By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    bowl of vegetable salad
    Raw Foods: benefits and harms
    November 9, 2021
    pros and cons of the keto diet
    Read This Before You Follow the Keto Diet
    May 18, 2022
    spinal cord injuries
    4 Potential Causes of Spinal Cord Injuries (and How to Seek Compensation)
    May 25, 2022
    Latest News
    Beyond Nutrition: Everyday Foods That Support Whole-Body Health
    June 15, 2025
    The Wide-Ranging Benefits of Magnesium Supplements
    June 11, 2025
    The Best Home Remedies for Migraines
    June 5, 2025
    The Hidden Impact Of Stress On Your Body’s Alignment And Balance
    May 22, 2025
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    The key stakeholders involved in improving healthcare policy
    The Key Stakeholders involved in Improving Healthcare Policy
    October 26, 2023
    medical erros avoid
    How to Report Medication Errors and Why It’s Important
    November 17, 2024
    Essential Steps for Developing a Life Care Plan
    Essential Steps for Developing a Life Care Plan
    December 26, 2024
    Latest News
    Top HIPAA-Compliant Messaging Apps for Healthcare Teams
    June 25, 2025
    When Healthcare Ends, the Legal Process Begins: What Families Should Know About Probate and Medical Estates
    June 20, 2025
    Preventing Contamination In Healthcare Facilities Starts With Hygiene
    June 15, 2025
    Strengthening Healthcare Systems Through Clinical and Administrative Career Development
    June 13, 2025
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: How to Recover from a HIPAA Breach
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Business > How to Recover from a HIPAA Breach
BusinessPolicy & Law

How to Recover from a HIPAA Breach

Abby Norman
Last updated: April 3, 2015 8:00 am
Abby Norman
Share
7 Min Read
SHARE

If you find yourself in the midst of a HIPAA breach, your first instinct might be to panic, but you need not. While a security breach of any kind is a high stress event, keeping cool headed and following tried and true HIPPA breach recovery protocols will help you avoid further trouble down the line.

Contents
Step One: Understanding a HIPPA BreachStep Two: AssessStep Three: NotificationStep Four: Reassess your liability and take actionStep Five: Reevaluate your policies and debrief

If you find yourself in the midst of a HIPAA breach, your first instinct might be to panic, but you need not. While a security breach of any kind is a high stress event, keeping cool headed and following tried and true HIPPA breach recovery protocols will help you avoid further trouble down the line.

How To Recover From a Breach

Step One: Understanding a HIPPA Breach

What defines a HIPPA breach? Any release of information protected under HIPAA that violates the protection standard set forth by the rule. When you think of a breach you probably think of massive security breaches that result in thousands of records being released into the wrong hands — but sometimes breaches occur on a much smaller scale. Just because they only impact one or two patients doesn’t mean they should be regarded with less weight than a numerically larger one.

A textbook example would be mailing test results to the wrong patient or giving someone another patient’s after visit summary at a doctor’s appointment. These things might seem like laughable accidents, but in the wrong hands patient information can quickly become a hotbed of identity theft potential. No breach should be regarded as insignificant.

More Read

high quality, low cost healthcare
High Quality, Low Cost HealthCare Video Interview Series: Herbert Ong from Healthentic Talks Corporate Wellness
Wall Street Journal Shames Itself with Health Policy Coverage
Measure What You Manage, With Caveats: Thoughts on Surgeon Ratings
Apple investors say iPhones cause teen depression. Science doesn’t
The Global Eye Tracking System Market Is Expected To Skyrocket In The US

Step Two: Assess

The first step after any suspected HIPAA breach is to assess how much information was impacted and compare it to national reporting standards. Typically, if more than 500 patient records are involved, you must notify the public that a breach has occurred. Generally speaking, regardless of the size of the breach — or even the confirmation that a breach has occurred — there must be internal notification up the chain of command within the hospital system itself, usually facilitated by the hospital’s privacy officer (who may or may not be affiliated with the health information department).

Step Three: Notification

In instances where there are clearly identified patients involved, you should begin the process of notifying them via an official letter from your organization without delay. Generally speaking you are allowed 60 days after the breach to make your notifications, but the process should begin as soon as you’ve discovered it. This letter should inform the patient of what occurred, what’s being done by the hospital to rectify it and what the patient should do to protect themselves.

It would be in your hospital’s best interest to offer help wherever you can, particularly in the form of offering the patient something like credit monitoring in order to help reduce the likelihood that your mistake will negatively impact their lives. For any breach involving less than 500 people, you still need to notify DHHS annually.

Step Four: Reassess your liability and take action

If you haven’t purchased regulatory liability insurance, don’t wait. Most plans will cover HIPAA breaches as well as other issues related to compliance, intentional or not. For staff, the intent of the breach (wittingly or unwittingly) will determine in large part the type of disciplinary action they receive.

For example, if a nurse knows that she isn’t supposed to go snooping in her neighbor’s medical record since she isn’t that person’s nurse, but does it anyway, that would warrant disciplinary action far more severe than if a nurse stumbled into the wrong record because she used the wrong birth date and got into a record of a different “Jane Smith” – only to realize her error and report it immediately. Penalties can range anywhere from a few hundred dollars to a few hundred thousand dollars, depending on the nature and size. There are both federal and state penalties, so combining both could be a hefty set of fines for any hospital that’s experienced a breach.

Step Five: Reevaluate your policies and debrief

Since you’ve properly documented the entire process (right?) you can now assess the event from a bird’s eye view with your privacy officer and other pertinent staff members to uncover why the breach occurred and what could have prevented it, if anything.

If you find that there was a flaw, say, in your EMR steps should be taken immediately to patch it. If there are personnel issues, disciplinary action should be taken and in some cases, if there have been multiple offenses, an employee may need to be terminated. If you have experienced a few breaches rather close together, you should be looking to see if there are any patterns or common denominators in the events that could lead you to a culprit.

Most importantly, remember to keep all documentation around the breach and its aftermath for six years after the event occurs. Not only will the records be of value to you in the event of a lawsuit, but as previously mentioned, if there are future breaches you may want to come back to a particular event that seemed somewhat similar and see if you can establish a pattern or link between them.

Knowledge is power, as they say, and when it comes to patient data breaches understanding the why and the how is just as important — if not more so — than the who!

 

The post How To Recover From a HIPAA Breach appeared first on BHM Healthcare Solutions.

TAGGED:HIPAAsecurity
Share This Article
Facebook Copy Link Print
Share
By Abby Norman
My name is Abby Norman and I am a healthcare blogger. With over 10 years of experience in the medical field, I have developed a passion for helping others understand the complexities of healthcare.

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

women dental care
What Is a Smile Makeover and How Much Does It Cost?
Dental health
June 30, 2025
HIPAA-Compliant Messaging Apps
Top HIPAA-Compliant Messaging Apps for Healthcare Teams
Global Healthcare Policy & Law Technology
June 25, 2025
recovering from injury
Rebuilding After Injury: Path to Physical and Emotional Recovery
News
June 22, 2025
scientist using microscope
When Healthcare Ends, the Legal Process Begins: What Families Should Know About Probate and Medical Estates
Global Healthcare
June 18, 2025

You Might also Like

Poor Need More Financial Services than Rich

April 6, 2011
first is first
BusinessFinanceHospital Administration

First Principle of Enduring Success: Existing Patients First

March 27, 2014
Public Health

Use It or Lose It: The Price of Inactivity

March 26, 2012
Image
Policy & Law

Pregnancy and Autonomy – Just Whose Body is it Anyway?

June 18, 2012
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?