When something goes wrong with patient or resident information, such as a lost laptop, a misdirected fax or a compromised email account, the first questions are usually the same. Is this a breach? Who do we tell? How long do we have? The HIPAA Breach Notification Rule answers these, but the language can be hard to apply under pressure. This question-and-answer guide covers the basics. It is general information, not legal advice, so involve counsel for specific situations.
A breach is generally an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule presumes that an impermissible use or disclosure is a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a documented risk assessment.
The assessment must consider at least four factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom it was disclosed
Whether the PHI was actually acquired or viewed
The extent to which the risk has been mitigated
Write down your analysis and conclusion every time, even when you decide notification is not required.
Yes. The rule excludes certain situations, such as an unintentional access by a workforce member acting in good faith and within their authority that does not result in further misuse, certain inadvertent disclosures between authorized persons at the same organization, and cases where the recipient could not reasonably have retained the information. These exceptions are narrow, so apply them carefully.
Yes. The rule applies to unsecured PHI. If data was encrypted consistent with HHS guidance and the key was not compromised, a loss of the device or media is generally not a reportable breach. This is a major reason to encrypt laptops, phones and backups.
Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered. Sixty days is an outer limit, not a target, so move quickly. A breach is treated as discovered on the first day it is known, or would have been known with reasonable diligence, to anyone in the organization other than the person who committed it.
Notice is usually sent by first-class mail, or by email if the individual has agreed to electronic notice. It must include a description of what happened, the types of information involved, steps individuals should take, what you are doing in response, and contact information. For residents who lack capacity, notice may go to a personal representative.
For breaches affecting 500 or more individuals, notify HHS at the same time as individuals, within 60 days. For breaches affecting fewer than 500, you may log them and report to HHS within 60 days after the end of the calendar year in which they were discovered.
If a breach affects more than 500 residents of a state or jurisdiction, you must also notify prominent media outlets serving that area, within the same 60-day limit.
Many states have their own breach notification laws, with different definitions and timelines. Oklahoma, Texas and Arkansas each have statutes that may apply in addition to HIPAA, so check them with counsel.
A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days. Your agreement can require something faster, and it should. The covered entity generally remains responsible for notifying individuals unless the parties agree otherwise in writing.
The timeline of discovery and response
Your risk assessment and the reasoning behind it
Copies of notices and mailing records
Corrective actions taken
HIPAA documentation generally must be retained for six years.
Name a privacy officer and a backup
Write a short incident procedure that tells staff to report immediately
Prepare template notification letters in advance
Keep contact details for counsel, your insurer and your IT provider
Train staff to report mistakes, such as a misdirected fax, without fear
UnityCare IT helps with the technical side of incidents, including log review, scoping and containment, and can help you build the preparation steps above.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172