LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > The HIPAA Final Rule Is a Game-Changer for Breach Notification

Font Size: increase font decrease font

Previous

  • 1
  • 2
  • 3

Next

The HIPAA Final Rule Is a Game-Changer for Breach Notification

January 28, 2013

  •    
  •    
  •    
  •      
 

When a breach occurs, HHS must be notified within certain prescribed time parameters. For breaches involving over 500 people (large breaches as defined by HHS), the breach must be reported contemporaneously with the notice being provided to the affected patient. For breaches involving under 500 people, the breach must be reported to HHS within sixty (60) days of the last day of the preceding calendar year in which the breach was discovered. After breaches are reported, the reporting healthcare organization usually receives voluminous "voluntary" requests for information about the breach from Office for Civil Rights (OCR), because OCR has enforcement authority of both the Privacy and Security Rules of HIPAA. OCR has been quite active in its enforcement and investigative activity against covered entities such as hospitals, health plans, hospices, physician practices, and health systems; however, BAs have been virtually left alone.

It is anticipated that OCR's approach to investigations will change dramatically when a BA is involved because of the new rules imposing direct liability. BAs should be expecting the type of voluminous requests and detailed investigations that CEs have been involved in since HITECH went into effect in 2009.

BREACH ANALYSIS

The biggest change for everyone is probably the definition of a breach. Prior to the final rule, and up until March 26, a HIPAA/HITECH breach was defined as a use or disclosure that caused a "significant risk of financial, reputational, or other harm." This standard provided CEs with an opportunity to consider the type of harm the affected patient was exposed to as a result of the use or disclosure. For example, a hospital could conclude in most circumstances that disclosure of a patient's tonsillitis diagnosis did not pose a significant risk of any harm. However, disclosure of a patient's HIV status likely did pose a threat of significant harm.

The final rule has changed the definition of a breach. An impermissible use or disclosure of PHI or ePHI is presumed to be a breach unless the CE or BA demonstrates that there is a low probability that the PHI or ePHI has been compromised. HHS reminds us that the burden of proof is on the CE or BA to make this showing. HHS also tells us that this change was made because it believes that breaches were being unreported even though breaches impacting tens of millions of patients have been reported since HITECH.

Reputational harm continues to be a fact-specific inquiry and does not arise solely from the sensitivity of the diagnosis. OCR will look at whether the impermissible use or disclosure adversely affected the patient's employment, standing in the community, or personal relationships.

The final rule specifically requires the probability of harm be assessed by considering at least:

1. The nature and extent of PHI involved.

2. The unauthorized person who used the PHI or to whom the disclosure was made.

3. Whether PHI was actually acquired or viewed.

4. The extent to which the risk to PHI has been mitigated (e.g. assurances from trusted third-parties that the information was destroyed).

Continue reading

Previous

  • 1
  • 2
  • 3

Next



Subscribe to Law Technology News

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • CE
  • British Airways PLC
  • Hitech
  • KPMG LLC
  • Office for Civil Rights
  • United States Department of Health and Human Services

Most viewed stories

    
  1. Big Law Whipped for Poor Tech Training
    •      
  2. 10 Devices You Should Never Take Along on a Business Trip
    •      
  3. Is Stanford Law the New Vortex of Legal Technology?
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. How the Predictive Coding Process Will Affect Paralegals
    •      
  6. Collaboration Is Key to Defending Cyberattacks
    •      
  7. ILTA Study to Gauge New Technologies' Impact on Law Practice
    •      
  8. CEIC: the Destination for Digital Investigation
    •      
  9. Enron Sandbox Stirs Up Private Data, Again
    •      
  10. Cisco E-Book Delivers Ethics on the Go
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Interns? Be Sure to Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

In Tricky Prosecutions, Judges Play Peacemakers

Ropers Majeski Tries to Re-Invent Itself
  •      
    • Subscription Required

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Not Covered for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Firm Takes Another Hit in Bid for 'Unconscionable' Fees

New York's Martin Act Faces Test in Challenge to 2005 Case

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

'Follow That Escapee!'

Judge Who Tossed Defense Counsel Accused of 'Partiality'
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About LTN   |
  • Contact LTN   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media