When a laptop is stolen, an email goes to the wrong person or ransomware hits a server, administrators face an immediate question: is this a reportable breach, and what are the deadlines? The HIPAA Breach Notification Rule sets the framework. This article summarizes the basics so you know what to expect. It is general information, not legal advice, and you should involve your privacy officer and counsel for actual incidents.
Under the rule, a breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule applies to unsecured PHI, meaning PHI that has not been rendered unusable, unreadable or indecipherable to unauthorized persons, for example through proper encryption.
An impermissible use or disclosure is presumed to be a breach unless you can demonstrate a low probability that the PHI has been compromised, based on a risk assessment.
To determine whether a low probability of compromise exists, evaluate at least these factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom the disclosure was made
Whether the PHI was actually acquired or viewed
The extent to which the risk has been mitigated
Document the analysis and the conclusion. If you decide it is not a reportable breach, you need a written record that shows why.
The rule describes limited exceptions, such as good-faith, unintentional access by a workforce member acting within their authority, certain inadvertent disclosures between authorized persons at the same organization, and cases where the recipient could not reasonably have retained the information. Apply these carefully and document your reasoning.
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target. If you know the facts earlier, notice should go out earlier.
A breach is treated as discovered on the first day it is known to the organization, or would have been known by exercising reasonable diligence. Staff members who know about it count, which is why training matters.
For breaches affecting 500 or more individuals, notify the Secretary of HHS at the same time as individual notices, within the 60-day limit. For breaches affecting fewer than 500 individuals, you may keep a log and submit it to HHS no later than 60 days after the end of the calendar year in which the breaches were discovered.
For breaches involving more than 500 residents of a state or jurisdiction, notice to prominent media outlets in that area is also required within the same 60-day period.
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery, unless the contract requires sooner. Your agreements should set shorter timeframes so you have time to act.
Notices to individuals are written in plain language and should describe:
What happened, including the dates of the breach and discovery
The types of information involved
Steps individuals should take to protect themselves
What you are doing to investigate, mitigate harm and prevent recurrence
Contact procedures, including a toll-free number, email address, website or postal address
Oklahoma, Texas, Arkansas and other states have their own breach notification laws, which may set different timelines or include other requirements. Check with counsel about how they apply together with HIPAA.
Name a privacy officer and a security officer, and publish how staff report incidents.
Create a breach response template covering the risk assessment and notices.
Encrypt laptops, phones and backups so lost devices are not unsecured PHI.
Keep contact information for counsel, your insurer and your IT provider on paper.
UnityCare IT supports healthcare organizations with the technical side of incident response, including determining what data was affected and preserving evidence. If you want to review your breach response plan, we are glad to help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172