The HIPAA Breach Notification Rule ensures that covered entities promptly inform individuals when there is a breach of their Protected Health Information (PHI).
The Change Healthcare data breach led to a major disruption of the US healthcare system with many pharmacies and hospitals unable to receive claims and payments. Change Healthcare often acts as a clearing house connecting healthcare providers with insurers, which contributed to the uncertainty about their role in providing breach notifications and delayed notifying the public. The Ascension health system ransomware attack made them unable to provide emergency care because providers were locked out of their system.
Such incidents highlight the necessity of breach notifications to fulfill legal obligations and mitigate cascading impacts on healthcare operations and maintain public trust. Understanding and adhering to these requirements protects individuals and the broader healthcare system.
The U.S. Department of Health and Human Services states, “Following a breach of unsecured protected health information, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media”.
According to The Office of the National Coordinator for Health Information Technology, the following are the consequences of failing to properly notify authorities and affected individuals about a HIPAA breach:
University of Rochester Medical Center (URMC) failed to report breaches involving unencrypted devices multiple times and was fined $3 million. The organization had ongoing issues with device encryption and risk analysis, which compounded the severity of the penalties.
On the other hand, Hot Topic recently faced criticism for failing to notify customers and authorities promptly about a significant data breach, a delay that could lead to legal repercussions and diminished customer trust. The breach, which exposed sensitive information from nearly 57 million accounts, included names, addresses, phone numbers, partial credit card details, and loyalty account information. The stolen data poses substantial risks, such as identity theft, financial fraud, and targeted phishing attacks. Despite the severity of the breach, Hot Topic has yet to fulfill its legal obligations for notification, potentially facing lawsuits and penalties as a result.
Healthcare law experts, Cohen Healthcare Law Group, suggest the following strategies to maintain compliance:
Implement robust data security measures
Conduct regular HIPAA risk assessments
Comprehensive employee training
Establish a breach response and incident management plan
Proactive compliance management
A breach notification should include a description of the breach, the type of data involved, the potential impact, and steps taken to mitigate the breach and prevent future occurrences.
Organizations can prepare by developing a comprehensive incident response plan, regularly training employees, and conducting security audits.
Long-term impacts can include sustained reputational damage, financial losses, and increased scrutiny from regulatory bodies.