HIPAA Breach Notification: Who You Must Tell and When

No administrator wants to discover that resident information was exposed. If it happens, the HIPAA Breach Notification Rule sets specific obligations and deadlines. Knowing the outline in advance makes it far easier to act calmly. This article summarizes the rule in plain language and is not legal advice. Involve your attorney and compliance officer in any actual incident.

What Counts as a Breach

A breach is, in general, an impermissible use or disclosure of protected health information that compromises the security or privacy of the information. The rule presumes an impermissible use or disclosure is a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a documented risk assessment.

That assessment considers at least four factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or to whom it was disclosed

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated

The rule also lists exceptions, including certain unintentional, good-faith access by workforce members acting within their authority, and some inadvertent disclosures between authorized persons at the same organization.

Unsecured PHI

Notification obligations apply to breaches of unsecured PHI, meaning PHI that is not rendered unusable, unreadable or indecipherable to unauthorized persons through methods specified by HHS, namely encryption meeting recognized standards or proper destruction. This is why encrypting laptops and backups matters.

Who Must Be Notified

Affected individuals

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target. Notice is generally by first-class mail, or by email if the individual has agreed to electronic notice. If contact information is out of date for ten or more individuals, a substitute notice, such as a conspicuous website posting or major media notice, is required, and a toll-free number must be provided for at least 90 days.

The notice should describe, in plain language, what happened, the types of information involved, steps individuals should take to protect themselves, what you are doing to investigate and prevent recurrence, and how to contact you.

HHS

For breaches affecting 500 or more individuals, notify HHS contemporaneously with individual notice, and in any case within 60 days of discovery. For breaches affecting fewer than 500, you must log them and report to HHS no later than 60 days after the end of the calendar year in which they were discovered.

The media

For a breach involving more than 500 residents of a single state or jurisdiction, covered entities must also notify prominent media outlets serving that area, within the same 60-day limit.

Business associates

A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your agreements may require faster notice, which is why contract terms matter.

Discovery Date Matters

A breach is treated as discovered on the first day it is known to the organization, or by exercising reasonable diligence would have been known. Waiting to investigate does not stop the clock.

State Laws

Oklahoma, Texas and Arkansas each have their own breach notification statutes, which may include different definitions, timelines or requirements to notify state attorneys general. Texas, for example, has specific requirements for notifying the state attorney general in certain cases. Ask counsel to review the applicable state requirements alongside HIPAA.

Documentation

Keep records of the incident, the risk assessment, decisions made, notices sent and the corrective actions taken. The burden of proof is on the organization to show it met its obligations. Maintain breach documentation for six years.

Prepare Now

Name an incident response lead and a back-up

Keep contact information for counsel, insurer and IT provider on paper

Prepare template notification letters

Train staff to report suspected incidents immediately

How UnityCare IT Can Help

UnityCare IT supports the technical side of incident investigation, such as determining what systems and data were affected, preserving logs and confirming encryption status. For the legal analysis of notification, please consult your attorney.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034