Deadline to Report 2017 HIPAA Breaches Approaching

January 17, 2018

If you experienced a HIPAA breach that affected fewer than 500 individuals in 2017, the deadline to report that breach to HHS is the end of February. You can submit a breach notice by clicking the link below:

Report a breach affecting fewer than 500 individuals

Be aware that once you begin a breach report on the HHS portal, you cannot save the report and return to it later. Having the breach information readily available makes the submission process easier. If you later discover information to add to your report, you can submit an addendum.

The HIPAA breach notification rule requires covered entities to report breaches of unsecured protected health information to:  

  • affected individuals;
  • the U.S. Department of Health and Human Services (HHS); and
  • the local media (in some cases).

The notice must be sent to individuals as soon as reasonably possible, but no later than 60 days after it was discovered.

The timing of notice to HHS depends on the number of individuals affected by the breach.  If the breach involves 500 or more individuals, the covered entity must notify HHS at the same time it notifies the individuals. If the breach involves fewer than 500 individuals, the covered entity must report the breach to HHS no later than 60 days after the end of the calendar year.

Questions? Contact TMLT’s PDCS team to speak with one of our HIPAA experts.

Previous Article
Law requires Texas physicians to query PMP before prescribing opioids
Law requires Texas physicians to query PMP before prescribing opioids

Texas physicians will soon be required to check the Texas Prescription Monitoring database before prescribi...

Next Article
Allscripts EHRs fall victim to ransomware attacks

EHR company Allscripts is still working to recover from a ransomware attack on Thursday, January 18, affect...