Compliance : Stay Compliant by Knowing Which Entities to Notify in HIPAA Breaches

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This compliance article discusses HIPAA breach reporting for covered entities and explains the notification process to the Department of Health and Human Services. It outlines the general timing framework for different breach sizes, discusses what kinds of information may be included in a breach notice, and describes the types of organizational follow-up HHS may expect to see. The piece is aimed at medical practices, compliance staff, and coding/billing professionals who help manage privacy and security reporting requirements.

Why This Topic Matters

Proper breach notification is a required part of HIPAA compliance, and missing the reporting process can expose a practice to penalties. Understanding the reporting workflow and the categories of information to prepare helps organizations respond more consistently when a breach occurs.

Article Sections

  1. Follow Different Timetables for Small, Large Breaches

    Explains the general reporting timelines for different breach sizes and the related notification pathway to HHS. The section focuses on timing and reporting categories rather than technical details.

  2. Have Extra Info Ready When Notifying Secretary

    Discusses the kinds of supplemental information that may accompany a breach notice and the practical differences between submitting a basic form and adding follow-up documentation. It also covers the general workflow for submitting an addendum.

  3. Make Sure to Show HIPAA Practice Improvements

    Describes broad categories of corrective actions and compliance improvements that may be included in breach follow-up documentation. The section emphasizes organizational response and remediation efforts.

What You Will Learn

  • How HIPAA breach notifications are generally structured
  • Which organization receives breach notices under HIPAA
  • How reporting timing differs for larger and smaller breaches
  • What categories of supplemental information may accompany a breach notice
  • How practices can document compliance improvements after a breach

Who Should Read This

  • Medical practices
  • Compliance officers
  • Privacy and security staff
  • Billing and coding professionals
  • Practice managers

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?