AUG 3, 2011 12:27pm ET

Related Links

Aetna Beefs Up its Mobile App
May 23, 2012
Hospital Laptop Theft = 2,159 Notifications
May 23, 2012
The Faces of Performance
May 23, 2012
Small Breach includes Social Security Numbers
May 21, 2012
Data Cleansing is a Life Saver
May 21, 2012
FCC Considers New Medical Wireless Spectrum
May 18, 2012
CAHPS Survey Coming to Home/Community Care
May 18, 2012

Web Seminars

Visual Business Intelligence for Healthcare
Available On Demand
The Evolution of Tablet Computing in Healthcare
Available On Demand
Which comes first? Chargemaster Standardization vs. System Conversion
Available On Demand

What Happens After a Data Breach?

Print
Reprints
Email

The federal health care breach notification rule requires HIPAA covered entities-comprising providers, insurers and vendors who must comply with HIPAA transaction sets-to report breaches of protected health information affecting 500 or more individuals to the Department of Health and Human Services' Office for Civil Rights.

OCR posts the breaches to a public Web site. And there have been a lot of postings: by mid-June, 288 listings had filled what is called the "Wall of Shame" in just an 18-month period.

Experts who make their living helping covered entities with the aftermath of a major breach say there are several factoids everyone should keep in mind:

* You'll have a breach if you haven't already. You'll have more than one. While only major breaches get listed on a public Web site, all incidents affecting protected health information must periodically be reported to the feds. As of mid-May there had been 31,000 reports of smaller breaches since September 2009;

* The cost to reduce the risk to protected health information before a breach can be as low as 10 percent of the cost to remediate a medium-sized breach;

* Privacy and security officers, often ignored and unfunded before a breach, suddenly find themselves to be appreciated and getting substantial budgets after a major breach;

* How an organization behaves after a major breach helps determine how well it recovers from the breach;

* Most states have their own breach notification laws that may be different from the federal rule, and many require the reporting of breaches to one or more state agencies, such as the insurance department, health department and/or attorney general; and

* Your breach remediation plan, if you have one, likely is unrealistic.

A feature story in the August issue of Health Data Management examines the steps organizations should take and the challenges they face following a major breach of protected health information.

 

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

Looking to build better care coordination, health systems are buying physician groups in droves. Making the deal work, however, requires careful management on the I.T. front.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.