By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    Cognitive Psychology and Risk-taking in Extreme Sports
    Theodore Rex Walrond Highlights the Connection between Cognitive Psychology and Healthcare
    April 1, 2025
    stress management for healthcare workers
    3 Tips For Healthcare Professionals: How To Stay Beautiful, Healthy, and Happy
    November 2, 2021
    importance of relaxing on the weekend for your health
    Importance of Relaxing During the Weekend for Optimal Health
    March 25, 2022
    Latest News
    Beyond Nutrition: Everyday Foods That Support Whole-Body Health
    June 15, 2025
    The Wide-Ranging Benefits of Magnesium Supplements
    June 11, 2025
    The Best Home Remedies for Migraines
    June 5, 2025
    The Hidden Impact Of Stress On Your Body’s Alignment And Balance
    May 22, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    Image
    Person-Centered HealthCare: The FDA Gets Patient-Centric
    May 31, 2013
    Does the Supreme Court Understand Health Reform?
    April 12, 2012
    Racial Health Disparities Among People with Chronic Conditions in the US: Facts and Statistics
    July 25, 2013
    Latest News
    Top HIPAA-Compliant Messaging Apps for Healthcare Teams
    June 25, 2025
    When Healthcare Ends, the Legal Process Begins: What Families Should Know About Probate and Medical Estates
    June 20, 2025
    Preventing Contamination In Healthcare Facilities Starts With Hygiene
    June 15, 2025
    Strengthening Healthcare Systems Through Clinical and Administrative Career Development
    June 13, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: How to Recover from a HIPAA Breach
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Business > How to Recover from a HIPAA Breach
BusinessPolicy & Law

How to Recover from a HIPAA Breach

Abby Norman
Last updated: April 3, 2015 8:00 am
Abby Norman
Share
7 Min Read
SHARE

If you find yourself in the midst of a HIPAA breach, your first instinct might be to panic, but you need not. While a security breach of any kind is a high stress event, keeping cool headed and following tried and true HIPPA breach recovery protocols will help you avoid further trouble down the line.

Contents
Step One: Understanding a HIPPA BreachStep Two: AssessStep Three: NotificationStep Four: Reassess your liability and take actionStep Five: Reevaluate your policies and debrief

If you find yourself in the midst of a HIPAA breach, your first instinct might be to panic, but you need not. While a security breach of any kind is a high stress event, keeping cool headed and following tried and true HIPPA breach recovery protocols will help you avoid further trouble down the line.

How To Recover From a Breach

Step One: Understanding a HIPPA Breach

What defines a HIPPA breach? Any release of information protected under HIPAA that violates the protection standard set forth by the rule. When you think of a breach you probably think of massive security breaches that result in thousands of records being released into the wrong hands — but sometimes breaches occur on a much smaller scale. Just because they only impact one or two patients doesn’t mean they should be regarded with less weight than a numerically larger one.

A textbook example would be mailing test results to the wrong patient or giving someone another patient’s after visit summary at a doctor’s appointment. These things might seem like laughable accidents, but in the wrong hands patient information can quickly become a hotbed of identity theft potential. No breach should be regarded as insignificant.

More Read

travel safely during the pandemic
How to Stay Healthy While Traveling During the Pandemic
Midwifery Training: The Whats and Hows of Birthing Simulators
Former Chicago Bear Contributing Voice to Concussion Policy Change
Important Guidelines for Saving Money on Medications
Data Alone Does Not Make Health Care Pricing Meaningful

Step Two: Assess

The first step after any suspected HIPAA breach is to assess how much information was impacted and compare it to national reporting standards. Typically, if more than 500 patient records are involved, you must notify the public that a breach has occurred. Generally speaking, regardless of the size of the breach — or even the confirmation that a breach has occurred — there must be internal notification up the chain of command within the hospital system itself, usually facilitated by the hospital’s privacy officer (who may or may not be affiliated with the health information department).

Step Three: Notification

In instances where there are clearly identified patients involved, you should begin the process of notifying them via an official letter from your organization without delay. Generally speaking you are allowed 60 days after the breach to make your notifications, but the process should begin as soon as you’ve discovered it. This letter should inform the patient of what occurred, what’s being done by the hospital to rectify it and what the patient should do to protect themselves.

It would be in your hospital’s best interest to offer help wherever you can, particularly in the form of offering the patient something like credit monitoring in order to help reduce the likelihood that your mistake will negatively impact their lives. For any breach involving less than 500 people, you still need to notify DHHS annually.

Step Four: Reassess your liability and take action

If you haven’t purchased regulatory liability insurance, don’t wait. Most plans will cover HIPAA breaches as well as other issues related to compliance, intentional or not. For staff, the intent of the breach (wittingly or unwittingly) will determine in large part the type of disciplinary action they receive.

For example, if a nurse knows that she isn’t supposed to go snooping in her neighbor’s medical record since she isn’t that person’s nurse, but does it anyway, that would warrant disciplinary action far more severe than if a nurse stumbled into the wrong record because she used the wrong birth date and got into a record of a different “Jane Smith” – only to realize her error and report it immediately. Penalties can range anywhere from a few hundred dollars to a few hundred thousand dollars, depending on the nature and size. There are both federal and state penalties, so combining both could be a hefty set of fines for any hospital that’s experienced a breach.

Step Five: Reevaluate your policies and debrief

Since you’ve properly documented the entire process (right?) you can now assess the event from a bird’s eye view with your privacy officer and other pertinent staff members to uncover why the breach occurred and what could have prevented it, if anything.

If you find that there was a flaw, say, in your EMR steps should be taken immediately to patch it. If there are personnel issues, disciplinary action should be taken and in some cases, if there have been multiple offenses, an employee may need to be terminated. If you have experienced a few breaches rather close together, you should be looking to see if there are any patterns or common denominators in the events that could lead you to a culprit.

Most importantly, remember to keep all documentation around the breach and its aftermath for six years after the event occurs. Not only will the records be of value to you in the event of a lawsuit, but as previously mentioned, if there are future breaches you may want to come back to a particular event that seemed somewhat similar and see if you can establish a pattern or link between them.

Knowledge is power, as they say, and when it comes to patient data breaches understanding the why and the how is just as important — if not more so — than the who!

 

The post How To Recover From a HIPAA Breach appeared first on BHM Healthcare Solutions.

TAGGED:HIPAAsecurity
Share This Article
Facebook Copy Link Print
Share
By Abby Norman
My name is Abby Norman and I am a healthcare blogger. With over 10 years of experience in the medical field, I have developed a passion for helping others understand the complexities of healthcare.

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

women dental care
What Is a Smile Makeover and How Much Does It Cost?
Dental health
June 30, 2025
HIPAA-Compliant Messaging Apps
Top HIPAA-Compliant Messaging Apps for Healthcare Teams
Global Healthcare Policy & Law Technology
June 25, 2025
recovering from injury
Rebuilding After Injury: Path to Physical and Emotional Recovery
News
June 22, 2025
scientist using microscope
When Healthcare Ends, the Legal Process Begins: What Families Should Know About Probate and Medical Estates
Global Healthcare
June 18, 2025

You Might also Like

Greedy Insurance Company Backs Down: The Little Guy Wins!

August 15, 2011
hospital marketing sniff test
BusinessHospital Administration

The Marketing “BS Detector” for Doctors and Hospitals

December 7, 2014
Home HealthMedical EducationPublic Health

Smooth Transition: Reducing Senior Readmissions to Hospitals

March 1, 2014

Smart Vending Machines Use Facial Recognition

January 2, 2012
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?