Breach Notification (HIPAA)

Breach Notification (HIPAA)

Breach Notification (HIPAA)

Covered entities must notify affected individuals without unreasonable delay and within 60 days of discovery, notify HHS annually or within 60 days for breaches affecting 500 or more individuals, and notify media for large breaches in a state or jurisdiction.

A risk assessment determines whether an impermissible use constitutes a reportable breach.

Alternative Names:

HIPAA Breach Notification, PHI Breach Notification

Why it Matters?

The risk assessment is where the analysis concentrates, since an impermissible disclosure is presumed to be a breach unless the entity demonstrates a low probability that the information was compromised. Four specified factors govern that assessment and must be documented. Law firms handling protected health information are business associates with notification obligations to the covered entity, which is separate from any state breach statute obligation.

Frequently Confused with

Related terms

Frequently asked questions

Is every impermissible disclosure a breach?

Is every impermissible disclosure a breach?

It is presumed to be unless the entity demonstrates through a documented four-factor risk assessment a low probability the information was compromised.

What are a law firm's obligations?

What are a law firm's obligations?

As a business associate, notification to the covered entity, which is separate from and additional to any state breach statute obligation.