Privacy Breaches Now Posted on HHS Website
Feb 25th, 10
In compliance with the HITECH Act of 2009, the Office of Civil Rights within the Department for Health and Human Services (HHS) now posts a list of privacy breaches reported to the federal agency by health care providers. To access the list of reported breaches click HERE.
The HITECH Act, enacted within the federal economic stimulus bill in February 2009, requires health care providers to notify HHS of privacy breaches involving unsecured protected health information. Breaches involving less than 500 individuals are reported to HHS annually. Breaches involving 500 or more individuals must be reported to HHS promptly upon discovery via the HHS website. In addition to notifying HHS of breach occurrences, health care providers are also required to provide notice to individuals affected by the breach and in some circumstances the media.
Although HHS implemented an enforcement grace period after federal breach notification were promulgated, the grace period expired on February 22, 2010. Health care providers are subject to fines and penalties for failing to adhere to breach notification requirements.
|