HIPAA and the HITECH Act: Get your breach notification ready
HIPAA Weekly Advisor, April 6, 2009
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Covered entities providing notification must adhere to the following guidelines under the Health Information Technology for Clinical and Economic Health:
-
Notices to those directly affected by the breach usually must be sent by first-class mail; an organization may use e-mail if the patient prefers that method of communication, or telephone in an emergency.
-
The notices must contain the following elements:
-
An account of what happened and how the organization discovered it, including dates
-
A description of the affected PHI
-
Guidance on how individuals can protect themselves from problems stemming from the breach
-
A brief description of how the organization is handling the breach to minimize harm and the potential for further breaches
-
Instructions for how individuals can ask questions or receive additional information (including a toll-free number, e-mail address, Web site, etc.) *If a breach involves more than 500 people in one state, the organization must send a notice to local media outlets in the state.
-
Editor’s note: This is an excerpt from a story in the April edition of the HCPro, Inc. newsletter, Briefings on HIPAA.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- HIPAA Q&A: Level of encryption needed for email
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- OB services: Coding inside and outside of the package
- QA:Coding multiple initial infusions
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- CMS has reformulated payments for some bilateral procedures
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched
