Get certified in HIPAA for just $29.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
So what happens if PHI is lost, inappropriately shared, or stolen? That is what the Breach Notification Rule covers. Your job is simple: if you know of or suspect a possible breach, report it to your supervisor and privacy officer within the timeframe and following the policies and procedures your organization has set. From there, your organization determines whether the incident is a breach. If PHI was used or shared in a way HIPAA does not allow, it is treated as a breach unless a risk assessment shows there is a low chance the information was actually compromised. If it is a breach, the affected individuals must be notified without unreasonable delay, and no later than 60 days after the breach is discovered. Breaches affecting 500 or more people also have to be reported to the Department of Health and Human Services at the same time the individuals are notified, and to local media in the affected area. Smaller breaches, affecting fewer than 500 people, are logged and reported to HHS no later than 60 days after the end of the calendar year in which they were discovered. One important note: that 60-day deadline is a federal outer limit. Many states require faster notice, so always check the rules in the states where the affected individuals live.
In this lesson, we'll go over what happens when PHI is lost, inappropriately shared, or stolen, and review the key requirements outlined in the Breach Notification Rule.
The Breach Notification Rule sets clear standards for how organizations must handle potential compromises of Protected Health Information (PHI). If PHI was used or disclosed in a manner not permitted under HIPAA, it is presumed to be a breach unless a thorough risk assessment demonstrates a low probability that the data was actually compromised.
Pro Tip: Your Primary Role as an Employee: Your job is simple: if you know of or suspect a possible breach, report it immediately to your supervisor and privacy officer within the timeframe and guidelines established by your organization's policies.
Once an incident is determined to be a breach, your organization must follow specific reporting protocols based on the scope and size of the breach:
The federal 60-day notification window is an absolute outer limit. Many state laws mandate much faster reporting deadlines for security incidents, so organizations must always verify and adhere to the specific privacy rules in the states where affected individuals reside.