Federal law requires hospitals and other HIPAA-covered entities to report all 2020 HIPAA privacy breaches affecting fewer than 500 patients to the Office for Civil Rights of the U.S. Department of Health and Human Services (HHS) by March 1.
Hospitals that notified affected patients and the California Department of Public Health are reminded that they must also report the breach to the federal government by the March 1 deadline. Breaches affecting 500 or more patients should have been reported to the federal government at the time of the incident. Information on how to report breaches may be found on the HHS Submitting a Notice of Breach to the Secretary web page.
CHA’s California Health Information Privacy Manual contains a complete discussion of state and federal health information privacy laws, including breach notification rules. For more information, or to order the manual, go to the CHA website.