“There's been a breach”.
No one ever wants to hear this, especially in healthcare. A breach of PHI can lead to HIPAA penalties, lawsuits, fines, jail time… basically an organization-wide headache. But let's face it: every organization is going to face a breach at some point. Therefore, understanding the HIPAA Breach Notification Rule could save your organization time and money. You can also safeguard your reputation.
LINKS:
____________________________________________
https://etactics.com/blog/hipaa-breac...
____________________________________________
What is the HIPAA Breach Notification Rule? It is part of the HIPAA law that requires organizations to notify any and all affected individuals about a data breach. They also need to notify the HHS when unsecured PHI has been breached. The OCR investigates these violations but tends to prioritize incidents involving 500 or more patient records.
If a breach affects less than 500 people, the Notification Security rule says that an organization should notify affected individuals within 60 days of discovering the breach. The organization must also notify the HHS within 60 days of the end of the year in which the breach was identified.
If a breach affects over 500 people, an organization needs to notify affected individuals within 60 days. They need to notify the HHS within 60 days of the breach too. Lastly, an organization must notify a major print or broadcast media outlet in the organization’s region within 60 days of the breach.
There are a few exceptions! Some scenarios technically fall under the definition of a breach, but the HHS gives the organization some slack about the situation.
Some exceptions include… unintentionally access or use PHI by an employee, made in good faith and within the scope of their authority… accidental disclosure of PHI between authorized persons… or the organization confidently believes that the person who obtained/accessed the PHI will not retain or compromise the data.
If one of these scenarios happens, the PHI is not considered “breached”. As such, the covered entity does not have to notify the affected parties or HHS under the Breach notification Rule
► Reach out to Etactics @ https://www.etactics.com
►Subscribe: https://rb.gy/pso1fq to learn more tips and tricks in healthcare, health IT, and cybersecurity.
►Find us on LinkedIn: / etactics-inc
►Find us on Facebook: /
#HIPAABreachNotificationRule #HIPAABreach