Breach Notification
The Health Insurance Portability and Accountability Act (HIPAA) guarantees the privacy and security of patients’ information.
When a PHI breach occurs, HIPAA-covered entities and their business associates are required to notify all affected individuals and the HHS Secretary (online form).
- For violations affecting 500+ individuals – The Secretary must be notified immediately (no later than 60 days after the breach’s discovery).
- For violations affecting fewer than 500 individuals – Covered entities must notify the Secretary within 60 days from the end of the calendar year of the violation.
HIPAA Violations
- Unauthorized access, use, or disclosure of PHI
- IT incidents, malware, and hacking
- Loss or theft of devices
- Accidental mishandling of PHI
Sample
Full Name: [FULL NAME] Title/Role: [TITLE/ROLE]
Signature: Date: [MM/DD/YYYY]
Actual Date of Incident: [DATE OF INCIDENT]
How was the incident discovered? [DESCRIBE DISCOVERY OF INCIDENT]
Describe the Incident: [DESCRIBE THE INCIDENT]
Violator Name (if known): [FULL NAME] Title/Role: [TITLE/ROLE]
Was the violation intentional? ☐ Yes ☐ No
Number of Prior Violations: [#]
PERSONAL HEALTH INFORMATION (PHI)
Do you know the identities of the Patients’ data that was involved? ☐ Yes ☐ No
If yes, how many records? [#]
Have the patients been contacted? ☐ Yes ☐ No
If yes, describe: [DESCRIBE CONTAINMENT MEASURES]
If yes, describe: [DESCRIBE IMPACTED SERVICES]
ADDITIONAL INFORMATION
Is there any other information that should be provided? ☐ Yes ☐ No
If yes, describe: [DESCRIBE ADDITIONAL INFORMATION]