
Explore HIPAA and HITECH pathway to compliance, a four-part series that explains Part 2: drafting complaint and breach report processes with templates, checklists, and guidance for monitoring and remediation.
Explore health information management practices for documenting, investigating, and reporting HIPAA and HITECH complaints and breaches, with privacy and security officers guiding PHI protection.
This case study illustrates the complaint and breach report process, detailing four individuals who requested access to their medical records and filed complaints with HHS after no response within 30 days.
Learn how to establish a compliant complaint management process under HIPAA and HITECH. Understand rights to PHI, timely investigations, six-year record retention, and OCR or HHS oversight.
Learn from Cignet Health's failed response to patient access requests and OCR cooperation, and note the $4.3 million penalty and need for breach reports and privacy and security officers.
Examine how an unencrypted disk containing the PHI of more than 5,000 clients went unreported for nearly six months, breaching privacy procedures under HIPAA and HITECH.
Explore the breach report and investigation process under HIPAA and HITECH, including PHI definitions, exceptions, risk assessment, and mandatory patient, HHS, FTC, and state attorney general notifications.
Health Net's delayed notification underscores enforcing 24-hour reporting of missing PHI and ePHI-containing equipment to privacy or security officers, with sanctions, retraining, and policy revisions.
Implement a HIPAA/HITECH compliance plan through ongoing workforce training to prevent sanctions, emphasizing case studies and the protection of PHI across covered entities and business associates.
An emergency room physician posts ER encounters on Facebook, sharing times, dates, and services for instruction, with colleagues and patients having access, illustrating a HIPAA and HITECH breach risk.
Examine a Rhode Island physician posting ER encounters on a Facebook page, risking phi exposure and reprimand, underscoring need for social media policies for covered entities and business associates.
Case study describes South Hospital shipping three boxes with 473 unencrypted backup tapes for erasure and resale, containing 800,000 individuals' PHI, without informing data solutions company; only one box arrived.
Case 4 shows a breach where unencrypted PHI on backup tapes shipped off-site for erasure, and a consent judgment enforcing HIPAA regulations and business associate contracts.
Case study 5 shows a hospital employee leaving a message with the patient's daughter that reveals mother's medical condition and treatment plan, calling the home number despite work number instructions.
Case 5 highlights an ocr finding that a message left on a home number violated minimum information and confidentiality rules, prompting staff privacy training and updated contact directives.
Despite best efforts - errors, workforce non-compliance, complaints and breaches do occur. HIPAA and HITECH impose the duty to monitor and resolve these issues in a mandated timeframe. The complaint and breach report process addressed in Part 2 outlines the elements of this key administrative safeguard and incorporates the HITECH risk assessment and notification requirements of the HIPAA Omnibus Rule.
Section 1: Health Information Management – It is the responsibility of the Covered Entity to document, investigate, and resolve all complaints and breaches that come to its attention in a timely manner as well as the responsibility of privacy and security officers to implement this safeguard. Business Associates are an element of and accountable to the Covered Entity in its Health Information Management process.
Section 2: Complaint Management Process – This section provides an outline of the elements of the administrative safeguard requiring the investigation of HIPAA complaints in a timely manner. It provides a template to guide development of a complaint report and investigation process and a template for a Privacy and Security Complaint Policy with sample complaint forms. Documentation developed form this section can be produced in an OCR audit to demonstrate the Covered Entity's/Business Associate's compliance efforts.
Section 3: Breach Management and Reporting – The HIPAA Omnibus Rule requires the documentation and investigation of all breaches and security incidents ("breaches") in a timely manner, and has outlined specific exceptions which fall outside of the breach notification requirement. This section provides a template to guide the development of a breach report and investigation process, as well as how to identify exceptions to the notification requirement; guidance about the required elements for a breach notification letter with a sample breach notification letter, and a template for a Privacy and Security Complaint Policy with sample complaint forms. Documents developed from this section can be produced in an OCR audit to demonstrate the Covered Entity's/Business Associate's compliance efforts.
Section 4: Sanctions, Workforce Training, and Case Studies - This section focuses on the liability of the Covered Entity, Business Associate and/or individual employees for non-compliance and violations.Case studies taken from actual HHS investigations demonstrate the regulatory oversight required and sanctions into the hundreds of thousands of dollars assessed for non-compliance to date.Accountability is an essential aspect of a Compliance Plan and meaningful workforce training programs.