Federal law requires hospitals and other HIPAA-covered entities to report all 2018 HIPAA privacy breaches affecting fewer than 500 patients to the Office for Civil Rights of the U.S. Department of Health and Human Services by March 1. This requirement also applies to hospitals that have already notified affected patients and the California Department of Public Health.
Breaches affecting 500 or more patients should have been reported to the federal government at the time of the incident. Information on how to report breaches may be found at https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html.
CHA’s California Health Information Privacy Manual contains a complete discussion of state and federal health information privacy laws, including breach notification rules. For more information, or to order the manual, go to www.calhospital.org/privacy.