March 1st HIPAA Breach Report Deadline to HHS
The March 1st HIPAA Breach Report Deadline is fast approaching. The HIPAA Breach Notification Rule requires health care providers to report breaches of unsecured protected health information (PHI) within 60 days from the end of the calendar year to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR).
The Rule applies to Covered Entities (CEs) such as doctors, insurance companies, and clearing houses that have had breaches affecting fewer than 500 individuals. This is considered a Minor Breach. Meaningful Breaches–those affecting more than 500 individuals–must be reported within 60 days of the breach occurring.
All minor breaches which occurred in 2016 must be reported by this March 1st deadline.
OCR has a dedicated site that you can visit to report these breaches. Below, we’ve included some information for behavioral health specialists about what OCR is looking for.
Who Needs to Report?
HIPAA regulation defines a covered entity as any health plan, health care clearinghouse, or health care provider that transmits “any information in an electronic form in connection with a transaction for which HHS has adopted a standard.” This includes, for the most part, MDs, clinicians, psychologists, therapists, nursing homes, and behavioral health specialists that handle PHI.
If your organization has had a data breach of any size in 2016, and you meet any of the above requirements, you must visit OCR’s site to report before March 1st.
What Needs to be Reported and When?
HHS has several requirements that determine what should be reported and when. Typically, it’s decided by the number of individuals who were affected by a given breach.
– Individuals affected by a breach should be notified within 60 days of the discovery of the breach.
– CEs must document minor breaches of fewer than 500 individuals’ unsecured PHI and report them to HHS annually. This annual report needs to be given to HHS within 60 days of the end of the previous calendar year–this is the deadline that’s approaching on March 1st.
– CEs must document meaningful breaches of more than 500 individuals’ unsecured PHI and report them to HHS within 60 days of the discovery of the breach. State media outlets need to be notified as well if the breach has affected 500 of more residents of a single state no later than 60 days of the discovery of the breach.
In the aftermath of OCR’s first fine in the history of HIPAA enforcement for improper compliance with the Breach Notification Rule, behavioral health specialists and health care professionals of all varieties should ensure that they report their minor breaches to OCR by this March 1st deadline.
Compliancy Group gives behavioral health professionals confidence in their HIPAA compliance with Breach Notification management through The Guard™. The Guard is a web-based HIPAA compliance solution, built by former auditors to help simplify compliance.
Compliancy Group’s team of expert Compliance Coaches™ field questions and guide users through the implementation process, taking the stress out of managing compliance. If a breach occurs, users can contact their Coach for a step-by-step walkthrough of the notification and remediation process–ensuring that patients are notified and proper federal protocol is followed.
With The Guard, behavioral health professionals can focus on running their practice while keeping their patients’ data protected and secure.
Find out more about how Compliancy Group can help simplify your HIPAA compliance today!