Privacy >> TUSDM Policy on Breach Notifications

TUSDM Policy on Breach Notifications

I. Purpose and Scope: 
  1. The purpose of this policy is to provide guidance to Tufts University School of Dental Medicine (TUSDM) on required notifications when the protected health information (PHI) of one or more patients, has been improperly accessed, used, or disclosed, and for notifying state and/or federal government officials if required by law.
II. Policy Statement: 
  1. TUSDM’s policy is to respond promptly and in accordance with state and federal requirements when there has been a breach or even a suspected breach of PHI.
III. Definitions: 
IV. General Rules: 
  1. TERMS.
    1. Breach. “Breach” means the acquisition, access, use, or disclosure of PHI which compromises the security or privacy of the PHI. There are exceptions for:
      1. instances in which the recipient of the information would not reasonably have been able to retain the information;
      2. unintentional acquisition, access, or use of information by employees or persons acting under the authority of a covered entity or business associate; and
      3. certain inadvertent disclosures among persons similarly authorized to access PHI as a business associate or covered entity.
    2. Unsecured PHI. “Unsecured PHI” means PHI that has not been secured by a technology standard identified by HHS that renders PHI unusable, unreadable, or indecipherable to unauthorized individuals. 
  2. REGULATORY REQUIREMENTS.
    1. HIPAA and the laws of many states require that patients and often regulators be notified of certain breaches or unauthorized uses or disclosures of PHI. If there is an incident involving PHI, it is important that TUSDM identify the type of information involved and the state or states where the affected patients reside.
  3. RISK ASSESSMENT.
    1. Not every incident involving PHI amounts to a reportable breach. For example, if the PHI was secured through encryption or other legally defined standard, its loss or disclosure may not constitute a breach. In all cases, TUSDM will conduct a fact-specific risk assessment to determine the nature of the breach and whether it is reportable under applicable law. There is a presumption that an impermissible use or disclosure of PHI is a reportable breach unless the TUSDM can demonstrate a low probability that PHI has been compromised. The following factors must be considered in the risk assessment and the risk assessment must be documented. Additional facts may also be considered:
      1. The nature and extent of PHI involved, including the types of identifiers and likelihood of re-identification.
      2. The unauthorized person who used PHI or to whom disclosure was made.
      3. Whether PHI was acquired or viewed.
      4. The extent to which the risk to PHI has been mitigated.
  4. BREACH REPORTING:FEDERAL.
    1. If TUSDM determines, based on its risk assessment, that a reportable breach has occurred, it must provide notice to affected individuals without unreasonable delay and within 60 days after discovery of the breach. A breach is considered “discovered” when a covered entity knows or should have known about the breach. Also, many state data breach laws require notification sooner than 60 days, so it is critical that breaches and suspected breaches be immediately reported to the TUSDM Security and Privacy Officer. Notification of breach must include, at a minimum:
      1. A description of the types of Unsecured PHI involved.
      2. The steps that affected individuals should take to protect against potential harm.
      3. A brief description of steps that TUSDM has taken to investigate the incident, mitigate harm and protect against future breaches.
      4. Contact information for follow up questions from patients. NOTE: Notification may be delayed at the request of law enforcement.
    2. Notice Format. Notice to patients must be in writing and sent by first class mail to the last known address of the patient or next of kin. If the patient has specified a preference for email notification, that method should be used. If more than 500 residents of a state or jurisdiction are affected, notice must also be published in prominent media outlets.
    3. Special Circumstances. If insufficient or out of date contact information exists for more than 10 affected individuals, notice may be made by conspicuous posting on TUSDM’s home page or through major print or broadcast media in the affected individual’s region. The duration of such posting will be determined by HHS. If the breach affects more than 500 individuals, HHS must be immediately notified. Breaches affecting fewer than 500 individuals must be logged and reported to the Secretary on an annual basis.
  5. BREACH REPORTING: STATE.
    1. The TUSDM Security and Privacy Officer and the TU Privacy Officer & Director IT Security Compliance will work with legal counsel to identify applicable state breach notification laws and their reporting requirements. TUSDM will comply with all such requirements.
  6. EMPLOYEE RESPONSIBILITIES.
    1. All employees must immediately report known or suspected breaches, and any other unauthorized uses or disclosures of PHI to the TUSDM Security and Privacy Officer and/or the TU Privacy Officer & Director IT Security Compliance. There will be no retaliation for all such reports made in good faith.

 

V. Policy Compliance Monitoring and Enforcement: 
  1. The Security and Privacy Officer is responsible for the monitoring and enforcement of this policy. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions: 
  1. Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM Sanction for HIPAA Violations Policy.
VIII. Approval and Review Cycle: 
  1. This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.