When a breach affecting a significant number of people is reported to the HHS Office for Civil Rights (OCR), the agency may open an investigation. For smaller breaches, it can too. A common early step is a data request: a letter asking the organization to provide documents and information about the incident and about its compliance with HIPAA. Receiving that letter is stressful, and the response deadline is usually short. Organizations that already keep their records organized respond with far less panic.
This post describes what OCR commonly asks for, and how to assemble it. It is general information and not legal advice, so involve your attorney or compliance counsel when you receive a request.
The best time to prepare is before an incident. If you keep your HIPAA documentation current and easy to find, a data request becomes a matter of collecting what you already have. A good habit is to maintain a single, access-controlled folder, a "HIPAA evidence binder," with the key records described below.
Requests vary by case, but they tend to cover the same themes.
A description of what happened, including timeline, discovery date and how it was found.
The number of individuals affected and the types of information involved.
Copies of notices sent to individuals, the media if applicable and HHS.
Documentation of how and when you determined it was a breach, including your risk assessment of the probability that information was compromised.
Steps taken to contain the incident and mitigate harm.
Any forensic reports or findings, which your attorney should help you handle carefully.
Your most recent enterprise-wide security risk analysis, and previous ones.
Your risk management plan and evidence that identified risks are being addressed.
Written HIPAA privacy and security policies and procedures.
Evidence of technical safeguards, such as access controls, audit logging, encryption, backups and multi-factor authentication.
Information security inventories, such as lists of systems that hold electronic protected health information.
Workforce training records, including dates and attendees.
Sanction policies and evidence they are applied.
The name of your designated privacy and security officials.
Your incident response plan and records of testing it.
Information system activity review records, such as log reviews.
Business associate agreements with the vendors involved.
Evidence of how you evaluate and monitor business associates.
Read the request carefully. Note each item, the deadline and the contact at OCR. Calendar the due date immediately.
Notify the right people. Alert your administrator, privacy and security officials, legal counsel, cyber insurer and IT provider. Many insurance policies include counsel and response resources, so contact them early.
Create a response tracker. List each request item, who owns it, where the records are, status and date submitted.
Preserve records. Do not delete or alter documents or logs that could be relevant. Issue a legal hold if advised.
Collect, then review. Gather documents, and have counsel review them before they go out. Make sure what you provide is accurate, complete and the current version.
Be honest about gaps. If a document does not exist, say so and explain what you are doing to address it. Never create backdated documents. Misrepresentation is far worse than a gap.
Ask for more time if needed. Regulators sometimes grant extensions when asked in advance and with good reason, but do not count on it.
Keep copies. Retain a complete copy of what you submitted and when.
Organizations often struggle with the same things:
No recent or complete risk analysis. Under the HIPAA Security Rule, risk analysis is a foundational requirement, so keep it current and review it when systems or operations change.
Policies that exist on paper but do not match practice.
Training records that are incomplete.
Missing or outdated business associate agreements.
Log data that has been overwritten before it could be reviewed.
Unclear documentation of decisions made during the incident.
If you find these in your own organization, they are worth fixing now.
Review your HIPAA binder at least annually. Update your risk analysis, confirm training records, check your vendor agreements and test your incident response plan. During any incident, keep a running log of decisions and times, because it will be useful later.
UnityCare IT helps healthcare organizations keep security documentation current, maintain logs and backups and gather technical evidence when it is needed. We work alongside your counsel and compliance staff. If you would like to check how ready you are, we can help you assess it.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172