Our series is designed to explain best practices about HIPAA compliance, HIPAA settlements, and the various requirements an organization must have in place under the HIPAA Security & Privacy Rules.
When does a HIPAA Breach Affecting Fewer than 500 Individuals Need to be Reported by?
If a breach of unsecured protected health information affects fewer than 500 individuals, a covered entity must notify the Secretary of the breach within 60 days of the end of the calendar year in which the breach was discovered. That makes the reporting date March 1, 2025.
A covered entity is not required to wait until the end of the calendar year to report breaches affecting fewer than 500 individuals; a covered entity may report such breaches at the time they are discovered. The covered entity may report all its breaches affecting fewer than 500 individuals on one date, but the covered entity must complete a separate notice for each breach incident. The covered entity must submit the notice electronically and complete all the fields of the breach notification form.
If your organization needs to report this type of breach notification, here is the link to submit the notification.
Colington Consulting | HIPAA Compliance, Risk Assessment & Management
Allow our team of regulatory experts to assess your organization’s compliance with the HIPAA Security and Privacy Rules, the risk assessment process, and breach notification requirements. We offer customized services to meet specific requirements for your organization, making HIPAA compliance strategies effective and efficient. For a free, initial consultation to see how we can assist your organization, give our office a call at 844.740.7100.