Sooner or later, most healthcare organizations face an incident involving protected health information: a fax sent to the wrong number, a stolen laptop, an employee looking at records without a reason, or a hacked email account. The question that follows is whether it is a reportable breach under HIPAA. The answer depends on a structured analysis, and getting it right matters because the rule carries firm deadlines.
This article summarizes how the HIPAA Breach Notification Rule works. It is general information and not legal advice, so involve your privacy officer and counsel on actual incidents.
The rule defines a breach as an acquisition, access, use or disclosure of protected health information in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. The rule applies to unsecured PHI, meaning information not rendered unusable, unreadable or indecipherable to unauthorized people, for example through encryption that meets HHS guidance.
An impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the information has been compromised, based on a documented risk assessment.
Three narrow exceptions exist:
An unintentional acquisition, access or use by a workforce member acting in good faith and within the scope of their authority, with no further impermissible use
An inadvertent disclosure between people authorized to access PHI at the same covered entity or business associate, with no further impermissible use
A disclosure where the recipient could not reasonably have retained the information
If no exception applies, assess the probability of compromise by considering at least these four factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom the disclosure was made, such as another covered entity bound by HIPAA versus an unknown party
The extent to which the risk has been mitigated, for example, by obtaining assurances that the recipient destroyed the information
Document the analysis and conclusion. If the assessment does not demonstrate a low probability of compromise, notification is required.
Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target. Notice is typically by first-class mail, or by email if the individual has agreed to electronic notice. It must include a description of what happened, the types of information involved, steps individuals should take to protect themselves, what the organization is doing and contact information. If contact information is out of date for 10 or more people, a substitute notice such as a website posting or media notice is required.
Breaches affecting 500 or more individuals: notify HHS at the same time as individuals, no later than 60 days after discovery.
Breaches affecting fewer than 500 individuals: keep a log and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.
For breaches involving more than 500 residents of a single state or jurisdiction, notice to prominent media outlets in that area is required, within the same 60-day limit.
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your business associate agreements should require much faster notice.
State breach notification laws may add requirements and shorter timelines. Oklahoma, Texas and Arkansas each have their own breach laws, so counsel should evaluate those along with HIPAA.
A breach is treated as discovered on the first day it is known to the organization, or by exercising reasonable diligence would have been known to any workforce member other than the person who committed the breach. This means delays in escalating internally can hurt you. Train staff to report suspected incidents right away.
HIPAA requires you to retain documentation of risk assessments, notifications and the burden of proof for six years. Keep a breach log, even for incidents you determine are not reportable.
Staff report the incident immediately to the privacy officer.
Contain the issue, such as retrieving a misdirected document or disabling an account.
Gather facts and preserve evidence.
Complete and document the four-factor risk assessment.
Decide on notification with counsel, and prepare letters if required.
Notify within required timelines, and report to HHS.
Review the root cause and update training and controls.
Having a written incident response plan, contact list and letter templates in advance saves valuable time. UnityCare IT helps healthcare organizations build incident response and breach assessment procedures and supports technical investigations when incidents occur. Reach out if you would like to review your plan before you need it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034