Businessolver
Businessolver Blog

H&W HIPAA Breach Notification: Deadline Quickly Approaching

Get the Businessolver Blog in your inbox
Compliance Dashboard profile photo
By Compliance Dashboard
 on February 22, 2018
Share:

The HIPAA Breach Notification Rule requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information. ย In addition to notifying affected individuals and the media (where appropriate), covered entities must notify the Secretary of breaches of unsecured protected health information. Covered entities will notify the Secretary by visiting the HHS web siteย and filling out and electronically submitting a breach report form.ย If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach. If, however, a breach affects fewer than 500 individuals (โ€œsmall breachesโ€), the covered entity may notify the Secretary of such breaches on an annual basis.

Deadline for Small Breach Notifications

Reports of breaches affecting fewer than 500 individuals are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered.ย  With this in mind, small breaches that occurred in 2017 need to be reported by March 1, 2018.