After the discovery of a data breach, a secure source of communication like HIPAA compliant email can become an invaluable resource for the extensive compliance and recovery processes that follow. When making use of trustworthy HIPAA compliant email platforms like Paubox, the security comes with the assurance that the systems will not be intercepted by threat actors leading to further exploitation.
HIPAA breach notification obligations are triggered when unsecured protected health information (PHI). According to to a U.S. Pharmacist article, “The breach notification regulations were mandated by the Health Information Technology for Economic and Clinical Health Act (HITECH), which was part of the American Recovery and Reinvestment Act of 2009 (ARRA) signed on February 17, 2009—the so-called federal stimulus bill.” A use of PHI considered to be impermissible or not allowed is presumed to be a breach unless the covered entity can show that there is a low probability that the PHI has been compromised, using a four factor risk assessment.
The assessment considers the nature and extent of the PHI was actually acquired or viewed and whether any PHI was actually acquired. If a low probability cannot be proven, notifications must be provided without unreasonable delay and no later than 60 calendar days after the incident. If the breach involves unsecured PHI and affects more than 500 individuals in a state or jurisdiction, the covered entity has to notify a prominent media outlet serving that area.
Otherwise for breaches affecting less than 500 individuals, covered entities only have to maintain a log and notify the HHS annually. As a result of the Omnibus Rule these requirements for breach notification extend to business associates.
HIPAA compliant email platforms protect PHI by providing better data security, access controls, and encryption than any other communication method. Its use also comes with the convenience of familiarity which allows for staff to easily prioritize breach protocols without additional steps. This reduces the risk of further unauthorized access during breach reporting, a time when sensitive details are being shared. It also demonstrates a commitment to protecting client's data privacy and security.
The notice should include specific details, though the search results do not specify the exact information.
An impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity demonstrates that there is a “low probability” that the PHI has been compromised. Physicians must evaluate the severity of improper use or disclosure of PHI by assessing whether the use or disclosure meets HIPAA’s “low probability of compromise” threshold using a 4-factor test.
HIPAA breach notifications must be sent within 60 days from the date of breach discovery. For breaches impacting more than 500 individuals, the notification to the HHS is also 60 days from discovery. For breaches impacting fewer than 500 individuals, notification to the HHS can be made within 60 days of the end of the calendar year in which the breach occurred.