When a laptop goes missing, a staff member emails the wrong resident's records or ransomware encrypts a server, the first question is often, do we have to report this? The HIPAA Breach Notification Rule answers it, and the answer depends on a structured assessment rather than a gut feeling.
This explainer outlines how the rule works. It is general information, not legal advice, and any real incident should involve your privacy officer and qualified counsel.
Under the rule, a breach is an acquisition, access, use or disclosure of protected health information in a way not permitted by the Privacy Rule that compromises the security or privacy of the information. Importantly, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate a low probability that the information has been compromised.
That presumption is why documentation matters so much.
To show a low probability of compromise, a covered entity weighs at least four factors.
The nature and extent of the information involved, including the types of identifiers and the likelihood that someone could be identified
The unauthorized person who used the information or to whom it was disclosed. For example, another covered entity bound by HIPAA is lower risk than an unknown outsider.
Whether the information was actually acquired or viewed. A lost device later recovered with forensic evidence that files were never opened is different from one that vanished.
The extent to which the risk has been mitigated, such as obtaining assurances that the recipient destroyed the information
Record the assessment in writing, including who performed it, the facts reviewed and the conclusion.
The rule applies to unsecured protected health information. Information that has been encrypted according to HHS guidance, or destroyed properly, is considered secured, and its loss generally does not trigger notification. This is a major reason to encrypt laptops, phones and backups.
If the assessment concludes a breach occurred, notification duties follow.
Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered. Notice is typically by first-class mail, or by email if the person has agreed to electronic notice. The notice must describe what happened, the types of information involved, steps individuals should take, what the entity is doing, and how to contact it.
For breaches affecting 500 or more individuals, the covered entity must notify HHS at the same time as individuals. For breaches affecting fewer than 500, entities must log them and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.
Breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets in that area.
A business associate must notify the covered entity of a breach without unreasonable delay and within 60 days of discovery, though contracts often require much faster notice.
The 60-day period begins when the breach is discovered, or would have been discovered by exercising reasonable diligence. Waiting to investigate does not stop the clock, and 60 days is an outer limit, not a target.
Oklahoma, Texas and Arkansas each have their own data breach notification laws that may apply alongside HIPAA, sometimes with different triggers or deadlines. Counsel can help sort out which apply.
Name a privacy officer and a security officer, and publish how staff should report suspected incidents
Train staff to report mistakes quickly without fear of blame
Keep a template for the four-factor assessment
Maintain a log of all incidents, including those judged not to be reportable
Encrypt devices and backups
Know your cyber insurance and legal contacts before you need them
Our team can help gather the technical facts for a risk assessment, such as device encryption status and access logs, and help you build reporting procedures so your staff know exactly what to do.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172