LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > The HIPAA Final Rule Is a Game-Changer for Breach Notification

Font Size: increase font decrease font

Previous

  • 1
  • 2
  • 3

Next

The HIPAA Final Rule Is a Game-Changer for Breach Notification

January 28, 2013

  •    
  •    
  •    
  •      
 

When a breach occurs, HHS must be notified within certain prescribed time parameters. For breaches involving over 500 people (large breaches as defined by HHS), the breach must be reported contemporaneously with the notice being provided to the affected patient. For breaches involving under 500 people, the breach must be reported to HHS within sixty (60) days of the last day of the preceding calendar year in which the breach was discovered. After breaches are reported, the reporting healthcare organization usually receives voluminous "voluntary" requests for information about the breach from Office for Civil Rights (OCR), because OCR has enforcement authority of both the Privacy and Security Rules of HIPAA. OCR has been quite active in its enforcement and investigative activity against covered entities such as hospitals, health plans, hospices, physician practices, and health systems; however, BAs have been virtually left alone.

It is anticipated that OCR's approach to investigations will change dramatically when a BA is involved because of the new rules imposing direct liability. BAs should be expecting the type of voluminous requests and detailed investigations that CEs have been involved in since HITECH went into effect in 2009.

BREACH ANALYSIS

The biggest change for everyone is probably the definition of a breach. Prior to the final rule, and up until March 26, a HIPAA/HITECH breach was defined as a use or disclosure that caused a "significant risk of financial, reputational, or other harm." This standard provided CEs with an opportunity to consider the type of harm the affected patient was exposed to as a result of the use or disclosure. For example, a hospital could conclude in most circumstances that disclosure of a patient's tonsillitis diagnosis did not pose a significant risk of any harm. However, disclosure of a patient's HIV status likely did pose a threat of significant harm.

The final rule has changed the definition of a breach. An impermissible use or disclosure of PHI or ePHI is presumed to be a breach unless the CE or BA demonstrates that there is a low probability that the PHI or ePHI has been compromised. HHS reminds us that the burden of proof is on the CE or BA to make this showing. HHS also tells us that this change was made because it believes that breaches were being unreported even though breaches impacting tens of millions of patients have been reported since HITECH.

Reputational harm continues to be a fact-specific inquiry and does not arise solely from the sensitivity of the diagnosis. OCR will look at whether the impermissible use or disclosure adversely affected the patient's employment, standing in the community, or personal relationships.

The final rule specifically requires the probability of harm be assessed by considering at least:

1. The nature and extent of PHI involved.

2. The unauthorized person who used the PHI or to whom the disclosure was made.

3. Whether PHI was actually acquired or viewed.

4. The extent to which the risk to PHI has been mitigated (e.g. assurances from trusted third-parties that the information was destroyed).

Continue reading

Previous

  • 1
  • 2
  • 3

Next



Subscribe to Law Technology News

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • CE
  • British Airways PLC
  • Hitech
  • KPMG LLC
  • Office for Civil Rights
  • United States Department of Health and Human Services

Most viewed stories

    
  1. Redacted Emails Ordered Released in Aaron Swartz Case
    •      
  2. Product of the Week: Adobe LeanPrint
    •      
  3. Lexis for Microsoft Office Now Works With Lexis Advance
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. Law Technology News Goin' Mobile With ALM
    •      
  6. Cross This App Off Your To-Do List
    •      
  7. EDRM Remains Vital to E-Discovery
    •      
  8. Judge Opens Toyota's Secrets to Additional Attorneys
    •      
  9. The Duty to Preserve: 'VOOM' One Year Later
    •      
  10. Federal Contractors Face Rising Debarment Threat
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

3-D Printing: The Next Big Thing in IP Law?

Best Legal Departments 2013

News Corp. Hires Ex-Skadden Communications Chief Bush

Law Firm Leaders' Confidence Slipping, Says Survey

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

CEIC: the Destination for Digital Investigation

Using Computer Forensics to Investigate IP Theft

Gibson Dunn Turns Heads as It Climbs Am Law 100 List
  •      
    • Subscription Required

In Executive's Trade Secret Prosecution, a Company's Outsized Role

Rothstein Bankruptcy Trustee Files New Reorganization Plan
  •      
    • Subscription Required

Fla. Bar Wants Disbarment for Former Judge
  •      
    • Subscription Required

Bar Candidate Quits N.Y. Job To Satisfy N.J. Practice Bylaw

Pro Bono Work Proposed as Condition for Bar Admission
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Judge in Stop-and-Frisk Case Relishes Her Independence

Ground Is Shifting in 14-Year Litigation

Third Circuit Rejects NLRB Recess Appointment

Judges Weigh Delaware Court of Chancery's Arbitration Program
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Litigator of the Week: Who Needs a Jury Consultant?
  •      
    • Subscription Required

Sanction Reversed; Filing of Sexually Explicit Chat OKd
  •      
    • Subscription Required

DeKalb Judge Dismisses, Then Recuses

Jury Finds For Attorney In Legal-Mal Case
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • Contact LTN
  • Editorial Guidelines
  • Magazine
  • RSS Feeds
  • LTN Awards
  • Bookstore
  • Site Map
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media