A laptop is stolen from a car. A staff member emails a spreadsheet to the wrong recipient. A ransomware attack encrypts a file server. Each of these may be a reportable breach under HIPAA, but not automatically. The Breach Notification Rule sets out how to decide and, if notification is needed, how quickly you must act.
This article is a plain-English overview for administrators and compliance officers. It is not legal advice, and you should involve counsel for actual incidents.
Under the rule, a breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule presumes that an impermissible use or disclosure is a breach unless you can demonstrate a low probability that the PHI has been compromised.
There are a few exceptions, including certain unintentional access by workforce members acting in good faith within their authority and inadvertent disclosures between authorized people within the same organization, as long as the information is not further misused.
To show low probability of compromise, you must assess at least these factors:
The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom it was disclosed
Document your analysis. If you cannot demonstrate low probability, treat it as a breach and notify.
PHI that is properly secured, meaning encrypted according to HHS guidance or destroyed, is not considered unsecured PHI, and the notification requirements generally do not apply if it was exposed. This is a major reason to encrypt laptops, phones, backups and removable media.
A breach is treated as discovered on the first day it is known to the organization, or would have been known with reasonable diligence.
Without unreasonable delay and no later than 60 calendar days after discovery. Sixty days is an outer limit, not a target.
500 or more individuals: notify HHS at the same time as individuals, no later than 60 days after discovery
Fewer than 500 individuals: log the breach and report to HHS within 60 days after the end of the calendar year in which it was discovered
If a breach involves more than 500 residents of a state or jurisdiction, notice must also be provided to prominent media outlets serving that area, within the same 60-day limit.
A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery, unless the contract requires a faster timeline. Many agreements set shorter limits.
Individual notices are written in plain language and generally cover:
What happened and the dates of the breach and discovery
The types of information involved
Steps individuals should take to protect themselves
What you are doing to investigate, mitigate harm and prevent recurrence
How to contact you for more information
Oklahoma, Texas, Arkansas and other states have their own breach notification laws with different definitions and deadlines, and some require notice to state attorneys general. Cyber insurance policies may also require prompt notice to the insurer. Check all applicable requirements at once.
Define who decides whether an incident is a breach
Keep a template for the risk assessment and notification letters
Maintain a breach log, including incidents determined not to be breaches
Train staff to report suspected incidents immediately
Keep contact details for counsel, insurer, IT forensics and a mailing or call-center vendor
Waiting to finish an investigation before starting the clock
Failing to document the risk assessment
Assuming a vendor will handle notification for you
Forgetting that small breaches still need to be logged and reported annually
UnityCare IT supports healthcare teams with incident investigation, log preservation and documentation, which are often the hardest parts of making a defensible breach decision. Having that process ready before an incident makes the timeline far easier to meet.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172