Free Consultation

Common HIPAA Issues – Part 2: Breaches

The next area we want to discuss is breaches – the cause of most audits.  Almost all covered entities may at some point face a breach in the privacy of Protected Health Information (PHI). Ultimately, by ensuring you have enacted the appropriate policies and procedures, performed your risk analysis and management plan, developed appropriate technical and physical safeguards, and trained your employees, you are doing all you can to prevent these breaches from occurring and in turn preempt any HIPAA issue regarding breach in a pharmacy.

However, even with all of this, breaches still happen.   In 2019, we saw a couple of instances where breaches occurred, but the subsequent patient and OCR notifications were not sent in the appropriate amount of time.

So What Is a Breach?

The HIPAA regulations define a breach under section 164.402 of the HIPAA Regulations as follows:

Breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under [the Privacy Rule] of this part which compromises the security or privacy of the protected health information . . .

In the “Breach Notification Rule” section of the Website, a breach is defined as follows:

A breach is, generally, an impermissible use or disclosure under the privacy rule that compromises the security or privacy of the protected health information . . .

In general, a breach is an event where a person or entity sees or obtains Protected Health Information (PHI) they had no legal reason to see.  There are some exceptions to this, and the pharmacy can conduct a risk assessment on the breach to determine if there is a low probability the PHI was compromised. If you go down the risk assessment route, we recommend enlisting the services of an attorney.

What Do You Do If you Think You Have a Breach?

As stated in the Breach Notification Rule, in the event that a breach of protected health information takes place, all HIPAA-covered entities and their business associates must notify patients and other parties. In fact, the Federal Trade Commission (FTC) also enforces such rules on all third-party health service providers like pharmacies and vendors of personal health records.

In light of the abovementioned and other similar rules enforced by HIPAA, it is mandatory that when there is a suspected breach, the pharmacy’s Privacy Officer and management begin a process of investigating, identifying, notifying and preventing.  This process (described below) will ensure the pharmacy is doing all it can to identify and address the breach and prevent future breaches or any HIPAA issues regarding breaches in a pharmacy, from occurring.  Here is a roadmap to the general process followed in case of a breach roadmap:

  1. Investigation: Investigate to determine if a breach of PHI did happen and if so, identify all the facts of the breach.
  2. Risk Assessment (optional step): If there was a breach – a violation with regards to the use or disclosure of protected health information – conduct a risk assessment of the breach to determine if there is a low probability that the PHI was compromised.

This step is extremely important considering that if the covered entity can demonstrate the low probability of the PHI being compromised, it is not a breach. However it’s important that the risk assessment be conducted on at least the following crucial aspects: 

  • What is the nature and extent of the protected health information at stake? What are the types of identifiers and is there any possibility of re-identification? 
  • Was the PHI actually acquired or viewed by the unauthorized person?
  • In addition what risk does the unauthorized person (who used the PHI or to whom the disclosure was made) pose to the PHI? 
  • To what extent, if any, has the risk to the PHI been mitigated?

These are just a few examples of the right questions that the covered entity or associate can ask themselves to ascertain the risk to the PHI.

  1. Patient Notification: Notify all of the affected patients within 60 days of discovery.  The notification must include:• A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known
    • A description of the types of Protected Health Information that was involved in the breach
    • The steps patients should take to protect themselves from potential harm resulting from the breach
    • A brief description of what the practice is doing to investigate the breach, mitigate losses, and protect against further breaches or HIPAA issues regarding breaches in a pharmacy
    • Contact procedures for patients to ask questions or learn additional information (which will include a toll-free telephone number, e-mail address, website, or postal address)
  2. OCR Notification (Federal Government): Notify the OCR:

    • Within 60 days of discovery for breaches of 500 or more
    • Within 60 days of the end of the year (Feb 29, 2020) for breach of less than 500

  3. Media Notification: Notify the media within 60 days of discovery if the breach is of 500 individuals in the same state.
  4. State Notification: Follow any other requirements your state has related to breaches.
  •  

Concurrent to the notification process, you should also be following up with any other items identified during the investigation and making all of the necessary changes to your operation to prevent a similar breach or HIPAA issue regarding a breach in a pharmacy, from occurring again in the future.  These steps could include:

    • Collection of the breached PHI
    • Mitigation of further disclosures
    • Determine if identity theft protection should be purchased for those who have had the information breached
    • Changes to policies and procedures
    • Notification of law enforcement
    • Employee sanctions
    • Employee training
    • Updates to technologies

If you suspect you have a breach or a potential HIPAA issue regarding a breach in a pharmacy, the PRS Pharmacy Services’ HIPAATrack Program can be of great help to you. All you would be required to do is simply start the process by following the policy and procedure: Suspected Violations and Breaches (if you are using the PRS HIPAATrack Program – members can login here). 

For more information about PRS Pharmacy Services’ Pharmacy Compliance Offerings, click on one of the following links, or simply call PRS at 1-800-338-3688

LINKS

HHS – HIPAA Regulations

HHS – Breach Notification Rule

Membership Login

HIPAATrack

COMPLIANCETrack