HIPAA Tip: Steps That Must Be Taken After a Breach
Understanding HIPAA Breach Notification Requirements
When your organization suffers a HIPAA Breach affecting 500 individuals or more there are numerous steps that must be taken as soon as possible once the breach has been discovered, but no later than 60 calendar days after the discovery of the breach.
- Timeline: Must notify within 60 calendar days of breach discovery
- Definition: Impermissible use/disclosure compromising PHI security or privacy
- Individual Notice: Written notice by mail or email (if agreed to electronically)
- Media Notice: Required for breaches affecting 500+ residents in a state
- HHS Notice: Submit breach report form electronically to HHS Secretary
- Business Associates: Must notify Covered Entity within 60 days of discovery
What Constitutes a HIPAA Breach
Definition of a Breach: an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of Protected Health Information (PHI). Covered Entities and Business Associates must only provide the required notifications if the breach involved unsecured PHI.
Breach Notification Requirements
Individual Notice
Covered Entities must notify affected individuals following the discovery of a breach of unsecured PHI. Covered Entities must provide this individual notice in written form by first-class mail, or alternatively, by e-mail if the affected individual has agreed to receive such notices electronically. If the Covered Entity has insufficient or out-of-date contact information for 10 or more individuals, the Covered Entity must provide substitute individual notice by either posting the notice on the home page of its web site for at least 90 days or by providing the notice in major print or broadcast media where the affected individuals likely reside.
Media Notice
Covered Entities that experience a breach affecting more than 500 residents of a State or jurisdiction are, in addition to notifying the affected individuals, required to provide notice to prominent media outlets serving the State or jurisdiction. Covered Entities will likely provide this notification in the form of a press release to appropriate media outlets serving the affected area.
Notice to the Secretary
In addition to notifying affected individuals and the media (where appropriate), Covered Entities must notify the Secretary of breaches of unsecured protected health information. Covered entities will notify the Secretary by visiting the HHS web site and filling out and electronically submitting a breach report form.
Notification by a Business Associate
If a breach of unsecured PHI occurs at or by a Business Associate, the Business Associate must notify the Covered Entity following the discovery of the breach. A Business Associate must provide notice to the Covered Entity without unreasonable delay and no later than 60 days from the discovery of the breach.
Submit a Breach Notification to the HHS Secretary
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.