps healthcare organizations investigate technical facts, such as whether a device was encrypted or which files were accessed, so your privacy officer and counsel can make a sound decision. We can also help you set up an incident log and response workflow.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172