Misdirected Email or Stolen Laptop: Do You Have to Notify Anyone?

An employee emails the wrong spreadsheet to an outside address. A laptop is stolen. A vendor reports that its systems were accessed. Each raises the same question for an administrator: do we have to notify anyone, and by when? The HIPAA Breach Notification Rule sets the framework. This post gives an overview in plain English. It is not legal advice, so involve your privacy officer and counsel on actual incidents.

What counts as a breach

Under the rule, a breach is an acquisition, access, use or disclosure of protected health information in a way not permitted by the Privacy Rule that compromises the security or privacy of the information. The rule applies to unsecured PHI, meaning information not rendered unusable, unreadable or indecipherable through methods such as proper encryption.

An impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the PHI has been compromised, based on a documented risk assessment.

The four-factor risk assessment

To decide whether a low probability of compromise exists, consider at least:

The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or received the disclosure

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated, such as obtaining assurances that the recipient destroyed it

Document this analysis whether you decide to notify or not.

When the clock starts

A breach is treated as discovered on the first day it is known to the organization, or would have been known by exercising reasonable diligence. It counts if any workforce member or agent, other than the person who committed the breach, knows. That means a staff member noticing a problem can start the clock even if the administrator is not told for days. This is why prompt internal reporting matters.

Notice to individuals

Deadline: Without unreasonable delay and no later than 60 days after discovery. The 60 days is an outer limit, not a target. If you have the facts sooner, notify sooner.

Method: First-class mail to the last known address, or email if the individual has agreed to electronic notice. Urgent situations may call for a phone call in addition.

Deceased individuals: Notify the next of kin or personal representative if the address is known.

Substitute notice: If contact information is out of date for ten or more people, a conspicuous website posting for 90 days or major media notice with a toll-free number is required. For fewer than ten, alternative written, phone or other means can be used.

What the notice must include

A brief description of what happened, including dates of the breach and discovery

The types of information involved

Steps individuals should take to protect themselves

What the organization is doing to investigate, mitigate harm and prevent recurrence

Contact information, including a toll-free number, email address, website or postal address

Write it in plain language.

Notice to HHS

500 or more individuals: Notify HHS at the same time as individuals, without unreasonable delay and within 60 days of discovery, through the HHS online portal. HHS posts these breaches publicly.

Fewer than 500 individuals: Keep a log and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.

Notice to the media

If a breach affects more than 500 residents of a single state or jurisdiction, you must also notify prominent media outlets serving that area, within the same 60-day window.

State laws and contracts

HIPAA is not the only source of obligations. Oklahoma, Texas, Arkansas and other states have their own breach notification laws, which may have different definitions and deadlines, and may require notice to a state attorney general. Contracts with payers, insurers and business associates may also set shorter timelines. Your cyber insurance policy may require prompt notice to the carrier before you engage responders or make certain commitments.

Business associates

If a business associate experiences a breach involving your PHI, it must notify you without unreasonable delay and no later than 60 days after discovery, and your agreement may require faster notice. The covered entity generally remains responsible for notifying individuals, unless it delegates that task by contract. Review your agreements to see what vendors must report and how quickly.

Practical steps now

Name a privacy officer and a backup.

Write a simple incident reporting procedure and tell staff to use it right away.

Keep a template for the four-factor assessment and for notification letters.

Maintain a breach log.

Know your insurer's and counsel's contact information.

Practice with a tabletop exercise.

Getting support

UnityCare IT can help with the technical side of an investigation, such as identifying what was accessed, preserving logs and strengthening controls afterward, in coordination with your privacy officer and counsel. We can also help you prepare a response plan before you need one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172