Few things are more stressful for an administrator than discovering that protected health information may have been exposed. A laptop is missing. A fax went to the wrong number. An employee looked at records they had no reason to see. Within hours, questions arise: is this a reportable breach, who do we tell, and how long do we have?
The HIPAA Breach Notification Rule gives clear answers, though the details matter. This is general information, not legal advice, and you should involve counsel and your compliance officer for any real incident.
Under the rule, a breach is the acquisition, access, use or disclosure of unsecured protected health information in a manner not permitted by the Privacy Rule that compromises its security or privacy. Unsecured means not encrypted or destroyed according to HHS guidance.
Any such impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the information was compromised, based on a documented risk assessment.
To rebut the presumption, evaluate at least:
The nature and extent of the information involved, including identifiers and how likely it is to identify people.
The unauthorized person who used the information or to whom it was disclosed.
Whether the information was actually acquired or viewed.
The extent to which the risk has been mitigated, for example through a signed assurance that the recipient destroyed the data.
Document your reasoning. If you cannot show a low probability of compromise, treat it as a reportable breach.
A breach is treated as discovered on the first day it is known to your organization, or would have been known with reasonable diligence. Any workforce member, other than the person who committed the breach, knowing about it can start the clock, so staff must know to report immediately.
Stop the exposure, whether that means recovering a document, disabling an account or locking a device.
Notify your privacy officer and security officer.
Preserve evidence and begin documenting.
Call your insurer if cyber coverage may apply, since policies often have prompt-notice conditions.
You must notify each affected individual without unreasonable delay, and no later than 60 calendar days after discovery. The 60 days is an outer limit, not a target. Notice is generally sent by first-class mail, or by email if the individual agreed to electronic notice, and must include:
A description of what happened and when, including the date of discovery.
The types of information involved.
Steps individuals should take to protect themselves.
What you are doing to investigate, mitigate harm and prevent a recurrence.
Contact information for questions.
Where contact information is out of date for ten or more people, substitute notice through a website posting or major media may be required.
If a breach affects more than 500 residents of a state or jurisdiction, you must also notify prominent media outlets in that area within the same 60-day limit.
500 or more individuals: notify the HHS Secretary at the same time as individual notice, without unreasonable delay and within 60 days, through the OCR breach portal.
Fewer than 500: log the breach and report to HHS within 60 days after the end of the calendar year in which it was discovered.
If a vendor is breached, they must notify you without unreasonable delay and within 60 days of discovery, though your contract may require sooner. The clock for your obligations can depend on whether the vendor acts as your agent, so ask counsel and read the agreement.
Many states, including Oklahoma, Texas and Arkansas, have their own breach notification statutes with different definitions, deadlines and attorney general reporting requirements. A breach may trigger both federal and state obligations, and the shorter deadline governs in practice.
If law enforcement states that notification would impede a criminal investigation, you may delay as directed. Document the request.
Write a breach response procedure naming who decides, who drafts notices and who calls counsel.
Train staff to report suspected incidents immediately.
Keep a breach log with risk assessments, even for incidents you decide are not reportable.
Encrypt laptops, phones and backups. Properly encrypted data is generally exempt from notification.
UnityCare IT helps with the technical side of incidents, including scoping what was accessed, preserving logs and strengthening controls afterward. If your breach procedure is not written yet, we can help you build one before you need it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172