HIPAA violations occur every day. Many are minor or incidental to the operations of a HIPAA-covered entity. These can range from staff members discussing a patient’s protected health information (PHI) in a non-private area to sending patient statements to the wrong address or giving a procedure report to the wrong patient. Fortunately, most of these incidents do not cause actual harm to the person whose PHI was improperly disclosed.
Table of contents
A Covered Entity’s Role in HIPAA Violation Reporting
Despite the lack of harm in many cases, managers and supervisors need to remain vigilant in identifying and minimizing these violations. Reducing unauthorized disclosures can prevent serious breaches that may harm patients. So, how should a HIPAA-covered entity approach the issue of HIPAA violation reporting? A good starting point is understanding key provisions of HIPAA that determine reporting requirements for suspected violations.
Definition of Protected Health Information
PHI is defined as “individually identifiable health information held or transmitted by a covered entity or its business associate in any form or media whether electronic, paper or oral.”
Of course, this definition rests on the definition of individually identifiable health information, or IIHI. The Privacy Rule defines IIHI as information, including demographic data, that relates to:
and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number).
There are some exceptions to this definition of PHI. PHI does not include any personal health information maintained in employment records by a covered entity in its capacity as an employer, and certain education records defined in the Family Educational Rights and Privacy Act (20 U.S.C. §1232g.)
Breach Notification Rules
The interim final HIPAA Breach Notification Rules were originally promulgated in August, 2009, and were updated in 2013. This part of the HIPAA Rules codified the requirements for Covered Entities and Business Associates (BAs) to notify people – and government authorities – of unauthorized disclosures of their PHI.
The Breach Notification rules outline a series of steps Covered Entities (CEs) and their Business Associates (BAs) must take when investigating potential HIPAA violations. These steps range from establishing the date of discovery of a breach to notification of individuals and the Secretary of Health and Human services (HHS) to publicizing information in the media about the breach.
Definition of a Breach of PHI
An important change in the Breach Notification Rules was the introduction the requirement for a risk assessment of the breach of PHI. A risk assessment for a breach of PHI has to include at least four factors.
- The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
- The unauthorized person who used or accessed the PHI or to whom any disclosure has been made.
- Whether the PHI was actually acquired or viewed.
- The extent to which the risk to the protected health information has been mitigated.
If a risk assessment determines that there is a low probability of compromise of the PHI, the Covered Entity and/or Business Associate may conclude that notification to an individual – and to the Office for Civil Rights (OCR) of HHS is not necessary.
Breach Notification to Individuals
When a Covered Entity or Business Associate determines there has been an unauthorized disclosure of PHI with more than a low probability of compromise, the entity is required to send a notification of the breach to the individual. The disclosure communication must be sent within 60 days of the date of discovery, and include:
Communication may be by letter or email, if the person has consented to the use of email for communications that include PHI.
Breach Notification to the Secretary of HHS
The HIPAA Breach Notification Final Rule requires CEs and BAs to provide the Secretary of HHS with notice of breaches of unsecured PHI (45 CFR 164.408). The number of individuals affected by the breach determines when the notification must be submitted to the Secretary. CE must notify the Secretary by visiting the HHS website filling out and electronically submitting a breach report form.
HIPAA Breach affecting 500 or more Individuals
If a breach affects 500 or more individuals, a CE or BA must provide the Secretary with notice of the breach without unreasonable delay and in no case later than 60 days from discovery of the breach. This notice must be submitted electronically.
HIPAA Breach affecting fewer than 500 Individuals
For breaches that affect fewer than 500 individuals, a CE or BA must provide the Secretary with a report annually. All disclosure notifications of breaches occurring in a calendar year must be submitted within 60 days of the end of the calendar year in which the breaches occurred. The notice must be submitted electronically. A separate electronic form must be completed for every breach that has occurred during the calendar year.
When a CE or BA has submitted a breach notification form to the Secretary and discovers that there is additional information to report, the entity can submit an additional form, checking the appropriate box for an updated submission.
HIPAA Violation Reporting and the Office for Civil Rights
In addition to investigating reports from CEs and BAs, the OCR can investigate complaints against Covered Entities and Business Associates submitted by individuals. Filing a complaint is easy using the OCR Portal. The OCR is very sensitive to complaints about lack of timely disclosure after requests for copies of medical records. While an initial complaint may only merit a letter to a CE or BA reminding them of their obligations under the HIPAA rules, multiple complaints about the same issue may even trigger an onsite investigation into the complaints or unauthorized disclosures. When that happens, fines are almost certain to follow.
Employees and Reporting HIPAA Violations
Employees are often the source of suspected HIPAA violations, especially in the era of electronic health records. Employees can sometimes report gossip about each other’s health information as HIPAA violations, even though it may not be actual PHI from a medical record. Employees can also be a source of legitimate information about unauthorized disclosures when they identify breakdowns in systems designed to comply with HIPAA Privacy rules. Many CEs and BAs offer anonymous reporting of employee concerns about a wide range of issues, including reporting HIPAA violations, quality of care concerns or corporate compliance problems. And employees can file a complaint with the Office for Civil Rights directly.
CEs and BAs with lots of employees and extensive electronic systems containing PHI are at significant risk these days. The risks are both from hackers who want to steal and monetize the health information of the US population and from the regulatory agencies that are monitoring the complaints and breaches of privacy. If you are not sure you are doing enough to protect the privacy of the PHI you create or maintain, just read about what providers who have been hacked have done after the intrusion – and do it now! Maybe you can stay off the Office for Civil Rights Wall of Shame. These days, most of the types of breach are hacking/IT incidents!
