ARTICLE
24 February 2022

Don't Forget The March 1 HIPAA Smaller Breach Reporting Deadline

HK
Holland & Knight

Contributor

Holland & Knight is a global law firm with nearly 2,000 lawyers in offices throughout the world. Our attorneys provide representation in litigation, business, real estate, healthcare and governmental law. Interdisciplinary practice groups and industry-based teams provide clients with access to attorneys throughout the firm, regardless of location.
If a Health Insurance Portability and Accountability Act (HIPAA)-covered entity experiences a data breach involving fewer than 500 individuals, the incident must be reported to the...
United States Food, Drugs, Healthcare, Life Sciences

If a Health Insurance Portability and Accountability Act (HIPAA)-covered entity experiences a data breach involving fewer than 500 individuals, the incident must be reported to the U.S. Department of Health and Human Services (HHS). The breach can be reported within the same 60-day timeframe in which the affected individuals are notified, just as larger breaches must be. Alternatively, covered entities can document the incident, then report it to the HHS Office for Civil Rights no later than 60 days after the end of the calendar year.

These breaches must be reported in the manner specified on the HHS website. The 2022 deadline to submit reports is March 1. Covered entities must still complete separate notices for each incident. The online notice form will require several pieces of information, including:

  • contact and identification information for the entity reporting the breach
  • identification of the type of incident involved
  • the location of the breach
  • the type of data involved
  • a brief description of the incident
  • identification of any safeguards implemented prior to the incident
  • certain details regarding the provision of notice to individuals
  • actions taken in response

More information is available on the HHS website. Covered entities should have systems in place to ensure that these incidents are reported as required.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More