Health Insurance Portability and Accountability Act (HIPAA): Breach Notification Rule
April 2019 Alissa Smith
1
Health Insurance Portability and Accountability Act (HIPAA): Breach - - PowerPoint PPT Presentation
Health Insurance Portability and Accountability Act (HIPAA): Breach Notification Rule April 2019 Alissa Smith 1 Outline of Presentation HIPAA Breach Notification Rule Overview Updates on OCR Enforcement Complaints
1
2
3
4
5
6
7
– No later than 60 days after breach discovery – Delivered by first-class mail
Services – No later than 60 calendar days after breach(es) were discovered
– Breaches involving 500+ residents of a state or jurisdiction all prominent media outlets of the state or jurisdiction – No later than 60 days after breach discoveries
8
9
10
11
12
13
14
15
14% 62% 1% 0% 23% 0%
Theft Hacking/IT Incident Improper Disposal Loss Unauthorized Access/Disclosure Unknown/Other
16
9% 9% 5% 20% 25% 25% 1% 6%
Desktop Laptop Paper/Films Electronic Medical Record Network Server Email Other Portable Electroic Device Other
17
23% 0% 77%
Health Plan Healthcare Clearing House Healthcare Provider
18
19
20
21
22
23
24
25
26
27
28
– 1 in 2017 involving 16,429 individuals – 1 in 2018 involving 1.4 million individuals
– Contact information such as: names, phone numbers, email address, etc. – Billing information such as: insurance information, Medicare numbers, billing numbers, etc. – Health information such as: diagnoses, lab results, medications, etc.
– Invasion of Privacy – Negligent Training and Supervision – Negligence – Breach of Contract
29
30
31
32
33
34
35
36