HIPAA · Domain 5
Breach Notification & Enforcement
About 10% of the exam
What counts as a breach
- Definition
- impermissible use or disclosure of information
- Presumption
- a breach unless you prove otherwise
- Secured data
- encrypted or destroyed to standard
- Exception one
- good faith access within authority
- Exception two
- inadvertent sharing between authorized people
- Exception three
- the recipient could not retain it
- Burden of proof
- sits with the covered entity
The four factor assessment
- Factor one
- nature and extent of information
- Factor two
- who used or received it
- Factor three
- whether it was actually acquired
- Factor four
- how far risk was mitigated
- Conclusion
- notify unless probability is low
- Documentation
- keep the analysis either way
Skipping the four factor analysis is itself a finding, and regulators have penalized entities whose only record was the conclusion
Individual notice
- Without unreasonable delay, sixty days maximum
- Clock runs from discovery, not containment
- First class mail or agreed email
- Describe what happened and what data
- Steps individuals can take now
- What you are doing about it
- Contact details for questions
Media and regulator notice
- Media notice at five hundred residents
- The same sixty day outer limit
- Regulator told promptly for large breaches
- Smaller breaches logged and filed annually
- Annual filing sixty days after year end
- Large breaches appear on a public list
Discovery and the clock
- Discovered when any workforce member knows
- Or when diligence should have found it
- Employee knowledge is imputed upward
- Ongoing snooping dated to pattern discovery
- Oral law enforcement delays are capped
Business associates
- Notify the covered entity without delay
- The sixty day outer limit applies
- Identify affected individuals where possible
- Subcontractors report up the chain
- Contracts may demand faster reporting
The four penalty tiers
- Tier one
- did not know despite reasonable diligence
- Tier two
- reasonable cause, not willful neglect
- Tier three
- willful neglect corrected in thirty days
- Tier four
- willful neglect never corrected
- Per violation
- amounts rise sharply by tier
- Annual cap
- applies per identical violation type
- Criminal referral
- knowing misuse handled by prosecutors
Willful neglect corrected inside thirty days still carries a minimum penalty, so speed lowers the number but does not remove it
Enforcement in practice
- Complaint or compliance review opens
- Investigation and document requests
- Findings shared with the entity
- Voluntary compliance or technical assistance
- Resolution agreement and corrective plan
- Monitoring for one to three years
- Penalties if the plan fails
- Complaints filed within one hundred eighty days
- Most matters close without a penalty
- State attorneys general may also sue
- They must notify the department first
The Omnibus Rule
- Business associates directly liable for compliance
- Subcontractors pulled into the same chain
- Breach presumption replaced the harm test
- Penalty tiers restructured with higher amounts
- Marketing, sale and fundraising tightened
- Notice of privacy practices updated
Improving the outcome
- Report and cooperate without prompting
- Correct quickly and prove it
- Show a current risk analysis
- Offer credit monitoring where sensible
- Sanction the individuals responsible
State law interaction
- Stricter state rules are not preempted
- Different deadlines may run in parallel
- Extra content may be required
- Attorneys general seek injunctions and damages
- Comply with both, not the easier one
Numbers to memorize
- Sixty days
- outer limit for individual notice
- Five hundred
- media and prompt regulator notice
- Sixty days after year end
- deadline for the small breach log
- One hundred eighty days
- window to file a complaint
- Six years
- retention for compliance documentation
- Thirty days
- correction window for willful neglect
- Fifty years
- protection after an individual dies
Reference strip: definition, assessment, notice, penalties, oversight
Definition
- Presumed a breach until disproved
- Three narrow exceptions
- Encryption to standard secures data
Assessment
- Four factors, documented
- Low probability means no notice
- Keep the analysis regardless
Notice
- Individuals within sixty days
- Media at five hundred
- Small breaches logged annually
Penalties
- Four culpability tiers
- Willful neglect costs most
- Criminal cases go to prosecutors
Oversight
- Complaints and compliance reviews
- Corrective plans monitored for years
- States can act too
Quick exam traps
- Trap: Every impermissible disclosure must be reported to the individuals
- Trap: The sixty day clock starts when the investigation concludes
- Trap: Breaches under five hundred records need no reporting at all
- Trap: Encryption of any strength removes the notification duty
- Trap: A business associate notifies affected individuals directly
- Trap: Correcting willful neglect within thirty days avoids any penalty
- Trap: State breach notification laws are preempted by the federal rule
cybercertprep.com · original revision sheet written from the public body of knowledge