HIPAA Breach Notification Timelines Explained for Administrators

When a laptop is stolen, an email goes to the wrong person or ransomware hits a server, administrators face an immediate question: is this a reportable breach, and what are the deadlines? The HIPAA Breach Notification Rule sets the framework. This article summarizes the basics so you know what to expect. It is general information, not legal advice, and you should involve your privacy officer and counsel for actual incidents.

What counts as a breach

Under the rule, a breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule applies to unsecured PHI, meaning PHI that has not been rendered unusable, unreadable or indecipherable to unauthorized persons, for example through proper encryption.

An impermissible use or disclosure is presumed to be a breach unless you can demonstrate a low probability that the PHI has been compromised, based on a risk assessment.

The four-factor risk assessment

To determine whether a low probability of compromise exists, evaluate at least these factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or to whom the disclosure was made

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated

Document the analysis and the conclusion. If you decide it is not a reportable breach, you need a written record that shows why.

Exceptions

The rule describes limited exceptions, such as good-faith, unintentional access by a workforce member acting within their authority, certain inadvertent disclosures between authorized persons at the same organization, and cases where the recipient could not reasonably have retained the information. Apply these carefully and document your reasoning.

The deadlines

Notice to individuals

Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target. If you know the facts earlier, notice should go out earlier.

A breach is treated as discovered on the first day it is known to the organization, or would have been known by exercising reasonable diligence. Staff members who know about it count, which is why training matters.

Notice to HHS

For breaches affecting 500 or more individuals, notify the Secretary of HHS at the same time as individual notices, within the 60-day limit. For breaches affecting fewer than 500 individuals, you may keep a log and submit it to HHS no later than 60 days after the end of the calendar year in which the breaches were discovered.

Notice to the media

For breaches involving more than 500 residents of a state or jurisdiction, notice to prominent media outlets in that area is also required within the same 60-day period.

Business associates

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery, unless the contract requires sooner. Your agreements should set shorter timeframes so you have time to act.

What the notice must include

Notices to individuals are written in plain language and should describe:

What happened, including the dates of the breach and discovery

The types of information involved

Steps individuals should take to protect themselves

What you are doing to investigate, mitigate harm and prevent recurrence

Contact procedures, including a toll-free number, email address, website or postal address

State laws

Oklahoma, Texas, Arkansas and other states have their own breach notification laws, which may set different timelines or include other requirements. Check with counsel about how they apply together with HIPAA.

Prepare before an incident

Name a privacy officer and a security officer, and publish how staff report incidents.

Create a breach response template covering the risk assessment and notices.

Encrypt laptops, phones and backups so lost devices are not unsecured PHI.

Keep contact information for counsel, your insurer and your IT provider on paper.

Getting help

UnityCare IT supports healthcare organizations with the technical side of incident response, including determining what data was affected and preserving evidence. If you want to review your breach response plan, we are glad to help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172