image_pdfimage_print

New HIPAA Breach Notification Rules

These significant changes affect your practice As of September 23, 2009, all healthcare businesses regulated by HIPAA and any business that offers products or services that use with protected health information (PHI) are required to:

  • Notify patients when health information has been breached;
  • Update their HIPAA policies and procedures; and
  • Train employees what to do if a breach occurs.

The term “breach” is defined in the rules as the acquisition, access, use or disclosure of protected health information, in a manner not permitted under the privacy regulations, which compromises the security or privacy of protected health information. A disclosure or use is a breach if it poses a significant risk of financial, reputation or other harm to the individual.

All breaches to not require notification, therefore, regulated entities and business associates must review the rule to determine whether notification is required.

When Notification Is Required

If notification is required the regulated entity must notify individuals, the media and the Department of Health and Human Services (HHS), as soon as possible, but no later the 60 days after discovery of the breach. When a breach involves 500 or more people, the rules require a regulated entity to notify the Secretary of HHS immediately.

Five Essential Steps Regulated Entities Should Take

Step 1 – Establish Breach Notification Procedures and Update Policies
Step 2 – Amend your HIPAA privacy and security policies to incorporate the requirements of the new rules;
Step 3- Maintain Breach Incident Log to record security breaches.
Step 4 – Train staff regarding the 60-day breach notification date; and
Step 5 – Revise your Business Associate Agreements.