No organization plans to have a breach, but every organization that handles protected health information should know what the rules require if one occurs. The HIPAA Breach Notification Rule sets out who must be told, how and by when. Understanding the timelines in advance can prevent mistakes made under pressure.
This article provides a general explanation and is not legal advice. Consult counsel for decisions about a specific incident, and remember that state laws and contracts may impose additional requirements.
Under HIPAA, a breach is generally an impermissible use or disclosure of PHI that compromises its security or privacy. The rule presumes that such an event is a breach unless the covered entity can demonstrate a low probability that the PHI has been compromised, based on a documented risk assessment.
Examples include a lost unencrypted laptop, a ransomware attack, an email sent to the wrong person, an employee looking at records without a work reason and a vendor incident that exposes your residents' information.
The rule lists factors that must be considered when deciding whether there is a low probability of compromise:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
The unauthorized person who used the PHI or to whom the disclosure was made.
Whether the PHI was actually acquired or viewed.
The extent to which the risk has been mitigated.
Document the assessment and the conclusion. If you cannot show a low probability of compromise, treat the event as a reportable breach.
There is a safe harbor for PHI that was properly encrypted according to HHS guidance, since it is considered unsecured only when it is not encrypted or destroyed in the approved ways.
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target, and waiting until day 59 without a good reason can itself be a violation.
A breach is treated as discovered on the first day it is known, or would reasonably have been known, to the organization or to any workforce member or agent other than the person committing it. This means the clock can start when a staff member notices, not only when leadership is informed. Train staff to report immediately.
Notice must generally be sent by first-class mail, or by email if the individual has agreed to electronic notice. It should be written in plain language and include a description of what happened, the types of information involved, steps individuals should take, what the organization is doing and contact information.
500 or more individuals: notify HHS at the same time as individual notice, within the 60-day limit.
Fewer than 500 individuals: you may keep a log and report to HHS within 60 days after the end of the calendar year in which the breaches were discovered.
If a breach affects more than 500 residents of a single state or jurisdiction, the covered entity must also notify prominent media outlets serving that area, within the same 60-day limit.
A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days. Your agreement may require a much shorter period, which is why contract terms matter. The covered entity generally remains responsible for notifying individuals unless the agreement delegates that task.
If a law enforcement official states that notice would impede a criminal investigation, the notification may be delayed for the period specified.
Oklahoma, Texas and Arkansas each have their own breach notification statutes, and they may have different triggers, deadlines and requirements to notify state officials. Ask counsel to review them.
Keep an incident response plan and contact list.
Maintain a breach log and documentation of assessments.
Practice the process in a tabletop exercise.
Make sure vendors know how to reach you.
UnityCare IT supports incident response and the technical investigation that informs breach assessments. If you want to put a plan and contact list in place before you need one, we can help.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034