A “breach” is defined as an impermissible use or disclosure that compromises the privacy or security of PHI. HIPAA covered entities (most health care providers) must give notice to patients and to the U.S. Department of Health and Human Services (HHS) if the covered entities discover that they have breached HIPAA rules regarding “unsecured” protected health information (PHI). When the breach affects more than 500 persons, covered entities must also provide notice to prominent media outlets in the area. In addition, business associates must notify covered entities if a breach occurs at or by the business associate. The notice must be given to patients within 60 days of discovering the breach.
Generally, “unsecured” PHI means PHI that is not encrypted to government standards. If you lose PHI that has been encrypted to government standards, there is no breach.
Keep reading with an ICS membership
This in-depth guidance is reserved for ICS members. Join the Illinois Chiropractic Society for full access to every article, CEU, compliance tool, and advocacy update.
















