The HIPAA Breach Notification Rule: Timelines and Decisions

Sooner or later, most healthcare organizations face an incident involving protected health information: a fax sent to the wrong number, a stolen laptop, an employee looking at records without a reason, or a hacked email account. The question that follows is whether it is a reportable breach under HIPAA. The answer depends on a structured analysis, and getting it right matters because the rule carries firm deadlines.

This article summarizes how the HIPAA Breach Notification Rule works. It is general information and not legal advice, so involve your privacy officer and counsel on actual incidents.

What Counts as a Breach

The rule defines a breach as an acquisition, access, use or disclosure of protected health information in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. The rule applies to unsecured PHI, meaning information not rendered unusable, unreadable or indecipherable to unauthorized people, for example through encryption that meets HHS guidance.

An impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the information has been compromised, based on a documented risk assessment.

The Exceptions

Three narrow exceptions exist:

An unintentional acquisition, access or use by a workforce member acting in good faith and within the scope of their authority, with no further impermissible use

An inadvertent disclosure between people authorized to access PHI at the same covered entity or business associate, with no further impermissible use

A disclosure where the recipient could not reasonably have retained the information

The Four-Factor Risk Assessment

If no exception applies, assess the probability of compromise by considering at least these four factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or to whom the disclosure was made, such as another covered entity bound by HIPAA versus an unknown party

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated, for example, by obtaining assurances that the recipient destroyed the information

Document the analysis and conclusion. If the assessment does not demonstrate a low probability of compromise, notification is required.

Who Must Be Notified and When

Individuals

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target. Notice is typically by first-class mail, or by email if the individual has agreed to electronic notice. It must include a description of what happened, the types of information involved, steps individuals should take to protect themselves, what the organization is doing and contact information. If contact information is out of date for 10 or more people, a substitute notice such as a website posting or media notice is required.

HHS

Breaches affecting 500 or more individuals: notify HHS at the same time as individuals, no later than 60 days after discovery.

Breaches affecting fewer than 500 individuals: keep a log and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.

Media

For breaches involving more than 500 residents of a single state or jurisdiction, notice to prominent media outlets in that area is required, within the same 60-day limit.

Business associates

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your business associate agreements should require much faster notice.

State requirements

State breach notification laws may add requirements and shorter timelines. Oklahoma, Texas and Arkansas each have their own breach laws, so counsel should evaluate those along with HIPAA.

When the Clock Starts

A breach is treated as discovered on the first day it is known to the organization, or by exercising reasonable diligence would have been known to any workforce member other than the person who committed the breach. This means delays in escalating internally can hurt you. Train staff to report suspected incidents right away.

Documentation Requirements

HIPAA requires you to retain documentation of risk assessments, notifications and the burden of proof for six years. Keep a breach log, even for incidents you determine are not reportable.

A Practical Workflow

Staff report the incident immediately to the privacy officer.

Contain the issue, such as retrieving a misdirected document or disabling an account.

Gather facts and preserve evidence.

Complete and document the four-factor risk assessment.

Decide on notification with counsel, and prepare letters if required.

Notify within required timelines, and report to HHS.

Review the root cause and update training and controls.

Be Prepared

Having a written incident response plan, contact list and letter templates in advance saves valuable time. UnityCare IT helps healthcare organizations build incident response and breach assessment procedures and supports technical investigations when incidents occur. Reach out if you would like to review your plan before you need it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034