A laptop is stolen from a car. A staff member emails a spreadsheet to the wrong person. A ransomware attack encrypts a file server. Each of these may be a breach of protected health information, and each triggers questions about what you must do, how quickly and for whom.
The HIPAA Breach Notification Rule answers many of those questions. This overview is intended for administrators and compliance leads and is general information, not legal advice. Always consult qualified counsel for a specific situation.
Under the rule, a breach is generally an impermissible use or disclosure of protected health information that compromises its security or privacy. Importantly, such an event is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the information was compromised, based on a documented risk assessment.
There are also a few exceptions, such as certain unintentional access by a workforce member acting in good faith, or inadvertent disclosures between authorized people within the same organization, as long as the information is not further misused.
To decide whether notification is required, evaluate at least these factors:
The nature and extent of the information involved, including how sensitive it is and the likelihood it could identify someone
The unauthorized person who used or received the information
Whether the information was actually acquired or viewed
The extent to which the risk has been mitigated, for example through assurances that data was destroyed
Document the analysis and your conclusion. If you cannot show a low probability of compromise, notification is generally required.
The notification requirement applies to unsecured protected health information, meaning information that has not been rendered unusable, unreadable or indecipherable to unauthorized people. Properly encrypted data, or data that has been destroyed according to federal guidance, generally falls outside the notification requirement. This is one strong reason to encrypt laptops, tablets and backups.
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. A breach is treated as discovered on the first day it is known, or would reasonably have been known with reasonable diligence. Notices are generally sent by first-class mail, or by email if the individual has agreed to electronic notice. The notice should include, in plain language:
What happened, including the dates of the breach and discovery
The types of information involved
Steps individuals should take to protect themselves
What the organization is doing to investigate and prevent recurrence
Contact information for questions
Sending notices to a resident's personal representative or next of kin may be necessary in a care setting.
Breaches affecting 500 or more individuals: notify HHS without unreasonable delay and no later than 60 days after discovery.
Breaches affecting fewer than 500 individuals: log them and submit the information to HHS annually, within 60 days after the end of the calendar year in which the breaches were discovered.
For breaches involving more than 500 residents of a state or jurisdiction, covered entities must also notify prominent media outlets serving that area, within the same 60-day outer limit.
A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days. Your contract may require sooner notice, which is why breach reporting terms in your agreements matter.
HIPAA is not the only rule. Oklahoma, Texas and Arkansas each have their own breach notification laws with their own requirements, and some involve notifying a state attorney general. Contracts with payers, insurers and corporate partners may add more. Your cyber insurance policy may require immediate notice to the carrier. Legal counsel can help sort through the overlapping rules.
Write a breach response procedure and name the people responsible
Train staff to report incidents immediately, since the clock can start when anyone in the organization knows
Keep a breach log and documentation for six years
Keep template notification letters ready for review by counsel
Know how to quickly identify affected residents
Most breach notifications start with preventable events. UnityCare IT can help you strengthen safeguards such as encryption and access controls, and can support investigation and documentation when something goes wrong.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172