• Connect
  • Bookmark Us
  • AF Twitter
  • AF YouTube
  • AF LinkedIn
  • Subscribe
  • Subscription Link
Arent Fox
  • Firm

    • History

    • Awards & Recognitions

    • Diversity

      • Overview
      • Diversity Scholarship
      • Employees on Diversity
      • LGBT Initiative
      • Women’s Leadership Development Initiative
    • Alumni

    • Pro Bono

      • Overview
      • Current Pro Bono Work
      • Community Involvement
      • Pro Bono Newsletter
      • Pro Bono Awards & Honors
      • FAQ: Pro Bono & Working at Arent Fox
    • Leadership

      • Firm Management
      • Administrative Leadership
  • Deals & Cases

  • People

  • Practices & Industries

    • Practices

      • Advertising, Promotions & Data Security
      • Government Relations
      • Antitrust & Competition Law
      • Health Care
      • Appellate
      • Insurance & Reinsurance
      • Bankruptcy & Financial Restructuring
      • Intellectual Property
      • Commercial Litigation
      • International Trade
      • Communications, Technology & Mobile
      • Labor & Employment
      • Construction
      • Municipal & Project Finance
      • Consumer Product Safety
      • OSHA
      • Corporate & Securities
      • Political Law
      • ERISA
      • Real Estate
      • Environmental
      • Tax
      • FDA Practice (Food & Drug)
      • Wealth Planning & Management
      • Finance
      • White Collar & Investigations
      • Government Contractor Services
    • Industries

      • Automotive
      • Energy Law & Policy
      • Fashion, Luxury Goods & Retail
      • Government Real Estate & Public Buildings
      • Hospitality
      • Life Sciences
      • Long Term Care & Senior Living
      • Media & Entertainment
      • Medical Devices
      • Nonprofit
      • Sports
  • Newsroom

    • Alerts

    • Events

    • Media Mentions

    • Press Releases

    • Social Media

    • Subscribe

  • Careers

    • Lawyers

    • Law Students

    • Professional Staff

  • Contact

    • Washington, DC

    • New York, NY

    • Los Angeles, CA

    Alerts

    • Newsroom Overview
      • Alerts

        Alerts by Criteria

        E.g., 1 / 21 / 2013
        E.g., 1 / 21 / 2013
      • Events
      • Media Mentions
      • Press Releases
      • Social Media
      • Subscribe

    You are here

    Home » Newsroom » Alerts

    Share

    • Printer-friendly version
    • Send by email
    • A Title
    • A Title
    • A Title
    • A
    • A
    • A

    New HIPAA Requirements: Individuals Must Be Notified of Breaches of Their Health Information

    August 28, 2009

    This week the US Department of Health and Human Services (HHS) issued new regulations requiring entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when a breach of their health information occurs.  As part of the 2009 economic stimulus legislation, Congress passed the Health Information Technology for Economic and Clinical Health (HITECH) Act, requiring HHS to issue breach notification rules.  These new regulations are effective September 23, 2009.  HHS, however, has stated in response to concerned commenters that the government will not enforce the penalties for any failure to provide proper notification for any breaches that occur prior to February 22, 2010.

    The new rules require health care providers and any entities covered under HIPAA to notify affected individuals after a breach of unsecured protected health information (PHI).  In addition, a business associate of a covered entity must notify the covered entity when it discovers a breach of such information so that the covered entity may take appropriate steps to notify affected individuals.  According to the rules, a “breach” includes any unauthorized “acquisition, access, use or disclosure” of PHI which compromises the security or privacy of that information.  However, the rules provide several types of disclosure as exceptions to this definition.  For example, it is not considered a breach if the recipient of the information would not have had enough time to retain the information.

    After a breach is discovered, the covered entity must notify the affected individuals within a reasonable time, but in no case later than 60 calendar days.  If the breach affects fewer than 500 individuals, the covered entity must maintain a log of the breach and subsequent notification for submission to the Secretary of HHS on an annual basis.  If the breach affects more than 500 individuals, however, the covered entity must notify the Secretary of HHS immediately and inform prominent regional media of the breach. 

    Any entity with properly secured PHI does not need to comply with these notification requirements when a breach occurs.  In order for covered entities to determine when information is considered “secured,” HHS is issuing new guidance detailing encryption and destruction to secure PHI properly.  This guidance will specify the technologies and processes covered entities may use to ensure the PHI is unusable, unreadable or indecipherable to unauthorized individuals.  HHS plans to update this guidance annually.

    For more information about compliance with the HIPAA breach notification requirements, please contact the author or another Arent Fox attorney.

    Related People

    • Lisa A. Estrada

    Related Practices

    Commercial Litigation
    Health Care
    • Firm
    • Deals & Cases
    • People
    • Practices & Industries
    • Newsroom
    • Careers
    • Contact

    Footer Main

    • Firm
    • Deals & Cases
    • People
    • Practices & Industries
    • Newsroom
    • Careers
    • Subscribe
    • Alumni
    • Diversity
    • Legal Notice
    • Privacy Policy
    • Social Media Disclaimer
    • Nondiscrimination
    • Site Map
    • Client/Staff Login

    Offices

    • Washington, DC
      1717 K Street, NW
      Washington, DC 20036
      Tel: 202.857.6000
    • New York, NY
      1675 Broadway
      New York, New York 10019
      Tel: 212.484.3900
    • Los Angeles, CA
      555 West Fifth Street, 48th Floor
      Los Angeles, California 90013
      Tel: 213.629.7400
    • © Copyright 2013 Arent Fox LLP. All Rights Reserved.

      Legal Disclaimer
      Contents may contain attorney advertising under the laws of some states. Prior results do not guarantee a similar outcome.