Purpose:
Notify individuals, HHS, and media of PHI breaches under §164.404.
Instructions:
Include breach description, PHI involved, and mitigation steps.
Notify affected parties within 60 days of discovery.
Retain breach documentation for six years.
Optional Template:
A breach notification template is available to meet HIPAA reporting standards, including placeholders for incident-specific details.
Purpose:
Standardizes communication of PHI breaches to individuals, HHS, and media outlets, ensuring compliance with §164.404.
Instructions for Use
Distribute Notifications Promptly:
Ensure notifications are sent within the required timeframe after a breach is discovered.Customize as Needed:
Include details specific to the breach and the impacted population.Retain Copies:
Retain copies of all notifications for six years as part of compliance records.
Breach Notification Template
Field | Description |
Breach Description | Summary of the breach, including what happened and when it was discovered. |
Types of PHI Involved | Specify the data types (e.g., Social Security numbers, medical records). |
Steps Taken to Mitigate | Actions taken to minimize harm and prevent future incidents. |
Contact Information | Provide a phone number, email, or address for affected individuals to seek assistance. |
Date of Notification | Specify the date the notification was sent.
|