HHS Posts Form and Instructions For Reporting Data Breaches

October 9, 2009 · Posted in Data breach, HITECH Act 

With the data breach requirements of the HITECH Act now in force, many HIPAA covered entities are contemplating their compliance strategies. The notification requirements of the HITECH Act require that breaches of unsecured protected health information be reported to the Department of Health and Human Services (”HHS”). To assist, HHS has recently posted a notification form that covered entities may use to report breaches of unsecured protected health information to HHS. The form includes all of the required elements specified by the HITECH Act and the implementing regulations issued by HHS. To further facilitate the notification process, HHS also has provided instructions on completing the notification form.

Comments

Leave a Reply





This website, which may be considered advertising under the ethical rules of certain jurisdictions, is provided with the understanding that it does not constitute the rendering of legal advice or other professional advice. The views expressed on this blog are my personal views alone and do not necessarily reflect views of my employer.
  • ABOUT




    Jacqueline Klosek, Senior Counsel in the Business Law Department of Goodwin Procter LLP, is a frequent author and commentator on data privacy and security. You can email her at jacquelineklosek@gmail.com
  • BOOKS