HHS to Target HIPAA Breaches Affecting Fewer Than 500 Individuals | Practical Law

HHS to Target HIPAA Breaches Affecting Fewer Than 500 Individuals | Practical Law

In a listserv email, the Department of Health and Human Services (HHS) announced its plans to more widely investigate breaches affecting the protected health information (PHI) of fewer than 500 individuals under the Health Insurance Portability and Accountability Act (HIPAA).

HHS to Target HIPAA Breaches Affecting Fewer Than 500 Individuals

Practical Law Legal Update w-003-1865 (Approx. 4 pages)

HHS to Target HIPAA Breaches Affecting Fewer Than 500 Individuals

by Practical Law Employee Benefits & Executive Compensation
Published on 23 Aug 2016USA (National/Federal)
In a listserv email, the Department of Health and Human Services (HHS) announced its plans to more widely investigate breaches affecting the protected health information (PHI) of fewer than 500 individuals under the Health Insurance Portability and Accountability Act (HIPAA).
In a listserv email distributed on August 18, 2016, HHS announced its intent to more widely investigate breaches affecting fewer than 500 individuals under HIPAA (see Practice Note, HIPAA Enforcement and Group Health Plans: Penalties and Investigations). The more extensive investigations will:
  • Occur through HHS's regional offices.
  • Begin effective in August 2016.
The government has prioritized investigations of reported breaches involving PHI through breach notification requirements added under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act) (see Practice Note, HIPAA Breach Notification Rules for Group Health Plans). Under implementing HIPAA regulations, the "500-or-more" affected individuals standard is a dividing line that impacts when notice of a HIPAA breach must be reported to HHS.
As part of HHS's initiative, the various regional offices will:
  • Continue to have discretion regarding which small breaches to investigate.
  • Expand their enforcement efforts to obtain corrective action regarding HIPAA noncompliance.
In evaluating which smaller breaches to investigate, the HHS regional offices will consider:
In addition, the HHS regional offices may consider the lack of breach reports affecting fewer than 500 individuals in comparing a particular CE or BA to like-situated CEs or BAs.

Practical Impact

HHS has investigated and obtained settlements for breaches affecting under 500 individuals in the past (for example, see Legal Update, $3.5 Million HIPAA Settlement Highlights Need for Training). The agency's website indicates that the first settlement involving a breach of unsecured electronic PHI affecting fewer than 500 individuals occurred in late 2012. But HHS's formal initiative on breaches affecting fewer than 500 individuals appears to reflect the government's belief that investigating the "root causes" of smaller breaches may reveal the kinds of entity-wide HIPAA noncompliance that have driven some of the large and expensive settlements publicized in 2016-to-date, subject to HHS's enforcement resource limits (see Legal Update, HHS Claims a Record Haul With $5.55 Million HIPAA Settlement).