Few moments test a care organization like discovering that resident information may have been exposed. A misdirected fax, a stolen laptop, a compromised email account or a ransomware attack all raise the same question: what are we required to do, and how quickly? The HIPAA Breach Notification Rule answers that question, but the details are easy to forget under pressure.
This post gives a plain-English overview. It is educational, not legal advice, and any real incident should involve your compliance officer and legal counsel.
Under the rule, a breach is an impermissible use or disclosure of unsecured protected health information that compromises its security or privacy. Unsecured generally means not encrypted or destroyed in a way that meets HHS guidance.
Not every incident is reportable. The rule starts from a presumption that an impermissible use or disclosure is a breach unless you can demonstrate a low probability that the information was compromised. There are also limited exceptions, such as certain unintentional, good-faith access by a workforce member acting within their authority.
To decide whether there is a low probability of compromise, you must assess at least these factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
The unauthorized person who used the information or to whom it was disclosed.
Whether the PHI was actually acquired or viewed.
The extent to which the risk has been mitigated.
Document your analysis carefully. If you cannot show a low probability of compromise, you must treat the incident as a reportable breach.
You must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovering the breach. The 60 days is an outer limit, not a goal. A breach is treated as discovered on the first day it is known, or would reasonably have been known, to the organization.
Notice is generally sent by first-class mail, or by email if the individual has agreed to electronic notice. It must be written in plain language and typically includes:
A description of what happened and the date of the breach and discovery, if known.
The types of information involved.
Steps individuals should take to protect themselves.
What the organization is doing to investigate, reduce harm and prevent a recurrence.
Contact information for questions.
Breaches affecting 500 or more individuals must be reported to HHS contemporaneously with individual notice, and no later than 60 days after discovery. Breaches affecting fewer than 500 individuals may be logged and reported to HHS within 60 days after the end of the calendar year in which they were discovered.
For breaches involving more than 500 residents of a state or jurisdiction, covered entities must also notify prominent media outlets serving that area, within the same 60-day limit.
Many states have their own breach notification laws with different definitions and timelines. Oklahoma, Texas and Arkansas each have statutes that may apply in addition to HIPAA, so your counsel should review both.
If a vendor discovers a breach involving your PHI, it must notify you, and your business associate agreement should set a faster timeline for doing so. Your own 60-day clock may begin when the business associate's discovery is imputed to you, so quick communication is essential.
Contain it: stop the exposure, disable accounts, retrieve the misdirected materials.
Start a written log with dates, times and actions.
Notify your privacy officer, administrator, IT provider and, if applicable, your insurer.
Preserve evidence, such as logs and affected devices.
Complete the risk assessment and record your conclusion.
Decide on notifications and prepare letters and reports.
Fix the root cause and update your risk analysis and training.
HIPAA requires you to retain breach documentation for six years, including your risk assessments, even when you determine no notification is required.
Having templates for notification letters, a contact list and a short incident checklist saves time. Practice a scenario with leadership so roles are clear.
UnityCare IT helps healthcare and senior-living organizations investigate incidents, preserve technical evidence and document findings that feed breach decisions. If you would like to build an incident checklist before you need it, we can help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034