When something goes wrong with resident information, whether a lost laptop, a misdirected fax, an employee snooping or a cyberattack, the first question is whether it counts as a reportable breach. The HIPAA Breach Notification Rule sets out how to decide, who to notify and how quickly. This walkthrough is a general explainer, not legal advice. Your attorney and your privacy officer should guide actual decisions, and state laws may add requirements.
Under the rule, a breach is an impermissible use or disclosure of unsecured protected health information that compromises its security or privacy. An impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment.
Two concepts matter here.
Unsecured PHI is information not rendered unusable, unreadable or indecipherable to unauthorized people through methods specified by HHS, namely appropriate encryption or destruction. Properly encrypted data, where the key was not compromised, generally falls outside the notification requirements. This is a major reason to encrypt laptops, phones and backups.
Exceptions exist for certain good-faith, unintentional acquisitions or accesses by workforce members acting within their authority, certain inadvertent disclosures between authorized persons at the same organization, and cases where the recipient could not reasonably have retained the information.
The clock starts when the breach is discovered, which is the first day it is known or, by exercising reasonable diligence, would have been known to the organization. Make sure staff know to report suspected incidents immediately. Contain the problem: retrieve the misdirected document, disable the account, secure the lost device record or disconnect the affected systems. Preserve evidence.
The rule requires you to consider at least these factors:
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
The unauthorized person who used the PHI or to whom the disclosure was made.
Whether the PHI was actually acquired or viewed.
The extent to which the risk has been mitigated, such as through satisfactory assurances that the recipient destroyed the information.
Document your reasoning, the facts you relied on and the conclusion. If you cannot demonstrate a low probability of compromise, you notify.
Individual notice must be provided without unreasonable delay and no later than 60 calendar days after discovery. Sixty days is an outer limit, not a target. Notices are generally sent by first-class mail, or by email if the individual has agreed to electronic notice. They must be written in plain language and include:
A brief description of what happened, including the date of the breach and the date of discovery, if known.
A description of the types of information involved.
Steps individuals should take to protect themselves.
What the organization is doing to investigate, mitigate harm and prevent recurrence.
Contact procedures, including a toll-free number, email address, website or postal address.
If the individual is deceased, notice goes to the next of kin or personal representative if the address is known. For residents with a legal representative, notice generally goes to the representative.
Breaches affecting 500 or more individuals: notify HHS at the same time as individual notices, within the 60-day limit, using the OCR breach portal.
Breaches affecting fewer than 500 individuals: keep a log and submit to HHS no later than 60 days after the end of the calendar year in which the breaches were discovered.
If a breach involves more than 500 residents of a state or jurisdiction, the covered entity must also notify prominent media outlets serving that area, within the same 60-day limit. This is in addition to individual notices.
A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days after discovery, and your contract may require faster notice. This is why BAAs should specify timelines and contacts.
Keep records of the incident, the risk assessment, notices and communications for six years. Then hold a review: what allowed the incident to happen, which safeguards would have prevented it, and what training or technical changes are needed.
Many states, including Oklahoma, Texas and Arkansas, have their own breach notification statutes that may impose different timelines or content requirements, and your insurance policy may require prompt notice to the carrier before you notify others. Check with your attorney.
UnityCare IT helps healthcare organizations prepare incident response plans, encrypt devices and backups, and gather the technical facts needed for a defensible risk assessment. If you do not have a written breach response procedure, we can help you draft the technical portions to go with your privacy officer's process.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034