No organization wants to think about a breach, but every covered entity should understand how the HIPAA Breach Notification Rule works before one happens. Deadlines begin to run quickly, decisions must be documented, and the people making them are often under stress. Knowing the framework in advance makes those decisions clearer.
This article gives a plain-English overview. It is not legal advice, and you should involve your compliance officer or counsel in any actual incident.
Under HIPAA, a breach is generally an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule presumes an impermissible use or disclosure is a breach unless the covered entity demonstrates, through a documented risk assessment, that there is a low probability the information has been compromised.
The rule also contains exceptions, such as certain unintentional access by workforce members acting in good faith within the scope of their authority, or certain inadvertent disclosures between authorized people at the same organization, where information is not further misused.
The notification requirements apply to unsecured PHI. HHS guidance describes PHI as secured when it has been rendered unusable, unreadable or indecipherable to unauthorized people, through encryption or destruction consistent with its guidance. If properly encrypted data is lost and the key is not compromised, notification generally is not required. This is one of the strongest practical reasons to encrypt devices and backups.
When you cannot rule out a breach, you assess the probability that PHI has been compromised by considering at least these factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom the disclosure was made
Whether the PHI was actually acquired or viewed
The extent to which the risk to the PHI has been mitigated
Document the analysis and the conclusion, whichever way it goes.
If a breach of unsecured PHI occurred, notification generally goes to:
Affected individuals, or their personal representatives, in writing
The Secretary of HHS, through the Office for Civil Rights breach reporting process
The media, when a breach affects more than 500 residents of a state or jurisdiction
Business associates must notify the covered entity of breaches they discover.
Notice to individuals must be provided without unreasonable delay and no later than 60 calendar days after discovery of the breach. A breach is treated as discovered on the first day it is known, or reasonably should have been known, to the organization. That detail matters: the clock does not start when the investigation ends.
For breaches affecting 500 or more individuals, HHS must be notified at the same time as individuals, and media notice follows the same timeline. For breaches affecting fewer than 500, covered entities may log them and report to HHS within 60 days after the end of the calendar year in which they were discovered.
Sixty days is an outer limit. Delay without good reason can itself create problems.
Individual notices are written in plain language and generally include:
A brief description of what happened, including the date of the breach and date of discovery, if known
The types of information involved
Steps individuals should take to protect themselves
What the organization is doing to investigate, mitigate harm and prevent recurrence
Contact procedures, including a toll-free number, email, website or postal address
Oklahoma, Texas and Arkansas each have breach notification statutes that may impose additional or different requirements, such as notice to the state attorney general or shorter timelines. Your contracts and cyber insurance policy may also require prompt notice. Counsel can help reconcile them.
Keep a written breach response procedure naming who decides and who communicates
Maintain a template for the four-factor assessment
Keep a breach log, including incidents you determined were not reportable
Train staff to report suspected incidents immediately
Know your insurance carrier's notification requirements
Retain documentation for six years
UnityCare IT helps healthcare organizations with the technical side of incidents: investigating what happened, preserving evidence and identifying which systems and data were affected. We work alongside your compliance officer and counsel, who make the legal determinations.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172