Friday, September 11, 2009

HIPAA: HHS Issues Rule Requiring Individuals Be Notified of Breaches of Their Health

The breach notification notice of proposed rule making requires HIPAA covered agencies to give notification to affected individuals of breaches of unsecured protected health information (PHI). Business associates of HIPAA covered agencies are required to notify the agency following discovery of a breach of unsecured protected health information maintained by the business associate. The requirement for breach notification applies only to breaches of “unsecured protected health information,” which means PHI that has not been secured by use of a technology or methodology specified in guidance of the Secretary of HHS. That guidance essentially requires encryption or destruction of the PHI. The rule is effective September 23, 2009. However, HHS specifically states, "...we will use our enforcement discretion to not impose sanctions for failure to provide the required notification for breaches that are discovered before 180 calendar days from the publication of this rule, or February 22, 2010. During this initial time period - after this rule has taken effect but before we are imposing sanctions - we expect covered entities to comply with this subpart and will work with covered entities, through technical assistance and voluntary corrective actions, to achieve compliance." ANCOR is working to develop products and other information to assist members with this new development.