Deadline to Report 2017 HIPAA Breaches Approaching

January 17, 2018

If you experienced a HIPAA breach that affected fewer than 500 individuals in 2017, the deadline to report that breach to HHS is the end of February. You can submit a breach notice by clicking the link below:

Report a breach affecting fewer than 500 individuals

Be aware that once you begin a breach report on the HHS portal, you cannot save the report and return to it later. Having the breach information readily available makes the submission process easier. If you later discover information to add to your report, you can submit an addendum.

The HIPAA breach notification rule requires covered entities to report breaches of unsecured protected health information to:  

  • affected individuals;
  • the U.S. Department of Health and Human Services (HHS); and
  • the local media (in some cases).

The notice must be sent to individuals as soon as reasonably possible, but no later than 60 days after it was discovered.

The timing of notice to HHS depends on the number of individuals affected by the breach.  If the breach involves 500 or more individuals, the covered entity must notify HHS at the same time it notifies the individuals. If the breach involves fewer than 500 individuals, the covered entity must report the breach to HHS no later than 60 days after the end of the calendar year.

Questions? Contact TMLT’s PDCS team to speak with one of our HIPAA experts.

Previous Presentation
Case Closed: HIPAA and patient privacy
Case Closed: HIPAA and patient privacy

This presentation is a case study based on alleged violations of HIPAA privacy rules.

Next Article
How to Encrypt Your Smartphone

Your mobile phone comes equipped with tools for encryption that take a few minutes to an hour to initiate a...

Request onsite HIPAA training from TMLT staff certified in health care privacy compliance.