If a breach of unsecured PHI is discovered, the covered entity must follow the Breach Notification Rule.
Who Must Be Notified:
-
Affected Individuals: Notify by mail or email within 60 days of discovering the breach.
-
HHS (Health & Human Services):
-
If fewer than 500 individuals: notify annually.
-
If 500 or more: notify within 60 days.
-
-
Media: For breaches affecting 500+ individuals in a region, local media must be notified.
What Must Be Included in the Notice:
-
Description of the breach
-
Types of information involved
-
Steps individuals should take
-
Actions being taken to investigate and prevent future issues
-
Contact info
Tip: Even small breaches must be documented, even if no notice is required.