SoundBytes SoundBytes SoundBytes

OCR Shows Reported Unsecured Breaches of PHI Affecting 500 or More Individuals

25. March 2010 09:55
The Department of Health and Human Services Office for Civil Rights (OCR) has begun posting lists of unsecured private health information (PHI) affecting 500 or more individuals that have been reported by covered entities on their Web site. Breach notification requirements were enacted under the HITECH Act (issued as part of the American Recovery and Reinvestment Act of 2009). These requirements issued in August 2009 became effective on September 23, 2009. These requirements call for covered entities to provide notification of unsecured PHI to HHS, affected individuals, and (under certain circumstances) to the media.

Under these requirements, covered entities must report breaches affecting 500 or more individuals to HHS without unreasonable delay and in no case later than 60 days following the breach. The information is to be reported using an online form available on the OCR website.

The HHS is required to make publicly available some of the information from the submitted form, including:

  • Name of covered entity (or business associate involved),
  • State where the covered entity is located,
  • Approximate number of individuals affected,
  • Date of the breach,
  • Type of breach (e.g., theft, unauthorized access), and
  • Location of the breached information (e.g., computer, paper records, portable electronic device).

Click here to view the unsecured private health information (PHI) that covered entities have reported.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

HIPAA


Comments are closed

Powered by BlogEngine.NET 1.1.0.7
Theme by DataPath Marketing Services

Disclaimer: The views and opinions on this blog are those of the author. Nothing contained in this weblog is intended as legal advice. This weblog was created to provide general information, opinions of the author and general musings. Accessing this website is not a consultation for legal advice or services and this weblog does not create an attorney-client relationship.

Search

Type in a keyword or topic (HIPAA, Mandates, etc.)

Calendar

<<  May 2012  >>
MoTuWeThFrSaSu
30123456
78910111213
14151617181920
21222324252627
28293031123
45678910

Contact

Click Here to mail questions or comments to SoundBytes@dpath.com.

Admin Login

DataPath, Inc. © Copyright 2010
Sign in