HIPAA Vendor Breach Notification Requirements
BA Breach Reporting, CE Notification Duties, OCR Reporting, and Investigation Procedures
Quick Answer
Upon suspected PHI breach, Business Associates must notify Covered Entities without unreasonable delay (typically within 24-48 hours). Covered Entities must notify affected individuals within 60 days, and OCR if 500+ individuals affected. Breach assessment requires investigation to determine if compromised data poses significant risk of harm.
Breach Notification Timeline & Responsibilities
Business Associate Breach Notification Responsibilities
BA's Legal Obligation:
Business Associates must notify Covered Entities of any breach of PHI "without unreasonable delay and without unreasonably low priority." While specific timeline varies by state, 24-48 hours is standard healthcare practice.
Risk Assessment for Breach Notification
Covered Entity Notification Obligations
Breach Notification Content Requirements
- Date of breach and date discovered
- Description of what happened
- Types of PHI involved
- Steps individuals should take to protect themselves
- Steps CE took to secure data and prevent recurrence
- For questions: phone number and website
- Offer of credit monitoring if identity theft risk present
Special Considerations for Vendor Breaches
Contractual Indemnification
BA contract should include indemnification clause where BA reimburses CE for breach costs including notifications, credit monitoring, legal fees.
Cyber Insurance
BA should maintain cyber liability insurance naming CE as additional insured, covering breach notification costs.
Liability Allocation
BA liable to CE for breach. CE liable to individuals. Clarify liability chain in contracts.
Reputational Harm
Media breaches cause reputational damage. CE should require BA to assist with media response.
Regulatory Consequences
OCR may investigate and levy penalties (up to $1.5M per violation) against both CE and BA.
Litigation Risk
Breach victims may file lawsuits. BA should cooperate with CE's legal defense.
Breach Documentation Requirements
Post-Breach Risk Mitigation
- Offer free credit monitoring and identity theft protection for 12-24 months
- Create dedicated call center for affected individual questions
- Conduct press conference or media briefing to address concerns
- Implement technical and organizational improvements to prevent recurrence
- Conduct vendor risk reassessment and potential contract termination if appropriate
- Regular communication updates to affected individuals
Breach Response Checklist
Key Takeaways
- Vendors must notify BAs within 24-48 hours of suspected breach
- BAs must notify CEs without unreasonable delay (typically same day/next day)
- CEs must notify individuals within 60 days of discovery
- OCR notification required for all breaches regardless of size
- Unencrypted PHI breaches presumed to require notification
- 500+ individuals affected = media notification also required
- Maintain breach documentation minimum 6 years for regulatory audit