Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we'll go over what happens when PHI is lost, inappropriately shared, or stolen, and review the key requirements outlined in the Breach Notification Rule.
The Breach Notification Rule sets clear standards for how organizations must handle potential compromises of Protected Health Information (PHI). If PHI was used or disclosed in a manner not permitted under HIPAA, it is presumed to be a breach unless a thorough risk assessment demonstrates a low probability that the data was actually compromised.
Pro Tip: Your Primary Role as an Employee: Your job is simple: if you know of or suspect a possible breach, report it immediately to your supervisor and privacy officer within the timeframe and guidelines established by your organization's policies.
Once an incident is determined to be a breach, your organization must follow specific reporting protocols based on the scope and size of the breach:
The federal 60-day notification window is an absolute outer limit. Many state laws mandate much faster reporting deadlines for security incidents, so organizations must always verify and adhere to the specific privacy rules in the states where affected individuals reside.