HIPAA Breach Notification in Practice
The Breach Notification Rule, 45 CFR 164.400 through 164.414, starts from a presumption: an impermissible use or disclosure of protected health information is a breach unless the entity demonstrates a low probability that the information was compromised. That demonstration is the four-factor risk assessment, and it has to be documented whether or not notification follows.
Once a breach is established, three notification duties run in parallel: individuals, the Secretary of HHS, and, for breaches affecting more than 500 residents of a state or jurisdiction, prominent media outlets serving that area. Each has its own content and timing rules, and the clock starts at discovery, defined as the first day the breach is known or, by exercising reasonable diligence, would have been known, to anyone other than the person who committed it.
Business associates must notify the covered entity without unreasonable delay and within 60 days of discovery, and the contract usually shortens that. The covered entity remains responsible for notifying individuals, HHS and the media unless the business associate agreement delegates it.
Key points
Unsecured PHI
PHI that is not rendered unusable, unreadable or indecipherable through a technology or method specified by HHS guidance: encryption consistent with NIST standards, or destruction. A lost encrypted laptop with a protected key is not a reportable breach.
The four factors
The nature and extent of the PHI involved; the unauthorized person who used or received it; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated. All four must be considered and the analysis kept.
Three exceptions
Unintentional good-faith access by a workforce member within their authority; inadvertent disclosure between authorized persons at the same entity; and a good-faith belief that the recipient could not reasonably have retained the information.
Individual notice
Written notice by first-class mail, or email if the individual agreed, without unreasonable delay and no later than 60 calendar days after discovery. Ten or more unreachable individuals trigger substitute notice: a website posting for 90 days or major media, plus a toll-free number.
Notice to the Secretary
For 500 or more individuals, at the same time as individual notice. For fewer than 500, logged and submitted within 60 days after the end of the calendar year in which the breach was discovered.
Law enforcement delay
A law enforcement official's statement that notice would impede an investigation allows delay: for the period stated in writing, or up to 30 days on an oral statement pending a written one.
Common mistakes
Discovery versus confirmation
The 60 days run from when the breach is known or should have been known, not from the end of the forensic investigation. Waiting for a final report routinely blows the deadline.
Encryption at rest versus in use
The safe harbor requires that the data be unreadable to the unauthorized person. A device that was powered on and unlocked when stolen, or credentials that were also compromised, defeats the safe harbor even if the disk is encrypted.
State law versus HIPAA
State breach laws apply alongside HIPAA, often with shorter deadlines, different thresholds and attorney general notice. HIPAA compliance does not satisfy state law.
Sources
;
See it in the live data.
See what other entities changed afterward