Purpose and Scope
The Security Incident Response Plan - HIPAA Addendum identifies the requirements for covered entities and business associates in providing notification to affected individuals, the Secretary, and, in certain circumstances, to the media following a breach of unsecured protected health information
This addendum applies to all breaches of protected health information (PHI) covered under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).
HIPAA Breach Notification Policy
In the event that individually identifiable health information is affected during a breach, the following HIPAA Breach Notification Policy shall apply:
ZenGRM has adopted this HIPAA Breach Notification Policy in order to comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the HITECH Act of 2009 (ARRA Title XIII). ZenGRM also recognizes its responsibility to protect individually identifiable health information under the regulations implementing HIPAA, other federal and state laws protecting the confidentiality of personal information, and under general, professional ethics.
The following governs consumer notifications of breaches of individually identifiable health information for ZenGRM.
Assumptions
- ZenGRM understands that in some instances it may be a Business Associate under the definitions contained in the HIPAA regulations
- When applicable, ZenGRM must comply with HIPAA and the HIPAA implementing regulations concerned with notifications to consumers about breaches of individually identifiable health information, in accordance with the requirements at § 164.400 to § 164.414
- Compliance with HIPAA’s breach notification requirements is mandatory and failure to comply can bring severe sanctions and penalties
- Timely notifications to consumers about breaches of individually identifiable health information can help reduce or prevent identity theft and fraud
- Timely notifications to consumers about breaches of individually identifiable health information can help protect our business and reputation
- Only breaches of “unsecured” (unencrypted or not destroyed) protected health information trigger HIPAA’s breach notification requirements
Breach Notification Policy
- It is the policy of ZenGRM to provide timely notifications to affected parties about breaches of individually identifiable health information
- Model breach notification letters or emails may be developed and prepared to be used as needed
- It is the policy of ZenGRM to timely provide:
- Notice to parties alerting them to breaches “without unreasonable delay,” but no later than 60 days after discovery of the breach
- Notice to Covered Entities (CEs) by Business Associates (“BAs”) when BAs discover a breach
- Notice to the secretary of HHS and prominent media outlets about breaches involving more than 500 individual subject’s records
- Notice to next of kin about breaches involving parties who are deceased
- Notices to include what happened, the details of the breached Protected Health Information (PHI) or electronic PHI (ePHI), steps to help mitigate harm to the party, and the CE’s response
- Annual notice to the secretary of HHS 60 days before the end of the calendar year about PHI breaches involving fewer than 500 patient records
- When a security or privacy incident occurs that may be a “breach” under HIPAA regulations, the designated Officer will perform a risk assessment to determine whether there is significant risk of harm to the individual(s) whose PHI was inappropriately disclosed or compromised. The following questions must be accurately addressed by the risk analysis:
- Did the breach or compromise involve “unsecured” protected health information?
- In whose hands did the PHI land?
- Can the information disclosed cause “significant risk of financial, reputational, or other harm to the individual”?
- Was mitigation possible? For example, can you obtain forensic proof that a stolen laptop computer’s data were not accessed?
- Business Associate contracts, whether existing or new, are required to have corresponding breach notification requirements included in them
- Sanctions or re-training shall be applied to all workforce members who caused or created the conditions that allowed the breach to occur
- All breach-related activities and investigations shall be thoroughly and timely documented in accordance with this Plan
Exceptions
If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under this subpart would impede a criminal investigation or cause damage to national security, a covered entity or business associate shall:
- (a) If the statement is in writing and specifies the time for which a delay is required, delay such notification, notice, or posting for the time period specified by the official; or
- (b) If the statement is made orally, document the statement, including the identity of the official making the statement, and delay the notification, notice, or posting temporarily and no longer than 30 days from the date of the oral statement, unless a written statement as described in paragraph (a) of this section is submitted during that time.
ZenGRM business needs, local situations, laws and regulations may occasionally call for an exception to this policy or any other ZenGRM policy. If an exception is needed, ZenGRM management will determine an acceptable alternative approach.
Enforcement
Any violation of this policy or any other ZenGRM policy or procedure may result in disciplinary action, up to and including termination of employment. ZenGRM reserves the right to notify the appropriate law enforcement authorities of any unlawful activity and to cooperate in any investigation of such activity. ZenGRM does not consider conduct in violation of this policy to be within an employee’s or contractor’s course and scope of work.
Any employee or contractor who is requested to undertake an activity that he or she believes is in violation of this policy must provide a written or verbal complaint to his or her manager or any other manager of ZenGRM as soon as possible.
The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies and procedures, and any other security breaches.
Responsibility, Review, and Audit
This plan will be reviewed and tested on an annual basis. Ensuring that the plan reflects ongoing changes to resources is crucial. This task includes updating the plan and revising this document to reflect updates; testing the updates; and training personnel. Test results will be documented and signed off by ZenGRM management. The results are shared with appropriate parties internally and findings are tracked to resolution. Any changes are communicated across the organization.
This document is tested, maintained and enforced by Matt Hackett.
This document was last updated on May 6, 2026.
Comments
0 comments
Article is closed for comments.