This article addresses the kind of analysis required to decide whether breach notification is triggered under the HITECH Act for a given security incident. The bottom line is that not all security incidents trigger notification but the wicked problem remains how to determine the ones that do?
Section 13402 of the HITECH Act by requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.The regulations pertaining to breach notification have been codified in 45 CFR 164 Subpart D and went into effect on September 23, 2009. The final breach notification rule is still pending but it was announced "soon" in March 2011.
If you need tools that will help with your compliance initiatives then check out the HSG Store. Do you need an Internet Lawyer with HITECH / HIPAA experience?
Comments