HIPAA Breach Notification Requirements

Video 14 of 28
1 min 20 sec
English
English

In this lesson, we'll go over what happens when PHI is lost, inappropriately shared, or stolen, and review the key requirements outlined in the Breach Notification Rule.

What is the Breach Notification Rule?

The Breach Notification Rule sets clear standards for how organizations must handle potential compromises of Protected Health Information (PHI). If PHI was used or disclosed in a manner not permitted under HIPAA, it is presumed to be a breach unless a thorough risk assessment demonstrates a low probability that the data was actually compromised.

Pro Tip: Your Primary Role as an Employee: Your job is simple: if you know of or suspect a possible breach, report it immediately to your supervisor and privacy officer within the timeframe and guidelines established by your organization's policies.

Breach Notification Requirements & Timelines

Once an incident is determined to be a breach, your organization must follow specific reporting protocols based on the scope and size of the breach:

  • Affected Individuals: Must be notified without unreasonable delay, and no later than 60 days after the breach is discovered.
  • Large Breaches (500+ Individuals): Must be reported to the Department of Health and Human Services (HHS) at the same time affected individuals are notified, as well as to prominent local media outlets in the affected area.
  • Smaller Breaches (Fewer than 500 Individuals): Must be logged and reported to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.

State Laws and Faster Deadlines

The federal 60-day notification window is an absolute outer limit. Many state laws mandate much faster reporting deadlines for security incidents, so organizations must always verify and adhere to the specific privacy rules in the states where affected individuals reside.