decisionhealth Newsletters, Part B News - 2016 Issue 3 (March)
Practice burglary is not an automatic HIPAA breach; look for breach evidence
Subscribe or sign in to view the full article.
Article Overview
This article discusses how a health care practice should evaluate whether a burglary involving potential protected health information exposure rises to the level of a reportable HIPAA security incident. It is aimed at compliance staff, privacy and security officers, practice managers, and others responsible for HIPAA incident response, documentation, and breach assessment. The guidance covers asset inventory, evidence gathering, access-log review, internal reporting, committee documentation, and the general process for determining whether breach-notification steps may be needed.
Why This Topic Matters
A burglary does not automatically mean PHI was compromised, so practices need a structured way to assess the facts before deciding on reporting and follow-up. Proper evaluation and documentation can help organizations respond appropriately and maintain HIPAA compliance.
What You Will Learn
- How to evaluate whether a burglary incident may have involved protected health information
- What kinds of evidence can help determine whether PHI was compromised
- Why asset inventory and encryption status matter in incident assessment
- How access logs and internal documentation fit into a HIPAA response process
- When a practice may need to consider breach-notification procedures
Who Should Read This
- HIPAA compliance officers
- Privacy officers
- Security officers
- Practice managers
- Health care administrators
- Medical office staff responsible for incident response
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com