The Health Insurance Portability and Accountability Act (HIPAA) establishes federal standards for protecting protected health information (PHI). For organizations that handle PHI, maintaining appropriate privacy and security practices is an important part of managing operational and regulatory risk.
A HIPAA breach can happen in a variety of ways, from accidentally sending information to the wrong person to experiencing a cyberattack. Having a response plan in place can help your organization act quickly, limit potential exposure, and meet applicable notification and documentation requirements.
What Is a HIPAA Breach?
Under HIPAA, a breach generally involves the unauthorized acquisition, access, use, or disclosure of PHI that compromises the privacy or security of the information. Examples may include:
- Sending PHI to the wrong recipient
- Losing an unencrypted laptop, phone, or other device containing PHI
- Experiencing a cyberattack that exposes or compromises PHI
- Losing paper records containing PHI
- Improperly disposing of documents containing PHI without securely destroying them
Not every incident involving PHI necessarily constitutes a reportable breach. Organizations should evaluate each incident based on the circumstances and applicable HIPAA requirements.
What Should You Do if You Suspect or Discover a Breach?
If your organization discovers or suspects that PHI has been improperly accessed, used, or disclosed, prompt action is important. Consider the following steps as part of your organization’s incident response process.
Conduct a Risk Assessment
A risk assessment can help determine whether an incident constitutes a reportable breach under HIPAA. The assessment should consider factors such as:
- The nature and extent of the PHI involved
- The individuals or entities that received or accessed the information
- Whether the PHI was actually viewed or acquired
- The extent to which the organization has mitigated the potential risk
Document the assessment and the reasoning behind the organization’s determination.
Document the Incident
Maintain thorough documentation of the incident, investigation, risk assessment, and response. HIPAA requires covered entities and business associates to maintain certain documentation related to HIPAA compliance and breach determinations for six years.
If a vendor, business associate, or third-party administrator is involved, review the applicable agreement to understand each party’s responsibilities for investigating and reporting the incident.
Notify the Appropriate Personnel
Follow your organization’s established incident response procedures and notify the appropriate privacy, compliance, information security, or other designated personnel.
Depending on the circumstances, legal counsel and other professionals may also need to be involved in evaluating the incident and determining appropriate next steps.
Contain the Breach
Take reasonable steps to prevent further unauthorized access or disclosure. The appropriate response will depend on the nature of the incident.
For an electronic incident, this could include disabling compromised accounts or terminating unauthorized access. For a physical disclosure, it may involve retrieving improperly disclosed records or requesting that the recipient return or securely destroy the information.
Investigate the Cause
A thorough investigation can help determine what happened, whether a HIPAA violation occurred, and whether weaknesses in your organization’s processes contributed to the incident.
The investigation may also identify opportunities to strengthen privacy and security controls, update procedures, or provide additional employee training.
Respond Promptly
Timely action can help limit the potential impact of an incident and support compliance with applicable requirements. For reportable breaches, HIPAA generally requires notification to affected individuals without unreasonable delay and no later than 60 days after discovery.
Organizations should not wait until an investigation is complete to begin taking reasonable steps to contain an incident and preserve relevant information.
Take Corrective Action
Once the incident has been investigated, determine whether additional corrective measures are appropriate. Depending on the circumstances, this may include:
- Updating policies and procedures
- Strengthening technical or physical safeguards
- Providing additional employee training
- Reviewing vendor or business associate practices
- Implementing additional monitoring or access controls
- Applying appropriate disciplinary measures under established policies
The goal should be not only to address the immediate incident but also to reduce the likelihood of a similar event occurring again.
Complete Required Notifications
If an incident is determined to be a reportable breach, follow applicable HIPAA notification requirements.
Affected individuals generally must be notified without unreasonable delay and no later than 60 days after discovery of the breach. Breaches affecting 500 or more individuals generally require notification to the U.S. Department of Health and Human Services (HHS) within 60 days, and additional media notification requirements may apply.
For breaches affecting fewer than 500 individuals, covered entities generally must maintain appropriate documentation and report the breaches to HHS in accordance with HIPAA’s requirements for smaller breaches.
Because notification requirements can vary based on the circumstances, organizations should consult their privacy or compliance professionals and legal counsel when appropriate.
Preparing for a HIPAA Breach Before It Happens
Employee training, privacy policies, access controls, and other safeguards can reduce the likelihood of an unauthorized disclosure, but no organization can eliminate every potential risk.
Organizations that handle PHI should regularly review their administrative, physical, and technical safeguards and make sure employees understand their responsibilities for protecting sensitive information. Vendor and business associate relationships should also be reviewed to ensure responsibilities are clearly defined.
A well-developed incident response plan can make it easier to identify, contain, investigate, and report an incident when one occurs.
At Bender, we believe proactive risk management is an important part of protecting an organization’s operations and reputation. Reviewing your insurance program alongside your privacy, cybersecurity, and incident response practices can help identify potential gaps before a loss occurs.
Need help reviewing your organization’s risk management and insurance program? Contact Bender to discuss your exposures and coverage needs.
This article is intended for informational purposes only and should not be interpreted as insurance, legal, or risk management advice.
